BTC—ETH—BNB—SOL—XRP—USDC—TRX—ADA—DOGE—
Data by CoinGecko
Scam Watch▼Bearish

Third-Party Security Flaw Leads to $388M Exchange Hack

On September 24, 2026, malicious actors drained approximately $388 million from cryptocurrency exchange Bitget. The breach, which was initially estimated at $352 million, occurred when attackers compromised a third-party security product to acquire internal credentials.

Bitget CEO Gracy Chen stated the perpetrators "exploited vulnerabilities from third-party products to steal internal credentials, then used those credentials to send fraudulent withdrawal commands that bypassed our risk controls."

The attackers initiated the exploit at 18:31 UTC with two small test transfers designed to remain below the exchange's automated risk thresholds. Approximately 30 minutes later, the hackers began executing massive fraudulent withdrawals. Detailing the methodology, Chen explained, "Along the way, they used legitimate credentials. They disguised their activity as routine administrative operations while removing traces of their actions."

Despite the scale of the exploit, a Bitget statement confirmed that "Private keys were not compromised and cold wallets were not affected." The company noted that the sophisticated techniques used in the breach are "highly consistent with known patterns of North Korean hacker organizations." Platform representatives also noted this was the first major security incident of its magnitude during the company's eight years in operation.

Mitigation and Withdrawals

Following the breach, Bitget's User Protection Fund, which stood at $464 million prior to the attack, dropped to below $200 million. In an update to users, the platform declared, "The incident remains contained, and no further unauthorized transfers are possible."

Third-Party Security Flaw Leads to $388M Exchange Hack
Along the way, they used legitimate credentials. They disguised their activity as routine administrative operations while removing traces of their actions.

Services began returning online on September 28, 2026, with the resumption of Bitcoin (BTC) and BNB Smart Chain (BSC) network withdrawals. By 09:00 UTC that day, the platform had successfully processed 9,585 customer withdrawal orders. Customers withdrew over 4,000 bitcoins, valued at more than $334 million, within the first hour of operations resuming. Regarding the outflow, Chen observed, "Those hundreds of millions [in bitcoin withdrawals] actually most of them happen on the first hour of the withdrawal restart," adding that activity had subsequently stabilized.

The exchange scheduled Ethereum (ETH) withdrawals to reopen on September 29, followed by USDT on September 30. All other supported tokens, fiat, and P2P services were slated to re-enable by October 2.

Freezing Stolen Assets

External entities actively intervened to intercept the stolen funds. Cross-chain infrastructure protocol NEAR Intents detected and blocked more than $50 million in attempted transfers associated with the exploit. The protocol successfully froze $503,000 during execution, although $166,000 in suspected stolen funds managed to slip past its providers.

Alex Shevchenko, General Manager of NEAR Intents, emphasized the importance of network-level intervention. "The people who build these systems make choices about what those protocols enable. Refusing to help launder stolen assets is one of ours," he stated.

Additionally, stablecoin issuers Circle and Tether blacklisted a wallet linked to the exploiter, successfully freezing $318,013 in USDT and USDC. To incentivize further recovery, Bitget is offering a 5% bounty for freezing the attacker's funds and an additional 5% bounty for successful asset recovery. Despite these efforts, Chen maintains a cautious outlook, noting she is not very optimistic about retrieving the full $388 million.

← All stories