Bitget CEO Gracy Chen has confirmed that the recent $388 million exploit was the result of a critical security vulnerability found in a third-party service integrated into the exchange's ecosystem. The breach allowed attackers to bypass standard withdrawal limits, leading to one of the largest centralized exchange losses seen in early 2026. While the exchange's internal protocols reportedly remained secure, the external dependency served as a 'backdoor' for the sophisticated threat actors.
In the immediate aftermath, Bitget worked with global cybersecurity firms and law enforcement to track the movement of the stolen funds. As of this week, a significant portion of the assets has been successfully frozen on-chain, though Bitget has not yet disclosed the exact dollar amount recovered. The investigation has now shifted toward a geopolitical focus, as forensic evidence points to signature techniques frequently utilized by North Korean hacking collectives, such as the Lazarus Group.
This incident underscores the rising threat of supply-chain attacks within the crypto industry, where hackers target third-party vendors to compromise major platforms. US regulators are likely to use this breach as a catalyst for stricter oversight regarding how exchanges manage external service provider risks. The exploit highlights that even if a platform has robust internal controls, its weakest link may be an external software library or security partner.
For the broader market, the hack has temporarily dampened sentiment toward centralized exchanges (CEXs), driving a short-term migration of assets to self-custody solutions. Bitget has reassured users that its $300 million Protection Fund remains intact and will be used to cover legitimate user losses. Moving forward, investors should watch for the full forensic report and any official statements regarding the definitive attribution of the attack to North Korean actors.