On 24 September, at 18:31 UTC, someone moved 0.184 ETH out of one Bitget hot wallet and 193 TRX out of another. Both transfers were tiny, and both stayed below the exchange's risk-control threshold, so no alert fired, according to CEO Gracy Chen.
About half an hour later the same access was used for 17 larger transactions across eight blockchains, between 18:58 and 20:09 UTC. The exchange puts the total stolen at roughly $388 million.
According to The Hacker News and The Block:
The vulnerability has been patched, and Bitget has revoked and reissued internal credentials. Some details, including the product's name, have not been made public. Treat the attribution as unconfirmed until the report is out.
Security products sit in a privileged place. They see traffic, hold credentials and often have the access needed to change how other systems behave. That is what makes them useful, and it is also why a flaw in one is worth a lot to an attacker. We saw the same pattern two weeks ago when Check Point's management servers were open to attackers for two months.
Bitget did nothing unusual by running third-party security software. What matters is what the attacker got: valid credentials with administrative reach. From that point on there was no exploit to detect. Everything after it looked like an administrator using an administrative system.
The probe was the only warning, and it fell below the line. The two test transfers were sized to sit under a static threshold. A fixed limit tells an attacker exactly how much they can move without being noticed, and a probe can find that limit for the price of a few dollars. The useful signal was not the size of the transfers. It was that an account that normally did not initiate withdrawals started doing so, in an unusual way, minutes before a burst of activity.
Deleting traces only works if the traces live somewhere the attacker can reach. If the only record of a fraudulent command is on the system that ran it, then an attacker with administrative access can remove it. Detection here came from reconciliation, meaning a comparison of what the ledger says with what the wallets did. That was the right instinct, and it took seven minutes. Comparing balances is a control that does not depend on the logs an attacker can edit.
Obiguard SOC is for teams that need the evidence and the alert to sit somewhere the compromised system can't reach. Two parts apply directly to this incident.
A copy of the logs that the attacker didn't write. SOC ingests logs from your applications, cloud and infrastructure into a separate store. If a wallet service, admin console or security appliance later has its own records edited, the forwarded copy still shows the commands that ran, with host, level and time. In Live Logs you can search across every source at once, so a question such as "which admin identity issued a withdrawal at 18:58?" has one place to be answered.
Alerts you can write for the sequence, not only the size. SOC raises alerts from log-volume changes and rule matches, and each alert keeps an evidence timeline linked to the raw events behind it. A rule that matches any withdrawal command issued by an admin identity, whatever the amount, would have flagged the two probes. A sudden jump in admin-service log volume would have flagged the burst. Neither depends on a threshold the attacker can measure.
SOC will not stop a zero-day in a vendor's product, and it does not replace the reconciliation controls that caught this theft. What it does is shorten the time between the first odd action and someone looking at it, and it gives your investigators a record they can trust when the attacker has tried to erase the rest.
Bitget noticed in seven minutes, which is faster than most organisations manage. But the attacker still had the time to make 17 transfers, because the first two, the ones that mattered, raised nothing.
So the question is not is our security vendor patched? It is: if one of our privileged tools were compromised tonight, would the first strange thing it did reach a person before the tenth?
Explore Obiguard SOC or talk to us about sending your admin, wallet and security-tool logs to an independent timeline with alerts on the actions that should never happen quietly.
Obiguard sits in front of every AI request your organization makes — screening prompts and outputs against the guardrails, compliance frameworks, and audit trails that stories like this one make necessary.
See how it works →