Bitget lost about 388 million dollars, and the way in was the security product
2026-10-01Security
The exchange's own account says attackers may have used a flaw in a third-party security product to obtain high-level internal credentials, then issued withdrawal commands its systems accepted. Mandiant and SlowMist are reported to date the access to 31 August, three and a half weeks before the transfers. Cold wallets were untouched and private keys were not taken.