The crypto industry has spent years trying to reassure users that the security failures of the past are behind us. Better custody systems, larger insurance funds, sophisticated monitoring tools, and institutional-grade infrastructure were supposed to make major exchange breaches increasingly rare. Yet the alleged $387.5 million Bitget hack shows a far less comfortable reality: centralized exchanges remain one of the industry’s largest structural risks.
According to reports and a post mortem from Bitget, attackers exploited a vulnerability tied to a third-party security product and obtained internal access that allowed fraudulent withdrawals, despite private keys reportedly remaining uncompromised and cold wallets staying untouched. The exchange has also stated that customer balances remain safe and that withdrawals are gradually resuming.
Quick recap from today’s livestream:
1. Withdrawals
BTC live on Bitcoin Mainnet & BSC — 9,585 orders, 4,098.036 BTC processed as of 17:00 UTC+8. ETH, USDT, others follow in phases starting tomorrow.2. What happened
Full trace-back complete. The attacker exploited… pic.twitter.com/BmyTNFJgFC— Gracy Chen @Bitget (@GracyBitget) September 28, 2026
That may sound reassuring, but it misses the bigger point. If hundreds of millions of dollars can leave a platform without stolen private keys, then the industry’s problem is clearly larger than wallet security alone.
The Industry Keeps Solving the Wrong Problem
Every major exchange hack follows a familiar script.
An incident occurs. The platform assures users that funds are safe. A security firm joins the investigation. A recovery program launches. Management promises transparency and publishes a future post-mortem. Markets panic for a few days before moving on.
What rarely changes is the custodial model itself.
The Bitget incident reportedly involved compromised internal systems rather than direct cold-wallet exposure. That distinction matters far less than many executives would like investors to believe. Users ultimately trusted a centralized entity to secure assets on their behalf, and that trust created a single point of failure.
The lesson from repeated exchange breaches is not that platforms need larger protection funds. It is that concentration of assets creates irresistible targets. The larger exchanges become, the more attractive they are to highly sophisticated attackers, including state-linked groups that have repeatedly targeted the crypto sector.
No amount of marketing about reserves or insurance changes the fact that millions of users continue to place custody in the hands of organizations that can still be compromised.
North Korean Threats Are Growing Faster Than Exchange Defenses
Many industry observers immediately pointed toward North Korean cyber actors, reflecting growing concern about state-sponsored cryptocurrency theft. Reports connected to the investigation indicate that such possibilities are being examined, though findings remain ongoing.
This is exactly why the current model looks increasingly outdated.
Exchanges are fighting adversaries with virtually unlimited patience, funding, and technical expertise. Even if one attack route is closed, another eventually appears. Backend systems, employee credentials, vendor software, and operational processes all expand the potential attack surface.
The uncomfortable truth is that centralized organizations must defend everything. Attackers only need one weakness.
Conclusion
The dispute surrounding the movement of funds through THORChain highlights a deeper philosophical divide within crypto. Some want decentralized networks to intervene when stolen funds move across protocols. Others argue that permissionless systems should remain neutral regardless of circumstance.
Regardless of where someone stands on that debate, the Bitget hack reinforces a conclusion that becomes harder to ignore after every major breach: custody risk remains crypto’s most persistent vulnerability.
The industry’s long-term answer is unlikely to come from bigger emergency funds, stronger public relations responses, or another promise that investigations are underway. Real progress requires reducing dependence on centralized custodians altogether.
That means accelerating adoption of self-custody, improving on-chain user experiences, and expanding decentralized trading infrastructure capable of handling institutional-scale volume. Centralized exchanges will continue to play a role, particularly as onboarding gateways, but treating them as permanent vaults for enormous amounts of capital looks increasingly difficult to defend.
The safest future for crypto may be the one that requires trusting intermediaries the least.




Be the first to comment