News / Cybersecurity
Bitget Victim of Critical Flaw in Third-Party Product: $388 Million Stolen Without Accessing Private Keys Published on 28 September 2026 by Christ-loisele (4 min read)
The crypto exchange Bitget suffered an attack on September 24, 2026, exploiting a zero-day vulnerability in an external security tool. The stolen funds come from hot and warm wallets, while private keys and cold reserves remain intact according to ongoing investigations.
Video: Gracy Chen, CEO of Bitget (ME News, YouTube)
An Attack Targeting a Zero-Day Flaw in a Third-Party Tool
Bitget has confirmed that the attack on September 24, 2026, was made possible by a flaw in a third-party security product, identified as a zero-day by The Block . According to Gracy Chen , CEO of Bitget, the attackers used legitimate credentials to mask their actions, simulating routine administrative operations while erasing their traces. This method allowed them to bypass withdrawal controls without triggering an immediate alert.
Initial access was obtained through a vulnerability in Bitget’s internal management system, exploiting a chain of security dependencies. Mandiant and SlowMist , two cybersecurity firms, are collaborating with Bitget to analyze the incident. Although Bitget’s private keys were not compromised, the stolen funds, estimated at $388 million, exclusively came from hot and warm wallets, leaving cold reserves untouched.
The attackers used legitimate credentials to mask their actions, simulating administrative operations while systematically erasing their traces
Illustration: Lawing Tech
Immediate Measures to Limit Damage and Trace Funds
Upon detecting the intrusion, Bitget isolated affected systems, revoked and reissued internal credentials, and disabled the vulnerable functionality. The exchange also published compromised wallet addresses in real time and a transaction tracking dashboard, urging other crypto platforms, stablecoin issuers, and decentralized bridges to monitor these flows. TRM Labs has already established connections between the stolen funds and wallets used to launder previous thefts attributed to the TraderTraitor group, though Bitget still suspects a link to North Korean actors without formal evidence.
Bitcoin withdrawals were restored on September 28, 2026, followed progressively by other assets until October 2, 2026. Bitget assures that user balances were unaffected, thanks to its protection fund worth $464 million, sufficient to cover the losses. A detailed incident report is expected to be published this week.
What This Changes Here: Strengthened Vigilance for African Platforms
This attack reminds African financial platforms, whether operating in crypto or traditional banking services, of the crucial importance of systematically verifying third-party tools integrated into their infrastructures. In Benin and West Africa, where the digitalization of financial services is advancing rapidly, a similar vulnerability in an external security software could expose customer funds or sensitive data, especially if attackers manage to mimic legitimate operations.
Local authorities should also strengthen audits of technological partnerships , particularly for projects related to blockchain or electronic payments, where dependencies on external software solutions are common. Collaboration with specialized firms like Mandiant or SlowMist could become a standard, especially after incidents like Bitget’s, which demonstrate how an isolated vulnerability can trigger cascading consequences.
Finally, the transparency adopted by Bitget, publication of compromised addresses and public tracking of funds, could inspire African regulators to demand similar mechanisms for supervised platforms, to limit the risks of large-scale money laundering or misappropriation.
A protection fund and emergency programs to restore confidence
To reassure its users, Bitget activated two temporary initiatives: the Bitget Alliance Program and the Project Stand Together , though their precise details have not been disclosed. The protection fund, valued at 464 million dollars, guarantees full coverage of losses, while monthly Proof of Reserves reports (with a 127% ratio) confirm the platform’s solvency. These measures aim to counter post-attack liquidity concerns, a major issue for crypto exchanges in Africa, where distrust of centralized platforms remains high.
Bitget emphasizes that the stolen amount, 388 million dollars, reflects an accurate assessment of identified transactions, excluding any risk of further leakage. However, persistent suspicions surrounding groups like TraderTraitor or North Korean actors underscore the need for local companies to prepare cyberattack response scenarios , including clear communication plans and partnerships with digital investigation experts.
Sources