Bitget CEO Gracy Chen said the $388 million exploit stemmed from a vulnerability in a third-party security product that allowed the attacker to obtain high-level internal credentials. The attack, which occurred on Sept. 24, used those credentials to issue fraudulent withdrawal commands, but the exchange’s private keys and cold wallets were not compromised. Bitget has since patched the security flaw and tightened its controls with independent verification and enhanced monitoring. Some assets have been frozen with help from other industry participants, but the exchange has yet to disclose total recovery figures. The investigation, supported by Mandiant and SlowMist, continues to assess a possible North Korea link.
Source: Read the original article

