Loading prices...
All news
Shield split by a glowing crack with shards flying, a vault door standing ajar beside it

Bitget's loss grew from $352m to $388m, and the flaw was not its own

03:00 · 29.09.2026
Source: Cointelegraph
0

Bitget now puts the September breach at $388m, against the $352m it first reported. The money left multiple hot wallets on 24 September, and the vulnerability that made it possible sat in a third-party security product, not in the exchange's own code.

“We understand that THORChain operates as a decentralized protocol and has said that it cannot selectively blacklist individual addresses.”

— Gracy Chen, Bitget

Gracy Chen, chief executive of Bitget

How the Bitget hack ran through the week:

  • 24 September: attackers drain multiple hot wallets. Bitget detects the transfers the same day and suspends withdrawals.
  • First public figure: $352m.
  • 28 September: the figure is $388m, up $36m or 10.2% on the first estimate.
  • Cold wallets and private keys were not touched.
  • Mandiant and SlowMist are supporting the independent forensic work.

The mechanism matters more than the total. Chief executive Gracy Chen says the flaw let the attacker obtain high-level internal credentials, which were then used to issue withdrawal commands the exchange processed as legitimate. Nothing was broken into in the sense people imagine. The system did what it was told, by someone it had been persuaded to trust. Cold storage was untouched because cold storage does not take instructions over a network.

The vendor nobody has named

One detail deserves more attention than it is getting: the vulnerable product has not been named. Every other exchange running the same tool is now exposed to a flaw it cannot identify, and the decision not to say which vendor failed protects the vendor at the expense of everyone else on the same stack. We watched a version of this play out in September, when three Trezor incidents in 28 days all came through suppliers rather than the devices themselves. The soft edge of a hardened system is usually somebody else's software.

The recovery picture is where the week's other story intrudes. Some assets have been frozen with help from industry participants, and Chen notes that THORChain cannot selectively blacklist individual addresses because it is a decentralised protocol. Read that beside the Senate report on Tether, which turned on the opposite fact: a centralised issuer can freeze, and froze $550m of Iran-linked tokens this year. Money that reaches a router nobody controls stops being recoverable, and the attacker's route is the thing that decides which of those two worlds the funds end up in.

What freezing can and cannot reach

Bitget has not said how much has come back, and has not published a reimbursement position. Mandiant and SlowMist are on the forensics, which is the right pair of names for an incident of this size and also a signal that the internal answer was not obvious. Four days in, the only number that has moved is the loss, and it moved upward.

The figure to watch is not $388m. It is whatever the third number turns out to be, and whether anyone names the product before the next exchange finds out the hard way that it was running it too.

Informational only, not investment advice. The forensic work is ongoing, Bitget has not disclosed how much has been recovered, and the figure has already moved once.

Published: 03:00 · 29.09.2026
Maks

Author

Maks

Trading man

I've been interested in the cryptocurrency market for a long time, am a trader, and write articles and news about my experience and crypto in simple terms.

Comments (0)

No comments yet — be the first!

The market talks all day. We write when it says something

Short, and it tells you why it came