Skip to content
TECH CEO Daily

Bitget hack cost an estimated $387.5 million; exchange says attacker may have exploited a security tool

The exchange says an attacker may have used a flaw in a third-party security product to obtain internal credentials and slip fraudulent withdrawals past risk controls. Withdrawals are scheduled to resume in phases through October 2.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Bitget says an attacker may have exploited a flaw in third-party security software to obtain internal credentials and push fraudulent withdrawals; its forensic investigation is ongoing.
  • 2Losses are estimated at $387.5 million from hot and warm wallets; Bitget says cold wallets and customer balances were not affected.
  • 3CEO Gracy Chen pointed to North Korean hackers, while Bitget's own incident page declines to speculate on attribution.

The news

Cryptocurrency exchange Bitget said the Bitget hack that began on September 24 cost an estimated $387.5 million. The exchange said the attacker may have exploited a vulnerability in third-party security software to obtain internal credentials, then used them to push fraudulent withdrawals past its risk controls; an independent forensic investigation is still under way.

According to Bitget's incident timeline, unauthorized transfers started at 18:31 UTC on September 24 and were detected within 34 minutes. Emergency response began at 19:14 UTC and containment at 19:40 UTC. The exchange said the root cause was identified by September 25. Funds left 12 hot and warm wallet addresses across 11 blockchains and included XRP, ETH, USDT, ZEC, ATOM and USDC. Hot wallets are internet-connected wallets exchanges use to process withdrawals quickly.

Bitget first put the loss at $351.6 million and raised it to $387.5 million after further on-chain tracing, BleepingComputer reported. The exchange said cold wallets were not affected, private key compromise has been ruled out and customer account balances are intact. It said its Protection Fund covers the loss; TechCrunch and The Record reported the fund holds about $464 million. Bitget has not named the security vendor. CEO Gracy Chen described the flaw as a zero-day, meaning it had no patch when exploited, The Hacker News reported.

The Hacker News, citing Bitget's disclosures, reported that the attacker first sent two small test transfers kept below risk-control thresholds, then began larger withdrawals about 30 minutes later. Bitget said it notified the vendor, isolated affected systems, reissued internal credentials and brought in Mandiant and SlowMist to investigate. It has also notified law enforcement and offered a 5% bounty for recovered funds.

Chief Executive Gracy Chen said the attack matched patterns of North Korean hacking groups, citing IP addresses, behavior and on-chain signatures, according to TechCrunch and The Record. The Hacker News reported that blockchain analytics firm TRM Labs found overlaps between the stolen funds and wallets used to launder earlier North Korean thefts, pointing toward a group known as TraderTraitor, though TRM had not made a definitive attribution. Bitget's own incident page says it will not speculate on attribution while investigations continue. TechCrunch called it the largest known crypto theft of 2026 so far.

The numbers

Total stolen (revised estimate)
$387.5 million
Initial loss estimate
$351.6 million
Hot and warm wallet addresses affected
12
Blockchains involved
11
Time to detection
34 minutes
Protection Fund size (reported)
about $464 million
Recovery bounty
5% of recovered funds

Why CEOs should care

For CISOs, the entry point is the story. The attacker did not break Bitget's cryptography or steal private keys; according to the exchange, it may have abused a security product that held privileged access. Security leaders should list which third-party security and monitoring tools hold administrative credentials, confirm those credentials are scoped and rotated, and ask each vendor how quickly it discloses zero-days affecting customers. Tools that sit deepest in the environment deserve the tightest controls.

The two small test transfers also matter. Risk engines tuned only for large or unusual amounts can miss a patient attacker who probes first. Companies running payment, treasury or payout systems should ask whether controls flag sequences of new activity, not just single transactions above a limit, and whether fraudulent commands issued with valid credentials would be caught at all.

For CFOs and treasurers holding digital assets on exchanges, the incident is a counterparty question. Ask providers what share of client assets sits in hot wallets, how their protection funds are sized and audited, and how long withdrawals could be frozen during an incident. Bitget's staged schedule runs from September 28 to October 2, a reminder that access can pause even when balances are covered.

The bigger picture

Crypto platforms remain a top target for state-linked theft. TechCrunch reported that TRM Labs attributes roughly three-quarters of 2026 crypto thefts to North Korea, and SecurityWeek recalled the February 2025 Bybit heist, reportedly worth $1.5 billion. The method here is notable: by Bitget's account, no private keys were compromised and the attacker instead used internal credentials to issue withdrawals, which suggests the operational systems and trusted tools that approve transactions deserve as much scrutiny as key storage.

The case also adds to a broader concern about security software itself becoming an attack surface. When a product built to protect an environment holds high-level credentials, a single unpatched flaw in it can open the door to the systems it guards.

What’s next

Bitget said Bitcoin withdrawals resumed on September 28, with ETH scheduled for September 29, USDT for September 30 and remaining tokens, fiat and peer-to-peer services for October 2, each at 08:00 UTC. Watch for whether Bitget or its investigators name the third-party vendor, whether a patch or advisory follows for other customers of that product, and whether U.S. authorities formally attribute the theft.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

BitgetNorth KoreaCryptocurrencyThird-party risk

Earlier coverage of Bitget

All Bitget coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.