Bitget reveals attack path behind $387.5M breach as Bitcoin withdrawals restart

Bitget reveals attack path behind $387.5M breach as Bitcoin withdrawals restart

Gracy Chen said attackers exploited vulnerabilities in a third-party product to steal internal credentials and bypass the exchange’s withdrawal controls.

Bitget has begun restoring withdrawals following its $387.5 million security breach, as CEO Gracy Chen disclosed new details about how attackers gained access to the exchange’s systems.

Bitcoin withdrawals are now live on the Bitcoin network and BNB Smart Chain. Chen said in a post on X following a livestream that Bitget had processed 9,585 withdrawal orders totaling 4,098.036 BTC as of 17:00 UTC+8 on Monday. Ether, USDT and other assets are set to follow in phases.

The reopening comes four days after Bitget suspended withdrawals following the September 24 exploit. The exchange began processing Bitcoin withdrawals at 08:00 UTC Monday after completing additional security checks, with other assets scheduled to return through October 2.

Advertisement

Chen also provided Bitget’s most detailed explanation yet of how the attack occurred. She said the attacker exploited vulnerabilities in third-party products to obtain internal credentials and then used those credentials to issue fraudulent withdrawal commands that bypassed the exchange’s risk controls.

Private keys were not compromised and Bitget’s cold wallets were not affected, according to Chen.

The exchange said it isolated the affected systems and servers, revoked and reissued internal credentials and restructured access to highly sensitive infrastructure. It also notified the third-party vendor involved and disabled the affected functionality while the vulnerability is addressed.

Mandiant and SlowMist continue to support the forensic investigation and tracing of stolen assets.

Bitget initially estimated that $351.6 million had been affected after detecting unauthorized transfers at 18:31 UTC on September 24. It later raised the figure to approximately $387.5 million after identifying additional Zcash and TRON transfers, saying the increase represented a more complete accounting rather than additional theft.

The exchange has maintained that user balances are unaffected and that losses will be covered by its Protection Fund. The fund held more than $464 million when the incident was first disclosed. Chen said Monday that Bitget will replenish the fund with its own capital to bring its value back above $300 million within a week.

Bitget has historically committed to maintaining the Protection Fund above $300 million. Its August report placed the fund’s average monthly value at $382 million.

Chen also announced ā€œProject Stand Together,ā€ a program offering a trading-fee reward pool and additional benefits and protections for eligible retail, VIP, professional and market-making users.

The CEO described the breach as Bitget’s first security incident of this nature in eight years and said the exchange is now focused on recovery, strengthening its safeguards and disclosing further findings from the investigation.

Disclosure: This article was edited by Estefano Gomez. For more information on how we create and review content, see our Editorial Policy.
Bitget reveals attack path behind $387.5M breach as Bitcoin withdrawals restart
Bitget reveals attack path behind $387.5M breach as Bitcoin withdrawals restart

Gracy Chen said attackers exploited vulnerabilities in a third-party product to steal internal credentials and bypass the exchange’s withdrawal controls.

Bitget has begun restoring withdrawals following its $387.5 million security breach, as CEO Gracy Chen disclosed new details about how attackers gained access to the exchange’s systems.

Bitcoin withdrawals are now live on the Bitcoin network and BNB Smart Chain. Chen said in a post on X following a livestream that Bitget had processed 9,585 withdrawal orders totaling 4,098.036 BTC as of 17:00 UTC+8 on Monday. Ether, USDT and other assets are set to follow in phases.

The reopening comes four days after Bitget suspended withdrawals following the September 24 exploit. The exchange began processing Bitcoin withdrawals at 08:00 UTC Monday after completing additional security checks, with other assets scheduled to return through October 2.

Advertisement

Chen also provided Bitget’s most detailed explanation yet of how the attack occurred. She said the attacker exploited vulnerabilities in third-party products to obtain internal credentials and then used those credentials to issue fraudulent withdrawal commands that bypassed the exchange’s risk controls.

Private keys were not compromised and Bitget’s cold wallets were not affected, according to Chen.

The exchange said it isolated the affected systems and servers, revoked and reissued internal credentials and restructured access to highly sensitive infrastructure. It also notified the third-party vendor involved and disabled the affected functionality while the vulnerability is addressed.

Mandiant and SlowMist continue to support the forensic investigation and tracing of stolen assets.

Bitget initially estimated that $351.6 million had been affected after detecting unauthorized transfers at 18:31 UTC on September 24. It later raised the figure to approximately $387.5 million after identifying additional Zcash and TRON transfers, saying the increase represented a more complete accounting rather than additional theft.

The exchange has maintained that user balances are unaffected and that losses will be covered by its Protection Fund. The fund held more than $464 million when the incident was first disclosed. Chen said Monday that Bitget will replenish the fund with its own capital to bring its value back above $300 million within a week.

Bitget has historically committed to maintaining the Protection Fund above $300 million. Its August report placed the fund’s average monthly value at $382 million.

Chen also announced ā€œProject Stand Together,ā€ a program offering a trading-fee reward pool and additional benefits and protections for eligible retail, VIP, professional and market-making users.

The CEO described the breach as Bitget’s first security incident of this nature in eight years and said the exchange is now focused on recovery, strengthening its safeguards and disclosing further findings from the investigation.

Disclosure: This article was edited by Estefano Gomez. For more information on how we create and review content, see our Editorial Policy.