Bitget's CEO, Gracy Chen, disclosed that the recent $388 million hack of the crypto exchange was facilitated by a vulnerability in a third-party security product. This flaw enabled the attacker to gain access to high-level internal credentials, which were used to issue fraudulent withdrawal commands.
Despite the breach, Chen assured that Bitget's private keys and cold wallets remained secure. In response to the incident, the exchange has implemented stricter withdrawal controls, including enhanced monitoring and independent verification for withdrawals.
The hack occurred on September 24, prompting Bitget to temporarily suspend withdrawals after detecting unauthorized transfers from its hot wallets. Initially, the exchange estimated that around $352 million in assets were impacted.
While some stolen assets have been frozen with assistance from industry partners, Bitget has not yet disclosed the total amount recovered. Chen emphasized that the ongoing investigation, supported by firms like Mandiant and SlowMist, is still assessing potential links to North Korea.
Bitget has also reached out to THORChain to prevent the movement of stolen assets, although the decentralized protocol has stated it cannot selectively blacklist addresses. Chen reiterated respect for the technical limitations of different networks while continuing to work on the investigation.