2026-09-29 · view entry permalink →
Bitget: an attacker exploited a third-party security product to obtain internal credentials, spoofed wallet-authorization data, and stole $388M in one of 2026's largest crypto-exchange hacks
Cryptocurrency exchange Bitget confirms that, at 18:31 UTC on 2026-09-24, unauthorized transfers occurred from a portion of its hot and warm wallet infrastructure across eleven blockchains: Ethereum, XRP Ledger, TRON, Arbitrum, Optimism, Base, BNB Smart Chain, Avalanche, Algorand, Celestia and Zcash (Bitget, 2026-09-27). Per Bitget's own investigation, the attacker did not steal a private key: "the attacker may have exploited a vulnerability in a third-party security product to potentially obtain high-level internal credentials," then used those credentials "to impersonate authorized activity and send fraudulent withdrawal commands to the wallet system," bypassing existing risk controls (Bitget, 2026-09-27). CEO Gracy Chen described the mechanism directly: "The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out" (The Hacker News, 2026-09-25). Bitget states private-key compromise was ruled out and cold wallets were unaffected; the vulnerable third-party product's vendor was notified and the affected functionality disabled pending a fix.
Total loss is now estimated at approximately $388M, revised up from an initial roughly $351.6M on-chain estimate, across twelve wallet addresses. Bitget's approximately $464M User Protection Fund will cover the loss, customer account balances, deposits and trading were unaffected, and withdrawals, paused at detection, resumed in phases starting with Bitcoin on 2026-09-28. Bitget revoked and reissued internal login credentials, restructured access to highly sensitive systems, now requires multiple approvals for critical operations, and engaged Mandiant and SlowMist for independent forensics (Bitget, 2026-09-27).
Bitget's CEO called North Korean involvement "very likely," based on the team's preliminary investigation linking observed IP addresses to VPN services associated with a North Korean hacking group (TRM Labs, 2026-09-25). TRM Labs, an independent blockchain-forensics firm, reports that on-chain tracing shows the wallets laundering Bitget's stolen funds overlap with wallets previously used to launder proceeds from the 2025 Bybit and AFX Bridge hacks, both attributed to the DPRK-linked TraderTraitor cluster (also known as UNC4899/PUKCHONG): "these onchain links confirm the group laundering these proceeds is the same one used by TraderTraitor in other recent hacks" (TRM Labs, 2026-09-25). TRM is explicit that this stops short of definitive attribution: "TRM has not yet definitively attributed the exploit to North Korea" and "another actor carrying out the theft remains technically possible."
the attacker may have exploited a vulnerability in a third-party security product to potentially obtain high-level internal credentials
The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out.
these onchain links confirm the group laundering these proceeds is the same one used by TraderTraitor in other recent hacks
Builds on: 2026-09-21/tradertraitor-terraform-lockfile-nostr-dead-drop