The technical tea
Real talk: the crypto streets have been wild since Bitget caught a $388 million L on September 24. CEO Gracy Chen finally opened up about how the breach actually went down. Lowkey, the exchange’s own private keys and cold wallets weren't touched, but the attacker managed to get their hands on "high-level internal credentials" via a vulnerability in a third-party security product.
Once they had those keys to the kingdom, the attacker was able to push through fraudulent withdrawal commands. It’s giving security nightmare, no cap.
Moving forward
Bitget says they’ve already patched the hole and are clamping down on their internal access controls. They’ve also added independent verification for withdrawals and are keeping a much closer eye on suspicious activity. As for the stolen loot, some assets have been frozen with help from the industry, but they haven't dropped the final number on what’s actually been recovered yet.
There was some speculation early on that North Korea might be the main character behind the attack. Chen says those were just early indicators and that security pros at Mandiant and SlowMist are still deep in the investigation. As for that drama with THORChain—which Bitget previously asked to stop servicing the hacker's addresses—Chen says they’re chilling now. She noted they respect the protocol’s decentralized nature and aren't expecting them to do the impossible by blacklisting specific wallets.
Why it matters
This incident is a massive reminder that even top-tier exchanges are only as secure as their weakest link—and when that link is a third-party provider, the fallout can be massive. If you’re holding bags on any exchange, remember that this is not financial advice, but always practice good custody habits. Stay vigilant, fam.





