Skip to main content
Crypto SecurityIncident Report· 3 min read· in Technology

Bitget Resumes Withdrawals After $388 Million Hack Exploiting Third-Party Zero-Day Flaw

Cryptocurrency exchange Bitget has begun restoring customer withdrawals after attackers exploited a zero-day vulnerability in a third-party security product to steal approximately $388 million. The company states that cold wallets and private keys were unaffected, and its user protection fund will cover the losses.

By Diego Navarro

How this story has developed

This report is part of a developing story — read the earlier chapters below.

  1. Bitget Confirms $387.5 Million Loss in Backend System Hack, Suspects North Korea
  2. Bitget Resumes Withdrawals After $388 Million Hack Exploiting Third-Party Zero-Day Flaw (this article)
Exchange Operators 50%Security Auditors 50%
Exchange Operators
Focuses on maintaining liquidity, restoring user trust, and covering losses through internal insurance funds.
Security Auditors
Emphasizes the technical mechanics of the exploit, the failure of third-party dependencies, and the need for zero-trust architectures.

Perspectives this story doesn't cover

  • The unnamed third-party security vendor whose product contained the zero-day vulnerability.
  • Retail users whose funds were temporarily frozen during the four-day withdrawal halt.

Why this matters

The breach highlights a critical vulnerability in the cryptocurrency ecosystem: even when an exchange's core cryptographic keys remain secure, compromised third-party administrative tools can still authorize massive unauthorized transfers. For Bitget's millions of users, the immediate concern is the phased restoration of their assets, backed by the company's protection fund.

Cryptocurrency exchange Bitget has begun a phased resumption of customer withdrawals, ending a four-day freeze following a $388 million theft on September 24. The standard narrative for such a breach involves compromised private keys or breached cold storage vaults, but the exchange has now confirmed a different vector. Attackers exploited a zero-day vulnerability in an unnamed third-party security product to acquire high-level internal credentials. "The attacker then used these credentials to send fraudulent withdrawal commands to the wallet system, causing it to execute abnormal transfers that bypassed risk controls," the exchange stated.[4][5]

The breach began with a quiet probe. At 18:31 UTC on the day of the attack, the perpetrators initiated two small test transfers—0.184 ETH and 193 TRX—that fell below Bitget's risk-control thresholds and triggered no alarms. Half an hour later, the main drain commenced. Over the next several minutes, 17 transactions moved roughly $361 million across multiple networks, including Ethereum, BNB Chain, and Avalanche.[3][4]

Bitget's internal reconciliation systems caught the discrepancy within seven minutes of the first large transfer, automatically halting platform-wide withdrawals at 19:05 UTC. However, the attackers had already successfully routed the funds and subsequently deleted the administrative traces of their commands, complicating the initial forensic response.[3][4]

The attackers executed the main drain in a seven-minute window before internal systems halted withdrawals.

The exchange initially estimated the damage at $351.6 million, but later revised the total to $387.5 million after identifying additional unauthorized transfers on the Zcash and TRON networks. Bitget maintains that this revision reflects a more complete accounting of the original 30-minute window, rather than a secondary breach.[1][5]

Bitget maintains that this revision reflects a more complete accounting of the original 30-minute window, rather than a secondary breach.

Despite the scale of the theft, Bitget asserts that customer balances will not be affected. The company is drawing on its User Protection Fund—a self-funded reserve holding 5,500 Bitcoin, valued at over $464 million—to absorb the losses in full. The exchange has committed to replenishing this fund to at least $300 million within a week using corporate reserves.[1][4][5]

With the underlying vulnerability reportedly patched, Bitcoin withdrawals restarted on September 28 at 08:00 UTC. The exchange processed over 9,585 withdrawal orders totaling roughly 4,098 BTC in the opening hours. Ethereum withdrawals are scheduled to resume on September 29, followed by Tether (USDT) on September 30, as the security team validates each network route. “Bitget has identified the attack path, remediated the vulnerability, and strengthened controls across its withdrawal infrastructure,” the company explained.[3][4][5]

Cybersecurity firms Mandiant and SlowMist have been retained to conduct a formal forensic investigation into the breach.

