Bitget Restores BTC Withdrawals Four Days After $388M Exploit of Third-Party Security Tool
Key Takeaways
- •Bitget reopened Bitcoin withdrawals at 08:00 UTC on September 28 across the Bitcoin and BSC networks, with ETH withdrawals scheduled for September 29, USDT for September 30, and remaining services including fiat and P2P for October 2.
- •CEO Gracy Chen confirmed that approximately $388 million in assets were transferred out during the incident, while that user account balances remained unaffected.
- •The attacker exploited a vulnerability in a third-party security product to obtain high-level internal credentials and issue fraudulent withdrawal commands, and Bitget reported that private keys were not compromised and cold wallets were unaffected.
- •As of 09:00 UTC on September 28, Bitget had processed withdrawals totaling 4,098.03574 BTC from 9,585 users, with operations reported as normal.
- •Cybersecurity firms Mandiant and SlowMist are assisting an independent forensic review and on-chain tracing, some affected assets have been frozen through industry collaboration, and an official security report is expected this week.

Cryptocurrency exchange Bitget has begun a phased restoration of withdrawal services following the security incident first identified on September 24, with Bitcoin withdrawals reopening at 08:00 UTC on September 28 across the Bitcoin and BSC networks. In an official statement, CEO Gracy Chen confirmed that approximately $388 million in assets were transferred out during the incident, while stressing that user account balances remain unaffected.
According to the exchange, the attacker leveraged a vulnerability in a third-party security product integrated into Bitget's infrastructure to obtain high-level internal credentials. Those credentials were then used to issue fraudulent withdrawal commands to the wallet system, generating abnormal transfers that circumvented existing risk controls. Bitget stated that private keys were not compromised and cold wallets were not affected. The distinction — a compromise of credentials and command pathways rather than of key material — is central to understanding how the incident stayed confined to portions of the exchange's online wallet infrastructure while its cold storage remained outside the attacker's reach.
The breach marks the first security incident of its nature in Bitget's eight years of operation. Unauthorized transfers involving certain assets began at approximately 18:31 UTC on September 24, moving across multiple blockchains from portions of the exchange's hot and warm wallet infrastructure. The affected systems were isolated, the vulnerability was remediated, and the company said no further unauthorized transfers have been identified since containment. Bitget has since reinforced its withdrawal infrastructure with stricter assessment criteria and deployment controls for third-party products, stronger internal access controls, independent verification for withdrawals, and improved detection of abnormal activity — measures that correspond to each stage of the attack chain the company described, from third-party software oversight to the internal credentials and withdrawal approvals the attacker abused.
The $388 million figure reflects the latest reconciliation and classification of transactions tied to the incident does not represent additional losses after containment, according to the company. Bitget reports a comprehensive Proof of Reserves ratio of 127%, and its dedicated User Protection Fund currently stands at more than $464 million — the disclosures through which the exchange signals its capacity to stand behind user balances, which it reports remained intact throughout the incident.
Phased Withdrawal Schedule and Recovery Efforts
Under the current schedule, ETH withdrawals resume on September 29 across Ethereum, BSC, Arbitrum, Base, and Optimism. USDT withdrawals follow on September 30 across Ethereum, BSC, Solana, and Tron, and other supported tokens, fiat, and P2P services are set to reopen on October 2. Withdrawal availability is being reflected directly on the platform. As of 09:00 UTC on September 28, the exchange had processed withdrawals totaling 4,098.03574 BTC from 9,585 users, with operations reported as normal.
On the investigative side, cybersecurity firms Mandiant and SlowMist continue to support an independent forensic review, examining attack vectors, validating containment and remediation measures, and assisting with on-chain tracing. Bitget is also coordinating with law enforcement, exchanges, blockchain projects, and on-chain security specialists. Some affected assets have already been frozen through industry collaboration, and the exchange has published identified attacker addresses and tracing data to support recovery efforts. An official security report is expected to be completed this week, consolidating the findings of the forensic review into the company's public account of the incident.
Alongside the withdrawal resumption, Bitget has introduced two limited-time programs. The Bitget Alliance Program allows eligible users to share in transaction fees generated through platform trading activity, while Project Stand Together offers temporary fee discounts and extended PRO-level protection to eligible professional clients and market makers.
Source: Metaverse Post