If you keep a balance on a centralised crypto exchange, the Bitget case has read differently since September 28. The exchange's own keys were not cracked, and no cold wallet was emptied. The attacker came in through a security product that Bitget itself had bought, and used that product's privileges to pose as an administrator. On the figures published so far, the damage lies between $387.5 million and $388 million. For you, that means the question of whether an exchange is well secured does not hang on its own technology alone, but on every supplier it lets inside its systems.
This article sets out the attack path, names the documented figures and the schedule under which withdrawals are restarting. It also says which parts of it touch a decision of your own, and which remain corporate news and nothing more.
What Bitget says about the attack path
On the company's account, the attacker exploited a zero-day vulnerability in a third-party security product. Zero-day means a flaw that the software maker did not know about at the time of the attack, so there was neither a patch nor a warning. Through that flaw the attacker obtained valid administrator credentials. With those credentials he ...


English (US)