The identity of the attackers remains unconfirmed. While CEO Gracy Chen initially noted that the attack patterns and IP behaviors strongly resembled those of North Korean state-sponsored hacking groups, she later clarified that these were preliminary indicators. Bitget has retained cybersecurity firms Mandiant and SlowMist to conduct a formal forensic investigation, with a comprehensive incident report expected shortly.[2][4][5]

In an effort to reclaim the stolen assets, Bitget has launched a recovery bounty program, offering a 5 percent reward for information leading to the freezing of funds and another 5 percent for their successful recovery. While centralized stablecoin issuers like Circle and Tether have frozen a small fraction of the assets—roughly $318,000—the vast majority have already been swapped into decentralized cryptocurrencies, making protocol-level intervention technically impossible.[1][3][4]

Viewpoints in depth

Bitget Management

The exchange emphasizes its rapid response and the resilience of its protection fund.

Bitget executives, led by CEO Gracy Chen, have focused their public messaging on the containment of the breach and the integrity of customer funds. By highlighting that private keys and cold storage remained secure, the exchange is framing the incident as a failure of a specific third-party vendor rather than a fundamental flaw in Bitget's core cryptographic architecture. The rapid deployment of the 5,500 BTC User Protection Fund is being positioned as proof of the platform's financial solvency and commitment to making users whole.

Blockchain Security Analysts

Security researchers point to the systemic risks of third-party administrative access.

For forensic firms and on-chain analysts, the Bitget hack underscores a growing vulnerability in centralized exchanges: the administrative supply chain. Analysts note that attackers no longer need to break complex cryptography if they can simply compromise the backend tools used to authorize transactions. The fact that the attackers could inject fraudulent commands and delete their own traces using valid internal credentials highlights a severe gap in zero-trust architecture and internal monitoring.

What we don’t know

  • The specific third-party security product that contained the zero-day vulnerability has not been publicly identified.
  • While preliminary indicators point to North Korean hacking groups, official attribution remains pending the conclusion of the Mandiant and SlowMist investigation.
  • It is unclear exactly how much of the stolen $388 million has been successfully frozen by centralized stablecoin issuers or other exchanges.

Key points

  • Attackers stole approximately $388 million from Bitget on September 24 by exploiting a zero-day flaw in a third-party security product.
  • The breach allowed hackers to bypass risk controls and authorize withdrawals without compromising private keys or cold wallets.
  • Bitget's internal systems detected the anomaly and halted platform-wide withdrawals within seven minutes of the main attack.
  • The exchange is using its $464 million User Protection Fund to cover all customer losses.
  • Bitcoin withdrawals resumed on September 28, with other assets scheduled for a phased rollout through October 2.

Sources

Source coverage

5 outlets

2 viewpoints surfaced

Exchange Operators 50%Security Auditors 50%
  1. [1]Unchained CryptoExchange Operators

    Bitget Confirms It Was Tricked Into Approving Its Own $388 Million Theft

    Read on Unchained Crypto →
  2. [2]Traders UnionExchange Operators

    Bitget says third-party flaw enabled $388 million crypto exploit

    Read on Traders Union →
  3. [3]FinanceFeedsSecurity Auditors

    Bitget Hacker Used Zero-Day and Test Transfers Before $388M Drain

    Read on FinanceFeeds →
  4. [4]The BlockSecurity Auditors

    Bitget attacker tested risk controls with small transfers before $388 million theft, CEO says

    Read on The Block →
  5. [5]Bitcoin.comExchange Operators

    Bitget Restarts Bitcoin Withdrawals as $388M Hack Investigation Widens

    Read on Bitcoin.com →

Comments

Stay informed

Every angle. Every day.

Get Technology stories with full source coverage and perspective breakdowns delivered to your inbox.