• Bitget resumed Bitcoin withdrawals on Sept 28 after a roughly 3.5-day pause.
• Attackers drained about $388 million from Bitget hot and warm wallets across multiple chains.
• Hackers exploited a zero-day in a third-party security product to steal high-privilege internal credentials.
Bitcoin Withdrawals Back Online
Bitget has begun restoring customer withdrawals in stages after last week's breach, with Bitcoin (BTC) network withdrawals going live again from around 17:00 JST on Sept. 28. The phased restart opens Bitcoin first, then Ethereum plus the BSC, Arbitrum, Base and Optimism networks, followed by USDT, and finally remaining tokens and fiat services. The exchange kept a single withdrawal channel for retail, VIP and institutional clients with no priority queue, and left minimum amounts and 24-hour caps unchanged. Demand has been heavy but orderly: as of 16:50 UTC+8, the platform had received 7,683 Bitcoin withdrawal orders totaling 3,609 BTC, of which 6,946 orders worth 3,326 BTC already carried at least one on-chain confirmation, while 737 orders for 283 BTC were broadcast and awaiting confirmation. Staffing on withdrawal processing was raised roughly fivefold, and users can now route BTC out via BSC as a faster, cheaper alternative to the congested Bitcoin mainnet. The roughly three-and-a-half-day freeze, the exchange stressed, reflected the sheer number of systems that had to be re-verified, not any funding shortfall. Alongside the restart, Bitget tightened its security posture: access to sensitive systems now requires multi-party approval, third-party vendors were cut off pending remediation of the flaw they introduced, and every withdrawal request now faces independent verification. The company also reiterated that no private key was ever exposed. On-chain observers are meanwhile tracking the stolen money: on-chain analyst ZachXBT reported that funds are hopping between chains via bridges and feeding into mixing services such as Wasabi, and that Chinese-language laundering crews — acting, in his reading, on behalf of the attacking group — are openly advertising disposal services on Discord and Telegram. One operator using the alias “lolo/Marin” was previously tied to laundering the $292 million Kelp DAO drain, a pattern ZachXBT says also recurs across attacks attributed to North Korea's TraderTraitor cluster.
Third-Party Zero-Day, Forged Instructions
The exchange's own post-mortem briefing, delivered publicly by CEO Gracy Chen and Greater China head Xie Jiayin, laid out the attack minute by minute. It began at 02:31 UTC+8 on Sept. 25 with two tiny probes — 0.84 ETH from an Ethereum hot wallet and 93 TRX from a TRON hot wallet — that slipped under risk-control thresholds and triggered no alert. Between 02:58 and 04:09, the attacker fired 17 large transfers worth roughly $360 million across Ethereum, XRP, BSC, Base, Arbitrum, Optimism and Avalanche, with the second wave touching ALGO, TIA, ATOM and the privacy coin Zcash. The platform's reconciliation system caught the anomaly at 03:05, automatically blocking all user withdrawals, and a P0-level emergency response followed at 03:14; a second round of seven transfers added roughly $28 million before wallets were frozen. Total drained: about $388 million from hot and warm wallets. The entry point, per the official disclosure, was a zero-day vulnerability in a third-party security product that let attackers steal genuine high-privilege internal credentials, write forged withdrawal commands directly into the wallet backend to bypass pre-execution risk checks, and delete traces after each transfer — no malware involved. Bitget, one of the industry's largest venues for futures and spot trading, said private keys and cold wallets were never touched and insider involvement has been preliminarily excluded. Its protection fund, which stood near $464 million with a 127% reserve ratio at the time, will absorb the loss and be replenished to at least $300 million within a week in publicly verifiable wallets. Mandiant and SlowMist are conducting independent forensics, with a full report due within a week, and a recovery bounty pays 5% of any frozen or returned funds.
$300M Fund Test Ahead
Our reading: this was the first security incident in Bitget's eight-year history, and its core lesson is that a third-party security layer is itself an attack surface that exchanges must audit as aggressively as their own code. The on-chain evidence trail is unusually clean — attacker addresses are public, every movement is traceable, and the remediation is independently checkable, since the replenished fund will sit in open wallets users can verify themselves. The $300 million fund top-up and the independent forensic report due within a week are the real tests; sentiment gauges like the crypto Fear and Greed Index will show whether the market treats this as contained.
