According to Bitget CEO, a $388 million hacker attack exploited a third-party security vulnerability.
Some of the stolen assets have been frozen, but as investigators continue to assess whether they may be related to North Korea, Bitget has yet to disclose how much assets have been recovered.
Bitget CEO Gracy Chen stated that the recent security incident involving $388 million at this cryptocurrency exchange stemmed from a vulnerability in a third-party security product, which allowed attackers to obtain "high-privilege internal credentials."
In an interview with Cointelegraph, Chen stated that attackers used these credentials to issue fraudulent withdrawal instructions. She said that the private key of Bitget was not leaked, and the cold wallet was not affected either.
Bitget indicates that this security vulnerability has since been fixed, and withdrawal control measures have been strengthened, including restricting internal access rights, adding independent verification for withdrawals, and enhancing monitoring of abnormal activities.
The attack occurred on September 24th. At that time, Bitget discovered unauthorized transfers from multiple of its hot wallets and temporarily suspended withdrawals. The exchange initially estimated that about $352 million in assets were affected.
Bitget has not yet disclosed the recovered data.
The exchange has not yet disclosed how much of the stolen crypto assets have been recovered or frozen. Chen indicates that with the help of participants from other industries, some of the assets have been frozen, but Bitget the total amount will only be announced after the amount is verified.
Bitget previously called on THORChain – a protocol used for exchanging assets between different blockchains – to refuse to provide services to addresses related to this attack.
The exchange stated that in attempting to prevent the transfer of stolen assets, it did not request that THORChain stop its network operations. THORChain, on the other hand, indicated that it is not possible to selectively blacklist individual addresses.
Chen indicates: "We understand that THORChain operates as a decentralized protocol, and it has been stated that it is not possible to selectively block individual addresses. We respect the technical limitations of different networks and do not require any protocol to take actions that are technically unfeasible."
Chen also mentioned the earlier suspicion that Bitget might be behind this attack on North Korea.
Chen indicates that: 'The information shared previously is based on preliminary indications identified during the investigation process.'
She added, "These signs are still being evaluated at present. Mandiant and SlowMist are supporting independent forensic investigations, and the related work is still in progress. As the results are verified, we will share further findings."
Helen Partz also provides supplementary reports on this article.












