# Bitget says third-party product flaw enabled $388 million theft

_Published Monday, September 28, 2026 at 4:08 PM EDT · Security, Products · Latest · Tier 1 — Major_

![Bitget says third-party product flaw enabled $388 million theft — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgA8s-yMULxIXnKcHnHw7w1dF9pt58MDYc_-_wfJPo8ifPgGoD0GZcgE408ZdC1GbZvjp2wOOEYrlR8obpFEXZ-KUSjIBXFFb3LcswKfAd3EODISE5hSkU-QplYeZDnK95i0QrJhNZKcKEVgedmkKjAme9PV4vDLV-OY7Bh9KhCINbGuglY49greoPLCJQ/s1700-nu-rw-lo-l85-e365/bitget-hacker.jpg)

Bitget says the attacker who stole about $388 million from its cryptocurrency exchange exploited a flaw in a third-party security product to obtain high-level internal credentials. The account adds an entry point to Bitget's earlier disclosure that its wallet backend had been compromised. On September 24, the attacker used those credentials to send fraudulent withdrawal commands that the wallet system treated as legitimate.

Bitget says the stolen funds came from hot and warm wallets, while cold wallets and customer account balances were unaffected. It has isolated affected systems, replaced credentials and added withdrawal checks. The exchange has not named the security product, and its investigation remains in progress.

## Sources

- [The Hacker News](https://thehackernews.com/2026/09/bitget-says-attacker-exploited-third.html)

---
Canonical: https://techandbusiness.org/newswire/OVX5BiNHo4K4kMbJ8cppUx
Published: 2026-09-28T20:08:11.905Z
Story chronology: 2026-09-28T17:42:18.000Z
Retrieved: 2026-09-28T22:07:01.030Z
Publisher: Tech & Business (techandbusiness.org)
