Approximately $387.5m was moved without authorization from part of Bitget’s hot and warm wallet infrastructure, and four days later the exchange reopened Bitcoin withdrawals at 08:00 UTC on September 28 after additional security checks.
How the breach unfolded and the immediate response
Bitget detected the incident on September 24 when its security systems flagged unauthorized transfers from some of its hot wallets. The exchange initially estimated the affected amount at $351.6m, then revised that figure to approximately $387.5m after “further transaction classification identified additional affected Zcash and TRON transfers,” Bitget said. The exchange emphasized the revision did not represent additional unauthorized transfers after the incident was contained.
As a precaution, Bitget suspended withdrawals while it examined its withdrawal infrastructure. Trading and deposits continued during the pause. Bitcoin withdrawals on the Bitcoin network were restored on September 28 at 08:00 UTC after the company said it had performed additional security checks.
Attack vector identified: third‑party security product and credential misuse
In a public statement on September 28, Bitget said a flaw in a third‑party security product gave the attacker high‑level internal credentials. Those credentials were then used to send fraudulent withdrawal commands that bypassed the exchange’s risk controls. Bitget reported that its investigation, supported by Mandiant and blockchain security firm SlowMist, identified the attack path and that the underlying vulnerability had been fixed.
Bitget also said its investigation to date ruled out private‑key compromise. The exchange said its cold wallets were unaffected and that user account balances remained intact.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildStaged service recovery: dates, networks, scope
Bitget published a phased schedule for restoring remaining services, with each phase opening at 08:00 UTC. The exchange said the plan was:
- September 29 — Ether (ETH) withdrawals resume on Ethereum and on the BNB Smart Chain, Arbitrum, Base and Optimism networks.
- September 30 — Tether (USDT) withdrawals resume on Ethereum, BNB Smart Chain, Solana and TRON.
- October 2 — all other tokens, fiat withdrawals and peer‑to‑peer (P2P) services are scheduled to reopen.
Bitget stated the incident remained contained and that “no further unauthorized transfers are possible.” Mandiant and SlowMist were reported to continue supporting the investigation, providing forensic analysis and tracing of affected funds.
Recovery, legal coordination and asset tracing
Bitget said the loss falls within the coverage of its Protection Fund, which its first incident notice valued at more than $464m. The exchange has launched a recovery bounty program and reported it was coordinating with law enforcement, blockchain security firms and other industry participants to trace and recover affected assets. Bitget said some affected assets had already been frozen.
At the same time, the exchange noted its investigation had not concluded: details about the attacker’s identity and the full extent of the compromise remain subject to further findings. Bitget said it would review how it assesses and deploys third‑party security products.
What this means for technologists, users, and law enforcement
- Technologists and security teams — Expect renewed scrutiny of how third‑party security products are assessed and deployed. Bitget’s statement attributes the initial breach to a flaw in such a product that granted high‑level internal credentials, and the exchange has said it will review deployment practices.
- End users and account holders — Bitget has stated cold wallets were unaffected and that user account balances remained intact; withdrawals are being reopened in phases with Bitcoin already resumed. Users will likely watch the scheduled rollouts on September 29–October 2 and any follow‑up findings from the ongoing investigation.
- Law enforcement and asset recovery teams — Bitget reported coordination with law enforcement and that some affected assets had been frozen. The exchange also launched a recovery bounty program and continues to work with Mandiant, SlowMist and other participants on tracing and forensic work.
Bitget’s public timeline frames the incident as contained and tied to a third‑party product flaw, but the company itself notes the investigation is ongoing and that attribution and full accounting remain subject to further findings. The scheduled reopenings for ETH, USDT and other services over the next days will be the practical tests of the exchange’s remediation and control improvements.
Source: Infosecurity Magazine — Bitget Restarts Bitcoin Withdrawals Following $387.5m Wallet Breach




