"They used legitimate credentials. They disguised their activity as routine administrative operations while removing traces of their actions," Bitget CEO Gracy Chen said, according to a U.Today report.
How the attacker used a third‑party security product flaw
Bitget says the person or group that withdrew about $388 million from the exchange gained access through a vulnerability in a third‑party security product the company used. That flaw gave the attacker entry to a high‑level internal management system, according to Bitget’s account.
From that system the attacker inserted fraudulent withdrawal commands into Bitget’s wallet‑related backend services. Those commands were treated as legitimate by the wallet infrastructure and were used to trigger the exchange’s approval process, Bitget says. The company characterized the flaw as a zero‑day in comments reported by The Block, meaning the vulnerability was exploited before the vendor had issued a fix.
Timeline: test transfers and mass withdrawals on September 24
Bitget traced the intrusion to activity on September 24. At 18:31 UTC the attacker made two small test transfers that stayed below Bitget’s risk‑control threshold and raised no alert. About 30 minutes later, larger transfers began and the wallet system executed them, bypassing the exchange’s risk controls.
Bitget previously reported that a critical backend system had been compromised and used to spoof transaction data; on Monday the company disclosed how the attacker accomplished that spoofing and the steps taken afterward.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildWallet impact, private keys, and customer balances
Bitget said the stolen funds came from parts of its hot and warm wallets; its cold wallets were not affected. The company added that, based on its investigation so far, no private keys were compromised.
Customer account balances were not affected, Bitget said, and its Protection Fund — a reserve set aside for security incidents like this one — will cover the loss. Bitcoin withdrawals were reopened on Monday, and other assets are scheduled to follow in stages through October 2. Bitget told users they do not need to take any action.
Investigations, attribution, and chain analysis
Bitget has engaged outside firms to support the investigation. Security firms Mandiant and SlowMist are assisting, and Bitget expects to publish a formal incident report this week. The company also notified the vendor of the vulnerable product, isolated affected systems, revoked and reissued internal credentials, and turned off the affected functionality while addressing the vulnerability. Bitget has not said whether the vendor has released a fix.
On attribution, Bitget said last week it had pointed to North Korean hackers and on Monday told The Block it still suspects "the same group of people," though CEO Gracy Chen declined to name the group until the incident report is published. TRM Labs, a blockchain analytics firm, reported overlaps between the stolen funds and wallets used to launder earlier North Korean thefts; those overlaps pointed to the group TraderTraitor but TRM did not make a firm attribution.
Addresses, chain tracking, and what this means for exchanges, vendors, and users
Bitget has published the main addresses that received the stolen funds and set up a live tracking dashboard and a recovery portal. The addresses Bitget listed on September 25 are:
- Ethereum and EVM networks: 0x770b10b273fc44fe9197d6bf20f145c2e98463ee
- XRP: rwNhefsz1UQEusxhCvHip3RANinWi4CTck
- Zcash: t1WgMdtND8NF7NDUuYmq8MpMj1NTCXkMDVG
- TRON: TBWNguTTgezw9dVorX441C6nDrZpRxYwKD
TRM Labs advised exchanges to screen incoming deposits not only against the exploiter addresses Bitget identified but also against funds that originated from those addresses via several intermediate wallets, since proceeds were moving through bridges and cross‑chain swap services and therefore were more likely to arrive indirectly.
For exchanges: watch the published addresses and chains, and screen deposits against both direct and indirect flows, as TRM Labs recommended. For vendors of security products: expect incident notification from customers and pressure to disclose and patch zero‑day flaws promptly — Bitget has notified the vendor and has not said whether a fix is available. For users: Bitget says customer balances remain intact and that withdrawals will resume in phases; users were told no action is necessary while the exchange completes its operational checks.
Bitget has also taken immediate internal steps: it restricted internal access, added independent checks on withdrawals, increased monitoring for unusual activity, and plans to review how it assesses and deploys third‑party security products. The company expects to publish a formal incident report this week; whether that report will identify the vendor or describe a patch timeline remains to be seen.




