
Bitget details $388M hack security flaw
- Bitget said a third-party security vulnerability enabled fraudulent withdrawal commands during the September 24 attack.
- About $388 million moved across 12 hot or warm wallet addresses.
- Withdrawals are returning gradually as investigations and asset recovery continue.
Bitget has said that a third-party security vulnerability enabled fraudulent withdrawal commands during its September 24 attack.
The latest estimate puts affected assets at about $388 million across 12 wallet addresses.
The attacker allegedly obtained “high-level internal credentials,” Bitget CEO Gracy Chen told Cointelegraph.
Those credentials enabled abnormal withdrawals that bypassed existing risk controls, according to Bitget’s investigation.
The incident affected portions of Bitget’s hot and warm wallets across 11 blockchains.
Bitget said cold wallets and user account balances remained unaffected, while private-key compromise was ruled out.
The exchange has remediated the vulnerability, revoked internal credentials and strengthened withdrawal verification.
Bitget is progressively restoring withdrawals while investigations into the exploit continue.



