# Bitget says $388M theft stemmed from stolen internal credentials approved as legitimate withdrawals

*Monday, September 28, 2026 at 6:07 PM UTC — Hamer Intelligence Services Desk*

**Published**: 2026-09-28T18:07:21.819Z (1h ago)
**Category**: cyber | **Region**: Global
**Importance**: 8/10
**Sources**: OSINT
**Permalink**: https://hamerintel.com/data/articles/19080.md
**Source**: https://hamerintel.com/summaries

---

**Deck**: Crypto exchange Bitget says an attacker exploited a flaw in a third‑party security product to steal high‑level internal credentials, then used them to authorize $388 million in fraudulent withdrawals that the wallet system treated as legitimate. The breach highlights how deeply exchanges depend on vendors that sit inside their security perimeter.

A massive theft at crypto exchange Bitget has exposed how a single weak link in a security stack can unlock direct access to customer funds.

Bitget says an attacker took advantage of a flaw in a third‑party security product, obtained high‑level internal credentials, and used them to order withdrawals worth about $388 million. According to the company’s account, its wallet system accepted the fraudulent commands as genuine because they appeared to come from trusted internal sources, letting the attacker bypass normal risk controls.

In effect, the breach turned the exchange’s own systems into the tool for draining funds. There is no public breakdown yet of which assets were stolen, how many users were affected, or what role law enforcement may be playing. Bitget is presenting the incident as a failure at an external vendor rather than a direct compromise of its core infrastructure.

For customers, the distinction between a vendor flaw and an in‑house bug changes little. If a third‑party product used for authentication or access control is compromised, anyone who obtains those credentials can move funds with the authority of senior staff or automated systems.

The incident puts pressure on other exchanges and custodians to re‑examine where they rely on outside products to manage identities and permissions and how those tools interact with wallet software. It also gives regulators and auditors a concrete example as they push for tighter controls around key management, segregation of duties and real‑time monitoring of privileged access.

A central lesson is that strong on‑chain security and proof‑of‑reserves checks can still be sidestepped if internal commands are trusted without enough independent verification. When high‑level credentials are stolen, systems may obediently execute withdrawal orders that look valid from the inside.

Signals to watch now include how Bitget plans to cover the loss, whether other platforms report similar vulnerabilities or rotate critical credentials, and how quickly financial regulators reference this case when arguing for stricter standards on crypto‑exchange security.
