Bitget, a prominent cryptocurrency exchange, has suffered a significant security breach resulting in the theft of approximately $388 million. The breach was carried out by an attacker who exploited a vulnerability in a third-party security product, gaining access to Bitget's internal credentials. On September 24, the attacker used these credentials to issue fraudulent withdrawal commands to the exchange's wallet system, targeting its hot and warm wallets. Fortunately, Bitget's cold wallets remain untouched, safeguarding most customer funds. Bitget CEO Gracy Chen explained that the flaw allowed the attacker to infiltrate an internal management system and carry out unauthorized transactions. Initial small test transfers went unnoticed, but larger fraudulent transfers followed, bypassing risk controls. Despite the breach, the exchange confirmed that no private keys were compromised. Bitget has responded by notifying the affected vendor, isolating compromised systems, and revoking internal credentials. They have also added independent checks on withdrawals and enhanced monitoring for unusual activity. The exchange has reopened Bitcoin withdrawals and plans to resume other asset withdrawals in stages. Bitget's Protection Fund will cover the financial loss, ensuring customer accounts remain unaffected. While suspecting North Korean involvement, Bitget has refrained from naming any specific group pending further investigation. TRM Labs identified potential links to North Korean cybercriminals, suggesting the involvement of the TraderTraitor group. Bitget has shared the main addresses involved in the theft and urged exchanges and other entities to monitor these addresses. The investigation is ongoing, with Bitget working alongside security firms Mandiant and SlowMist to publish a detailed incident report soon.