Loading prices…
🩸BEARISH

Bitget Hackers Steal $380M Through Credential Theft

The CEO said private keys were not compromised, but attackers reached wallet backends and bypassed withdrawal risk controls.

Bitget CEO Gracy Chen said attackers stole approximately $380 million after exploiting a zero-day vulnerability in a third-party security product. In a September 28 livestream, Chen said the vulnerability gave attackers internal credentials to access wallet backend systems, insert fraudulent withdrawal commands and bypass risk controls. They then deleted traces of the transfers.

Why it matters

The incident points to risks beyond direct private-key theft. Compromised credentials and gaps in backend controls can expose exchange operations even when private keys remain secure.

Market impact

Chen said private keys were not compromised and an inside job had been preliminarily ruled out. Bitget has not identified the attackers and plans to release an incident report.

Frequently asked questions

  1. How did attackers gain access to Bitget's wallet backend systems?

    CEO Gracy Chen said attackers exploited a zero-day vulnerability in a third-party security product to obtain internal credentials, which they used to access wallet backend systems.

  2. How did the attackers move funds after accessing Bitget's systems?

    Chen said they inserted fraudulent withdrawal commands, bypassed risk controls and then deleted traces of the transfers.

  3. Were Bitget's private keys compromised?

    Chen said the private keys were not compromised.

  4. Did Bitget identify the attackers or confirm an inside job?

    Bitget had not identified the attackers. Chen said an inside job had been preliminarily ruled out.

  5. What is Bitget expected to release about the incident?

    Bitget plans to release an incident report.

Source attribution
Aggregated from WuBlockchain · Verified · Last refreshed 1h ago
Open original →