On September 24, the cryptocurrency exchange Bitget suffered a massive security breach resulting in the loss of approximately $388 million.. CEO Gracy Chen revealed that attackers exploited a vulnerability in a third-party security product to gain high-level internal credentials and execute unauthorized transfers.
The exploitation of a third-party security product
The breach at Bitget was not a direct assault on the exchange's own core code, but rather a strike against its supply chain. As reported by the exchange, the attacker leveraged a vulnerability within a third-party security product to gain access to high-level internal credentials. This allowed the perpetrator to impersonate administrative users, making the fraudulent activity appear as routine operations.
By using these legitimate credentials, the attacker was able to insert fraudulent withdrawal commands directly into Bitget's wallet-related backend services. The sophistication of the attack was further evidenced by the attacker's ability to delete traces of these commands, attempting to mask the theft as standard system maintenance.
From 0.84 ETH tests to a $361 million drain
The attack followed a calculated progression that began with tiny, non-alerting transactions to test Bitget's risk controls. At 18:31 UTC on September 24, the attacker moved 0.84 ETH from an Ethereum hot wallet and 93 TRX from a Tron hot wallet. Because these amounts fell below the exchange's automated alert thresholds, they passed through the system undetected.
Once the path was cleared, a massive wave of 17 transfers occurred between 18:58 and 20:09 UTC, totaling an estimated $361 million. These transfers spanned a wide array of assets and networks, including Ethereum, XRP, Zcash, BNB Smart Chain, Base, Arbitrum, Optimism, and Avalanche. a second wave of roughly $30 million followed shortly after, involving assets like Algorand, TIA, and Cosmos, before Bitget could fully isolate its systems.
Bitget’s P0 emergency response and the role of Mandiant
Bitget initiated its highest-level P0 emergency response at 19:14 UTC once discrepancies were detected in the wallet system.. The exchange's technical team worked to contain the breach by moving funds into cold storage and eventually shutting down all wallet withdrawal services, including the signing service, by 21:44 UTC.
To assist in the recovery and forensic analysis, Bitget has engaged professional security firms Mandiant and SlowMist. According to the report, these firms are currently analyzing the attack vectors, validating remediation measures, and conducting on-chain asset tracing to help law enforcement and other blockchain projects freeze the stolen funds.
The identity of the third-party vendor and the 'inside job' question
While Bitget CEO Gracy Chen has stated that the exchange does not currently believe the incident was an inside job, several critical details remain unverified.. The specific identity of the third-party security product that provided the entry point has not been disclosed, leaving other exchanges using the same software in a state of uncertainty.
Furthermore, while the attacker used legitimate credentials, the investigation has yet to determine if those credentials were stolen via phishing, malware, or a deeper systemic flaw within the third-party tool. The full extent of how long the attacker may have had access to the internal management system prior to the September 24 transfers also remains an open question for investigators.
Comments 0