[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fIr7tpdRj8AuPs1VEgHFS1YCsHfLu4geL5LFcgoKUe8s":3},{"article":4,"iocs":58},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":35,"category":36,"article_tags":40},"637dba7a-05aa-4129-aad4-cd7860b75140","Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M","bitget-says-attacker-exploited-third-party-security-product-flaw-to-steal-388m-cb8a6b","The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday. The attacker exploited the flaw to obtain high-level internal credentials and then, on September 24, used them to send fraudulent withdrawal commands to Bitget's wallet system. Exchanges keep most","Cryptocurrency exchange Bitget reported a $388 million loss due to a vulnerability in a third-party security product. Attackers exploited this flaw to gain high-level internal credentials, which they then used to initiate fraudulent withdrawal commands from Bitget's hot and warm wallets. The exchange suspects North Korean hackers, specifically the TraderTraitor group, may be responsible, citing overlaps with previous thefts.","Bitget lost $388M after a third-party security product flaw was exploited by attackers.","Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M Swati KhandelwalSep 28, 2026Vulnerability \u002F Cybercrime The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday. The attacker exploited the flaw to obtain high-level internal credentials and then, on September 24, used them to send fraudulent withdrawal commands to Bitget's wallet system. Exchanges keep most customer funds in offline cold wallets and use hot and warm wallets to process withdrawals. Transfers from those wallets must still be approved before they are signed. The stolen funds came from part of Bitget's hot and warm wallets, and its cold wallets were not affected. Bitget said last week that a critical backend system in its wallet infrastructure had been compromised and used to spoof transaction data and trigger its approval process. It had not said how the attacker got in. Bitget CEO Gracy Chen described the attack on Monday in a livestream, in an interview with The Block, and in comments to Cointelegraph. The flaw gave the attacker access to an internal management system. From there, the attacker inserted fraudulent withdrawal commands into wallet-related backend services, where they were treated as legitimate. On September 24, the attacker first made two small test transfers at 18:31 UTC. They stayed below Bitget's risk-control threshold and raised no alert. The larger transfers began about 30 minutes later, and Bitget's wallet system executed them, bypassing its risk controls. \"Along the way, they used legitimate credentials. They disguised their activity as routine administrative operations while removing traces of their actions,\" Chen said, according to a U.Today report. No private keys were compromised, according to Bitget, which says that finding is based on its investigation so far. Chen did not name the product in her reported comments on Monday. According to The Block, she described the flaw as a zero-day, the term for a vulnerability that attackers exploit before its maker has a fix. Bitget has notified the vendor, isolated the affected systems, revoked and reissued internal credentials, and turned off the affected functionality while the vulnerability is addressed, Crypto Briefing reported. Bitget has not said whether the vendor has released a fix. This account of the attack comes from Bitget. Security firms Mandiant and SlowMist are supporting its investigation, and Bitget expects to publish a formal incident report this week. Bitget has since restricted internal access, added independent checks on withdrawals, and increased monitoring for unusual activity. It plans to review how it assesses and deploys third-party security products. Customer account balances were not affected, the exchange says. Its Protection Fund, a reserve set aside for security incidents like this one, will cover the loss. Bitcoin withdrawals reopened on Monday, and other assets are scheduled to follow in stages through October 2. Users do not need to take any action. Bitget, which last week pointed to North Korean hackers, still suspects \"the same group of people,\" Chen told The Block. She declined to name the group until the company's incident report is published. TRM Labs, a blockchain analytics firm, said last week that it found overlaps between the stolen funds and wallets used to launder earlier North Korean thefts. Those overlaps pointed to the North Korean group TraderTraitor, but TRM had not made a firm attribution. Bitget has published the main addresses that received the stolen funds, along with a live tracking dashboard. It has asked exchanges, stablecoin issuers, bridges, custodians and other infrastructure providers to watch those addresses and report what they find through its recovery portal. The addresses Bitget listed on September 25 were: Ethereum and EVM networks: 0x770b10b273fc44fe9197d6bf20f145c2e98463ee XRP: rwNhefsz1UQEusxhCvHip3RANinWi4CTck Zcash: t1WgMdtND8NF7NDUuYmq8MpMj1NTCXkMDVG TRON: TBWNguTTgezw9dVorX441C6nDrZpRxYwKD TRM Labs advised exchanges last week to screen incoming deposits against the exploiter addresses it has tagged and against funds that originated from those addresses via several intermediate wallets, rather than only direct transfers. The proceeds were moving through bridges and cross-chain swap services, so deposits were more likely to arrive indirectly. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  cryptocurrency, Cybercrime, Vulnerability ⚡ Top Stories This Week Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access Beyond ISO 27001: Building a Risk Program That Can Keep Up With AI Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore ⭐ Featured Resources Validation Summit ’26: See How Pen Testing, Exposure Validation and BAS Work Together Red Teams: Learn How Attack Path Chaining Changes Automated Security Testing Turn Threat Intelligence Into Verified Risk With Threat-Led Penetration Testing Deploy Browser Security Monitoring in Minutes With a Single Header","https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fbitget-says-attacker-exploited-third.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEgA8s-yMULxIXnKcHnHw7w1dF9pt58MDYc_-_wfJPo8ifPgGoD0GZcgE408ZdC1GbZvjp2wOOEYrlR8obpFEXZ-KUSjIBXFFb3LcswKfAd3EODISE5hSkU-QplYeZDnK95i0QrJhNZKcKEVgedmkKjAme9PV4vDLV-OY7Bh9KhCINbGuglY49greoPLCJQ\u002Fs1600\u002Fbitget-hacker.jpg","2026-09-28T17:42:18+00:00","2026-09-28T20:00:43.79194+00:00",8,[18,21,24,27,30,33],{"name":19,"type":20},"wallet system","product",{"name":22,"type":23},"Bitget","vendor",{"name":25,"type":26},"TraderTraitor","threat_actor",{"name":28,"type":29},"North Korean thefts","campaign",{"name":31,"type":32},"cold wallets","technology",{"name":34,"type":32},"hot wallets","2e06f76c-d5b9-4f54-9eef-4d3447b10730",{"id":35,"icon":37,"name":38,"slug":39},null,"Breaches","breaches",[41,46,48,53],{"category":42},{"id":43,"icon":37,"name":44,"slug":45},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":47},{"id":35,"icon":37,"name":38,"slug":39},{"category":49},{"id":50,"icon":37,"name":51,"slug":52},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":54},{"id":55,"icon":37,"name":56,"slug":57},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",[]]