Bitget has resumed Bitcoin withdrawals following a September 24 security breach that resulted in $388 million in unauthorized transfers. The exchange is currently working with security firms Mandiant and SlowMist to investigate the incident and recover assets.

Advertisement

A third-party vulnerability and the $388 million drain

Bitget reported that an attacker exploited a flaw in a third-party security product to gain high-level internal credentials. According to Bitget, these credentials allowed the perpetrator to issue fraudulent withdrawal commands that bypassed the exchange's risk controls, leading to "abnormal transfers" totaling approximately $388 million.

This breach marks a significant failure in the exchange's perimeter defense . As reported by the exchange, this is the first security incident of this nature in Bitget's eight years of operation.. The vulnerability was identified and remediated four days after the initial attack on September 24.

The phased return of BTC and ETH withdrawals

Bitget began a staged restoration of its services on September 28, starting with Bitcoin (BTC) withdrawals on the Bitcoin and BSC networks at 08:00 UTC. By 09:00 UTC that same day, Bitget had processed 9,585 BTC withdrawals ,amounting to roughly 4,098 BTC.

The restoration schedule continues with Ethereum (ETH) withdrawals resuming on September 29 and USDT withdrawals on September 30. All other supported tokens, P2P services, and fiat withdrawals are slated to return by October 2. To mitiagte user frustration, Bitget is providing temporary fee benefits and extended PRO-level protection for eligible market makers and clients through October 30.

The $464 million User Protection Fund as a safety net

To reassure its user base, Bitget highlighted its financial buffers, reporting a 127% reserve ratio. The exchange also maintains a User Protection Fund that exceeds $464 million, a figure that suggests Bitget has enough dedicated capital to cover the $388 million loss without dipping into user deposits.

This incident reflects a broader trend in the cryptocurrency industry where the reliance on interconnected third-party security tools creates a "single point of failure" risk. While Bitget claims user account balances were not affected,the breach underscores how high-level internal credentials can render traditional risk controls obsolete once an attacker is inside the system.

Which third-party tool failed and who is the attacker?

Despite the detailed timeline, several critical pieces of information remain missing. Bitget has not yet named the specific third-party security prduct that was exploited, leaving other exchanges that might use the same tool in the dark. Furthermore, while Bitget is working with Mandiant and SlowMist on forensics, the identity of the attacker remains unknown.

There is also the question of how much of the $388 million can actually be recovered. While Bitget stated that some assets have been frozen through coordination with other industry participants,the exchange has not disclosed the exact amount recovered or the success rate of its law enforcement collaborations.