Bitget reveals attack path behind $387.5M breach as Bitcoin withdrawals restart
Gracy Chen said attackers exploited vulnerabilities in a third-party product to steal internal credentials and bypass the exchangeās withdrawal controls.
Bitget has begun restoring withdrawals following its $387.5 million security breach, as CEO Gracy Chen disclosed new details about how attackers gained access to the exchangeās systems.
Quick recap from today's livestream:
1. Withdrawals
BTC live on Bitcoin Mainnet & BSC ā 9,585 orders, 4,098.036 BTC processed as of 17:00 UTC+8. ETH, USDT, others follow in phases starting tomorrow.2. What happened
Full trace-back complete. The attacker exploited⦠pic.twitter.com/BmyTNFJgFC— Gracy Chen @Bitget (@GracyBitget) September 28, 2026
Bitcoin withdrawals are now live on the Bitcoin network and BNB Smart Chain. Chen said in a post on X following a livestream that Bitget had processed 9,585 withdrawal orders totaling 4,098.036 BTC as of 17:00 UTC+8 on Monday. Ether, USDT and other assets are set to follow in phases.
The reopening comes four days after Bitget suspended withdrawals following the September 24 exploit. The exchange began processing Bitcoin withdrawals at 08:00 UTC Monday after completing additional security checks, with other assets scheduled to return through October 2.
Chen also provided Bitgetās most detailed explanation yet of how the attack occurred. She said the attacker exploited vulnerabilities in third-party products to obtain internal credentials and then used those credentials to issue fraudulent withdrawal commands that bypassed the exchangeās risk controls.
Private keys were not compromised and Bitgetās cold wallets were not affected, according to Chen.
The news moving money, markets, and the world—before your day starts.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
The exchange said it isolated the affected systems and servers, revoked and reissued internal credentials and restructured access to highly sensitive infrastructure. It also notified the third-party vendor involved and disabled the affected functionality while the vulnerability is addressed.
Mandiant and SlowMist continue to support the forensic investigation and tracing of stolen assets.
Bitget initially estimated that $351.6 million had been affected after detecting unauthorized transfers at 18:31 UTC on September 24. It later raised the figure to approximately $387.5 million after identifying additional Zcash and TRON transfers, saying the increase represented a more complete accounting rather than additional theft.
The exchange has maintained that user balances are unaffected and that losses will be covered by its Protection Fund. The fund held more than $464 million when the incident was first disclosed. Chen said Monday that Bitget will replenish the fund with its own capital to bring its value back above $300 million within a week.
Bitget has historically committed to maintaining the Protection Fund above $300 million. Its August report placed the fundās average monthly value at $382 million.
Chen also announced āProject Stand Together,ā a program offering a trading-fee reward pool and additional benefits and protections for eligible retail, VIP, professional and market-making users.
The CEO described the breach as Bitgetās first security incident of this nature in eight years and said the exchange is now focused on recovery, strengthening its safeguards and disclosing further findings from the investigation.