Crypto exchange Bitget has confirmed that an attacker exploited a zero-day flaw in a third-party security product to steal approximately $388 million. The vulnerability allowed the attacker elevated internal access, which was then used to issue fraudulent withdrawal instructions through the exchange’s wallet backend. Bitget made this disclosure on September 28, 2026, following a breach that occurred on September 24.
Attack Vector and Wallet Compromise
The intruder gained entry via the management system of a third-party product used by Bitget, exploiting the flaw to secure privileged credentials. With those credentials, they injected fake withdrawal commands that circumstantially appeared authentic to internal systems.
Bitget separates holdings into cold wallets (for long-term storage), and hot and warm wallets (used for active funds and withdrawals), requiring approvals before any transfer. While cold storage remained untouched, the attacker tapped into hot and warm wallets to make off with the funds.
The incident unfolded with two small test withdrawals at 18:31 UTC to stay beneath risk thresholds, followed about half an hour later by larger transfers that bypassed the risk controls in place. These larger transfers were authorized by the system as valid.
Response, Attribution, and Customer Impact
Bitget has taken rapid remedial steps: disabling the compromised component, revoking and reissuing internal credentials, limiting internal access, and boosting monitoring and inspection of withdrawal operations. The firm is also reassessing its use and vetting of third-party security tools.
No customer account balances were impacted, the exchange says, and its security reserve fund will absorb the loss. Withdrawals for Bitcoin have resumed; other assets are expected to follow in phased rollouts through October 2. Users are not required to take any action.
Bitget suspects the same North Korean-linked group previously under scrutiny in other hacks was behind this attack. Blockchain tracing by TRM Labs revealed overlaps with addresses used in earlier North Korean thefts. While firm attribution remains under investigation, hints point toward a group known as TraderTraitor.
What to Watch Going Forward
The breach is being jointly probed with security firms including Mandiant and SlowMist. Bitget anticipates publishing a detailed incident report with fresh findings soon.
Additionally, Bitget has published key wallet addresses used by the attacker and established a live tracking dashboard. It has urged exchanges, custodians, stablecoin issuers, and other ecosystem players to flag any transactions involving those addresses.
While third-party tools are meant to bolster security, this case underscores the risk that a vulnerability outside core systems can still trigger profound damage. With zero-day flaws often unknown until exploited, such incidents demand proactive vetting, tighter internal controls, and assuming external dependencies must be as scrutinized as internal infrastructure.