Bitget Hack: How $388 Million Vanished Through a Third-Party Flaw
A zero-day in a third-party security tool let hackers drain $388 million from crypto exchange Bitget in under an hour.
Thirty minutes before Bitget's wallets were drained, someone sent two test transfers worth less than two dollars combined — 0.184 ETH and 193 TRX. Nothing flagged. Then, between 6:58 p.m. and 8:09 p.m. on September 24, seventeen transactions ripped through eight different blockchains and pulled out roughly $388 million.
A Dry Run, Then the Real Thing
What makes the Bitget breach stand out isn't just the size of the loss — crypto exchanges have lost bigger sums before — it's how deliberately the attacker tested the exchange's defenses before committing to the main event. Security researchers who reviewed the incident, including firms Mandiant and SlowMist who are now helping with the investigation, say the small transfers were a probe: amounts low enough to sit under Bitget's automatic risk-control thresholds, letting the attacker confirm their access actually worked before triggering any alarms.
- Two micro-transactions sent quietly, confirming unauthorized access without tripping any alerts
- A 30-minute pause, likely spent preparing the real withdrawal commands
- Seventeen transactions across Ethereum, XRP, Zcash, BNB Chain, Base, Arbitrum, Optimism and Avalanche, draining roughly $361 million worth of crypto in about 70 minutes
Only Bitget's hot and warm wallets — the ones kept connected to the internet for day-to-day withdrawals — were hit. Cold storage, which stays offline and is far harder to reach, was untouched, and the exchange says customer account balances themselves weren't altered.
The Real Vulnerability Wasn't Bitget's Own Code
Here's the part that should worry every exchange, bank, and fintech running on outside software: Bitget says the attacker didn't break its systems directly. They exploited a zero-day — industry shorthand for a flaw nobody, including the software's own maker, knew about yet, so there was no patch available — in a third-party security product the exchange relied on. That flaw handed the attacker high-level internal credentials, which were then used to push fraudulent withdrawal commands as if they came from Bitget itself.
Two transfers under the radar. Thirty minutes of quiet. Then $361 million gone before anyone could react.
Bitget has since restricted internal access, added independent checks on withdrawal approvals, and says it's reviewing how it vets the third-party security tools it plugs into its own infrastructure. The company's $465 million user-protection fund, built up since 2022, is covering the stolen balances, and it's being topped back up to at least $300 million from corporate reserves within a week.
Why This Matters for Indian Crypto Users
India doesn't need to look abroad to understand the stakes here. WazirX, one of the country's largest exchanges, lost roughly $230 million in 2024 in an attack attributed to North Korea's Lazarus Group — and it took the platform well over a year to begin even partial repayments to users, with no equivalent of Bitget's dedicated protection fund to fall back on. A large share of Indian retail crypto trading actually happens on exchanges like Bitget, Binance, and similar offshore platforms rather than domestic ones, which means Indian investors carry this exact risk every time they trade, with essentially no recourse through Indian courts or regulators if something goes wrong overseas.
There's also a regulatory angle worth noting. CERT-In, India's nodal cybersecurity agency, requires companies to report major breaches within six hours of detection — a rule aimed at exactly this kind of fast-moving incident. Yet that rule only binds entities operating in India; an exchange headquartered elsewhere has no obligation to tell Indian users anything on that timeline, or at all, unless its own jurisdiction compels it.
The Takeaway
Exchanges have spent years hardening their own code, wallet architecture, and multi-signature approvals. What this incident makes clear is that the next weak point is the vendor stack sitting underneath all of it — the security products, monitoring tools, and infrastructure providers that exchanges trust by default. Expect more platforms to start auditing those vendors with the same scrutiny they apply to their own smart contracts, because attackers have clearly figured out that's often the easier door in.
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Angry
0
Sad
0
Wow
0