Bitget says attackers exploited third-party security flaw, no private keys leaked
September 28, 2026, 9:24 AM
Bitget said its investigation into a recent security incident found that attackers exploited a vulnerability in an external security product to obtain internal authentication credentials. In a post on X, the exchange said the attackers used those credentials to send fraudulent withdrawal instructions to its wallet system, bypass risk controls, and trigger abnormal transfers. Bitget added that no private keys were leaked and its cold wallets were not affected.
The exchange also said it had disclosed the attacker addresses and related on-chain tracking data, and plans to complete its internal security report this week.
Previous related news
Leave the first comment
You need to log in to leave a comment.
Log In