# Bitget CEO Says Third-Party Flaw Enabled $380 Million Theft

By Simon Yoon

Canonical URL: https://www.tokenpost.com/news/technology/24803
Published: 2026-09-28T08:27:49.000Z
Updated: 2026-09-28T08:27:49.000Z
Section: Technology

> Gracy Chen said hackers stole internal access credentials, forged withdrawal commands and bypassed risk checks without compromising private keys.

Bitget CEO Gracy Chen said hackers exploited a vulnerability in a third-party security product to steal internal access credentials and execute roughly $380 million in unauthorized transfers.

During a community livestream on Sept. 28, Chen said the attackers used the credentials to forge withdrawal commands sent to Bitget’s wallet system and bypass risk checks. She said private keys were not compromised and that cold wallets were unaffected.

Chen said the verified loss falls within Bitget’s protection-fund coverage. The exchange plans to restore the fund to its $300 million baseline within a week.

Bitcoin (BTC) withdrawals have resumed. Ether (ETH), Tether (USDT) and other withdrawals will restart according to the previously announced schedule.

Bitget will release additional technical details in a follow-up security report.
