Bitget Begins Phased Withdrawals After $388M Exploit Shook The Platform

Bitget
Table of Contents

TL;DR

  • Bitget began phased withdrawals following the exploit that occurred on September 24, in which approximately $388 million were stolen from the platform.
  • The attacker exploited a vulnerability in a third-party security product to obtain internal credentials and execute fraudulent transfers.
  • The exchange confirmed that its user protection fund, holding 5,500 BTC, will fully cover the losses from the incident.

Bitget began the phased resumption of withdrawals, four days after an exploit drained approximately $388 million from its hot and warm wallet infrastructure. The process started at 8 a.m. UTC today. Withdrawals of BTC on the Bitcoin and BSC networks were the first to be enabled.

The exchange explained that each network must pass a series of security checks before withdrawals are enabled, which is why the restoration is being carried out in stages. ETH withdrawals on Ethereum, BSC, Arbitrum, Base and Optimism will become available on September 29 at 8 a.m. UTC. USDT withdrawals on Ethereum, BSC, Solana and Tron will resume the following day at the same time. Remaining assets, fiat withdrawals and P2P transactions will be operational by October 2.

Bitget: A Third-Party Vulnerability was the Key to the Attack

The exploit occurred on September 24 at 6:31 p.m. UTC. According to the exchange, the attacker exploited a flaw in a third-party security product to obtain high-level internal credentials, which were used to send fraudulent commands to the wallet system and execute anomalous transfers that bypassed risk controls. The exchange’s private keys were not compromised, and both user balances and cold wallets remained intact.

Among the transferred assets, ETH, USDT, USDC, AVAX and BNB were identified. Bitget stated that the vulnerability has already been patched and that no unauthorized transfers have occurred since. Mandiant and SlowMist are collaborating on the investigation, and the exchange expects to publish an official security report before the end of the week.

The scale of the theft makes it the largest hack in the crypto industry recorded so far in 2026, surpassing the incidents that affected KelpDAO and Drift Protocol. Nevertheless, the exchange confirmed that the Bitget User Protection Fund, which holds 5,500 BTC, will cover the entirety of the losses.

Bitget

The Protection Fund and the Hunt for Stolen Funds

In parallel, Bitget launched a bounty program offering 5% of the funds that are effectively frozen or recovered through the direct action of third parties. The exchange noted that some affected assets have already been frozen through coordination with industry partners, though it did not specify the amounts.

Regarding the identity of those responsible, Bitget stated that the attackers are “sophisticated” and have state backing, previously pointing to North Korea as the primary suspect, while clarifying that it will not draw definitive conclusions until the investigation confirms it.

RELATED POSTS

Ads

Follow us on Social Networks

Crypto Tutorials

Crypto Reviews