Bitget Hacker Used Custom Withdrawal Tool to Steal $388M…
By Abdelaziz Fathi

AI summary of the source article
Investigations by SlowMist and Mandiant into Bitget's approximately $388 million theft traced unauthorized access back to August 31, over three weeks before the incident was detected. The attacker exploited a zero-day vulnerability in a third-party product to retrieve database passwords, later accessed a management platform using internal employee credentials, and manipulated wallet infrastructure. Investigators found a custom tool designed to forge risk-control parameters and construct withdrawal requests without compromising private keys. Bitget reported its cold wallets remained unaffected, replenished its Protection Fund to over $300 million, and showed a 131% reserve ratio on September 29.
Why it matters
The findings show that an exchange's cryptographic keys can remain secure while compromised third-party software and credentials allow attackers to issue valid-appearing withdrawal requests.
Key facts
- Approximately $387.5 million was transferred to attacker-controlled addresses across multiple blockchains.
- The breach compromised third-party security products and internal credentials, ruling out cold wallet and private-key compromises.
- Bitget reported a total reserve ratio of 131% on September 29 and replenished its Protection Fund to more than $300 million.