Bitget CEO details zero-day exploit behind $380M theft
Security & Exploits ·
Gracy Chen said attackers used a flaw in outside security software to seize internal credentials and push through fake withdrawal orders.
Speaking during a livestream on September 28, Bitget's chief executive Gracy Chen laid out how a breach drained roughly $380M from the exchange, as detailed in a clip circulated on X. According to her account, intruders did not crack Bitget's own defenses directly but instead found a zero-day gap in a third-party security tool, which gave them internal login credentials. With that access, they reached the backend systems controlling wallets, injected fraudulent withdrawal instructions, sidestepped the platform's risk-control checks, and then wiped records of the transfers to cover their tracks.
Chen said the exchange's private keys themselves were never touched, and that an internal job has for now been ruled out, though Bitget has not publicly identified who carried out the attack and intends to publish a fuller incident report later. Separate reporting from The Block indicates the attacker first tested the exchange's defenses with small transfers before executing the roughly $388 million theft, and that Bitget's user protection fund is expected to absorb the losses.
Other accounts in the same episode describe the incident hitting withdrawal infrastructure across multiple chains, forcing Bitget to restore withdrawal service in phases while the protection fund covered affected users. Attention has since shifted to where the stolen funds are going: reports point to Chinese-linked laundering operations moving the money through cross-chain bridges and the Wasabi mixer, a pattern outlined in coverage from wublockchain.xyz. Some of those tracing the funds have suggested a possible connection to North Korea-linked actors and to an earlier Kelp DAO exploit, while separate observations note that individuals tied to the laundering effort have been soliciting help through public Discord and Telegram channels.
What remains unclear is the identity of the attackers, the exact mechanics of the zero-day flaw in the compromised security product, and whether any funds can ultimately be recovered or frozen as they move through bridges and mixers. Bitget's promised incident report is expected to fill in some of those gaps.