Bitget has disclosed that the September 24 theft of roughly $388 million began with a vulnerability in a third-party security product the exchange used. The flaw gave the attacker access to an internal management system, where they inserted fraudulent withdrawal commands that were treated as legitimate. Bitget says no private keys were compromised and that the attacker used valid credentials while masking their activity as routine administrative work.

The exchange's CEO, Gracy Chen, described the flaw as a zero-day in comments to The Block, though she did not name the product. The attacker first made two small test transfers that stayed below risk-control thresholds, then moved larger sums about 30 minutes later, bypassing Bitget's risk controls. Bitget has since revoked internal credentials, isolated affected systems, and added independent checks on withdrawals.

All details come from Bitget's own account, which is being supported by security firms Mandiant and SlowMist. TRM Labs found overlaps between the stolen funds and wallets tied to earlier North Korean thefts, pointing to the group TraderTraitor, but TRM has not made a firm attribution. Bitget still suspects the same group, according to Chen, but will wait for its formal incident report before naming anyone. The exchange has published the receiving addresses and a tracking dashboard, and is asking other platforms to screen for indirect deposits from those addresses.