In a September 28 livestream, Bitget CEO Gracy Chen stated that attackers exploited a zero-day vulnerability in a third-party security product to obtain internal credentials. They then used these credentials to access wallet backend systems, insert fraudulent withdrawal commands, bypass risk controls, and delete transfer traces. Chen added that private keys were not compromised and an inside job has been preliminarily ruled out. Bitget plans to release an incident report.