Start with Identity
News

Bitget's $388 million theft ran on legitimate admin credentials through a third-party security product

Attackers exploited a zero-day in an unnamed security product Bitget used, reached an internal management system, and inserted withdrawal commands while posing as administrators. Private keys were never touched; they did not need to be.

By SWI Community TeamSep 28, 2026

The cryptocurrency exchange Bitget said on September 28 that the attacker who stole about $388 million on September 24 got in through a zero-day in a third-party security product the exchange used. The flaw gave access to an internal management system, from which the attacker inserted fraudulent withdrawal commands into backend wallet services from hot and warm wallets. Chief executive Gracy Chen said the attackers used legitimate credentials, posed as administrators, and removed traces of their actions. Two small test transfers at 18:31 UTC stayed below alert thresholds before larger transfers about 30 minutes later. Bitget says private keys were not compromised and cold wallets were unaffected. It has not named the product or said whether a fix exists. Bitget suspects North Korean attackers; TRM Labs found overlaps with the TraderTraitor group without a firm attribution.

Why it matters

"The private keys were safe" is the least reassuring sentence in the disclosure. The keys did not need to leave, because the management plane could instruct the wallet service to sign, and anyone holding an administrator's credentials in that plane could issue the instruction. The control that failed is separation of duties: withdrawal authorization lived in the same trust domain as administrative access, so compromising one gave you the other. Bitget has since added independent withdrawal checks, which is the right fix and the one to verify you already have: a high-value action approved through a separate channel that the admin session cannot reach.

The entry point deserves the same attention it got at Cisco FMC and Cisco ISE this month. Security products run with broad access and are trusted by the systems around them, which makes them privileged identity infrastructure whether or not they are inventoried that way. The test transfers under the alert threshold are the detection lesson: thresholds tuned to amounts miss an attacker who is checking whether the pipe works. See zero standing privileges.

Source: The Hacker News

Last reviewed By SWI Community TeamSuggest a correctionHow we research
Independent analysis. No vendor sponsorship.