Bitget Exchange Loses $387 Million After Attacker Bypasses Transaction Approval Controls
What Happened — An adversary transferred approximately $387.5 million from Bitget’s online cryptocurrency wallets by manipulating transaction data and subverting the platform’s internal approval process. Private keys and the exchange’s offline (cold‑storage) wallets were not compromised, and withdrawals were suspended once the activity was detected on Sept 24.
Why It Matters for Trust & Control Assurance
- Highlights the risk of inadequate access‑control and transaction‑approval safeguards that a continuous‑control‑assurance program is built to detect and evidence.
- Demonstrates the need for immutable logging of privileged actions to provide a defensible audit trail after a breach.
- Shows how real‑time monitoring of wallet‑system activity can surface anomalous transfers before large‑scale loss occurs.
Who Is Affected – Cryptocurrency exchanges, digital‑asset custodians, and broader fintech firms that manage online wallets and high‑value transaction flows.
Recommended Actions –
- Conduct a forensic review of the transaction‑approval workflow; enforce multi‑party approval and least‑privilege for API keys.
- Deploy continuous monitoring and immutable logging of all wallet‑related actions, with alerts for out‑of‑policy transfers.
- Verify that cold‑storage procedures remain truly air‑gapped and are documented as part of your audit evidence.
Technical Notes – The attacker exploited a flaw in the exchange’s internal approval logic, allowing forged transaction metadata to pass validation. No private‑key compromise was reported; the loss stemmed from a process‑level vulnerability rather than a cryptographic break. Source: DataBreachToday