Bitget says $388m taken in third-party credential attack
Bitget has confirmed about $388 million in assets were transferred after an attacker used stolen internal credentials, and BTC withdrawals have resumed as it restores services in phases.
Key points
- Bitget CEO Gracy Chen said the attacker exploited a vulnerability in a third-party security product to obtain high-level internal credentials.
- The first large transfers ran from 18:58 to 20:09 UTC on Sept. 24, with 17 transfers worth about $361 million, followed by a second wave of about $30 million.
- Bitget says private keys and cold wallets were not compromised, and no further unauthorised transfers were found after containment.
- BTC withdrawals resumed at 08:00 UTC on Sept. 28, with 9,585 withdrawals totalling 4,098.03574 BTC by 09:00 UTC.
- Mandiant and SlowMist are assisting the investigation, and losses will be covered by a User Protection Fund of more than $464 million.
Bitget has confirmed that about $388 million in assets were transferred during a security incident on Sept. 24, which its chief executive said involved stolen internal credentials. The exchange detailed the attack as it began restoring withdrawals, starting with bitcoin.
Speaking on a public livestream on X, CEO Gracy Chen said the attacker exploited a vulnerability in a third-party security product to obtain high-level internal credentials. Those credentials were then used to send fraudulent withdrawal commands to Bitget's wallet system, triggering abnormal transfers that bypassed risk controls. Bitget said its private keys and cold wallets were not compromised, and that it had identified the attack path, fixed the vulnerability and contained the incident.
According to Chen, the first unauthorised transfers began at about 18:31 UTC on Sept. 24, with two small transactions of 0.84 ETH and 93 TRX that fell below the exchange's risk-control threshold. Between 18:58 and 20:09 UTC the attacker made 17 larger transfers across Ethereum, XRP, Zcash, BNB Smart Chain, Base, Arbitrum, Optimism and Avalanche, worth an estimated $361 million in total. Monitoring systems spotted a significant discrepancy at 19:05 UTC, seven minutes after the first large transfer, and user withdrawals were automatically blocked.
How the attack unfolded
Bitget activated its highest-level P0 emergency response at 19:14 UTC and began containment at 19:40 UTC. At about 20:40 UTC the wallet team started moving funds into cold storage as a precaution. A second wave of seven transfers between 20:55 and 21:23 UTC, involving Avalanche, XRP, Ethereum, Zcash, Algorand, TIA and Cosmos, was valued at about $30 million. At roughly 21:44 UTC the exchange shut down wallet withdrawal services and isolated withdrawal-related access.
Chen described the attack as a sophisticated, targeted operation in which legitimate credentials were used and activity was disguised as routine administrative work while traces were deleted. She said Bitget does not currently believe it was an inside job, but would not speculate on the attacker's identity before the investigation concludes. Forensic firms Mandiant and SlowMist are supporting the inquiry, including on-chain tracing, and the exchange has reported the incident to law enforcement.
Bitget said some assets have already been frozen through cooperation with other exchanges, blockchain projects and security specialists, and it has published attacker addresses. BTC withdrawals on the Bitcoin and BSC networks resumed at 08:00 UTC on Sept. 28; by 09:00 UTC users had initiated 9,585 BTC withdrawals totalling 4,098.03574 BTC. ETH withdrawals are due on Sept. 29, USDT on Sept. 30, and other tokens, fiat and P2P services on Oct. 2.
Forensics and recovery
Chen said the pause was a security measure and not a sign of insufficient user assets, adding that balances were unaffected and losses would be covered by the Bitget Protection Fund, which now exceeds $464 million. The exchange reported a Proof of Reserves ratio of 127% and said it has tightened third-party security standards, access controls and withdrawal monitoring. It also launched two limited-time programmes for users and market makers.