Bitget Resumes Withdrawals After $388 Million Hack Exploiting Third-Party Zero-Day Flaw
Cryptocurrency exchange Bitget has begun restoring customer withdrawals after attackers exploited a zero-day vulnerability in a third-party security product to steal approximately $388 million. The company states that cold wallets and private keys were unaffected, and its user protection fund will cover the losses.
How this story has developed
This report is part of a developing story — read the earlier chapters below.
- Bitget Confirms $387.5 Million Loss in Backend System Hack, Suspects North Korea
- Bitget Resumes Withdrawals After $388 Million Hack Exploiting Third-Party Zero-Day Flaw (this article)
- Exchange Operators
- Focuses on maintaining liquidity, restoring user trust, and covering losses through internal insurance funds.
- Security Auditors
- Emphasizes the technical mechanics of the exploit, the failure of third-party dependencies, and the need for zero-trust architectures.
Perspectives this story doesn't cover
- The unnamed third-party security vendor whose product contained the zero-day vulnerability.
- Retail users whose funds were temporarily frozen during the four-day withdrawal halt.
Why this matters
The breach highlights a critical vulnerability in the cryptocurrency ecosystem: even when an exchange's core cryptographic keys remain secure, compromised third-party administrative tools can still authorize massive unauthorized transfers. For Bitget's millions of users, the immediate concern is the phased restoration of their assets, backed by the company's protection fund.
Cryptocurrency exchange Bitget has begun a phased resumption of customer withdrawals, ending a four-day freeze following a $388 million theft on September 24. The standard narrative for such a breach involves compromised private keys or breached cold storage vaults, but the exchange has now confirmed a different vector. Attackers exploited a zero-day vulnerability in an unnamed third-party security product to acquire high-level internal credentials. "The attacker then used these credentials to send fraudulent withdrawal commands to the wallet system, causing it to execute abnormal transfers that bypassed risk controls," the exchange stated.[4][5]
The breach began with a quiet probe. At 18:31 UTC on the day of the attack, the perpetrators initiated two small test transfers—0.184 ETH and 193 TRX—that fell below Bitget's risk-control thresholds and triggered no alarms. Half an hour later, the main drain commenced. Over the next several minutes, 17 transactions moved roughly $361 million across multiple networks, including Ethereum, BNB Chain, and Avalanche.[3][4]
Bitget's internal reconciliation systems caught the discrepancy within seven minutes of the first large transfer, automatically halting platform-wide withdrawals at 19:05 UTC. However, the attackers had already successfully routed the funds and subsequently deleted the administrative traces of their commands, complicating the initial forensic response.[3][4]
The exchange initially estimated the damage at $351.6 million, but later revised the total to $387.5 million after identifying additional unauthorized transfers on the Zcash and TRON networks. Bitget maintains that this revision reflects a more complete accounting of the original 30-minute window, rather than a secondary breach.[1][5]
Bitget maintains that this revision reflects a more complete accounting of the original 30-minute window, rather than a secondary breach.
Despite the scale of the theft, Bitget asserts that customer balances will not be affected. The company is drawing on its User Protection Fund—a self-funded reserve holding 5,500 Bitcoin, valued at over $464 million—to absorb the losses in full. The exchange has committed to replenishing this fund to at least $300 million within a week using corporate reserves.[1][4][5]
With the underlying vulnerability reportedly patched, Bitcoin withdrawals restarted on September 28 at 08:00 UTC. The exchange processed over 9,585 withdrawal orders totaling roughly 4,098 BTC in the opening hours. Ethereum withdrawals are scheduled to resume on September 29, followed by Tether (USDT) on September 30, as the security team validates each network route. “Bitget has identified the attack path, remediated the vulnerability, and strengthened controls across its withdrawal infrastructure,” the company explained.[3][4][5]
The identity of the attackers remains unconfirmed. While CEO Gracy Chen initially noted that the attack patterns and IP behaviors strongly resembled those of North Korean state-sponsored hacking groups, she later clarified that these were preliminary indicators. Bitget has retained cybersecurity firms Mandiant and SlowMist to conduct a formal forensic investigation, with a comprehensive incident report expected shortly.[2][4][5]
In an effort to reclaim the stolen assets, Bitget has launched a recovery bounty program, offering a 5 percent reward for information leading to the freezing of funds and another 5 percent for their successful recovery. While centralized stablecoin issuers like Circle and Tether have frozen a small fraction of the assets—roughly $318,000—the vast majority have already been swapped into decentralized cryptocurrencies, making protocol-level intervention technically impossible.[1][3][4]
Viewpoints in depth
Bitget Management
The exchange emphasizes its rapid response and the resilience of its protection fund.
Bitget executives, led by CEO Gracy Chen, have focused their public messaging on the containment of the breach and the integrity of customer funds. By highlighting that private keys and cold storage remained secure, the exchange is framing the incident as a failure of a specific third-party vendor rather than a fundamental flaw in Bitget's core cryptographic architecture. The rapid deployment of the 5,500 BTC User Protection Fund is being positioned as proof of the platform's financial solvency and commitment to making users whole.
Blockchain Security Analysts
Security researchers point to the systemic risks of third-party administrative access.
For forensic firms and on-chain analysts, the Bitget hack underscores a growing vulnerability in centralized exchanges: the administrative supply chain. Analysts note that attackers no longer need to break complex cryptography if they can simply compromise the backend tools used to authorize transactions. The fact that the attackers could inject fraudulent commands and delete their own traces using valid internal credentials highlights a severe gap in zero-trust architecture and internal monitoring.
What we don’t know
- The specific third-party security product that contained the zero-day vulnerability has not been publicly identified.
- While preliminary indicators point to North Korean hacking groups, official attribution remains pending the conclusion of the Mandiant and SlowMist investigation.
- It is unclear exactly how much of the stolen $388 million has been successfully frozen by centralized stablecoin issuers or other exchanges.
Key points
- Attackers stole approximately $388 million from Bitget on September 24 by exploiting a zero-day flaw in a third-party security product.
- The breach allowed hackers to bypass risk controls and authorize withdrawals without compromising private keys or cold wallets.
- Bitget's internal systems detected the anomaly and halted platform-wide withdrawals within seven minutes of the main attack.
- The exchange is using its $464 million User Protection Fund to cover all customer losses.
- Bitcoin withdrawals resumed on September 28, with other assets scheduled for a phased rollout through October 2.
Sources
[1]Unchained CryptoExchange OperatorsBitget Confirms It Was Tricked Into Approving Its Own $388 Million Theft
Read on Unchained Crypto →
[2]Traders UnionExchange OperatorsBitget says third-party flaw enabled $388 million crypto exploit
Read on Traders Union →
[3]FinanceFeedsSecurity AuditorsBitget Hacker Used Zero-Day and Test Transfers Before $388M Drain
Read on FinanceFeeds →
[4]The BlockSecurity AuditorsBitget attacker tested risk controls with small transfers before $388 million theft, CEO says
Read on The Block →
[5]Bitcoin.comExchange OperatorsBitget Restarts Bitcoin Withdrawals as $388M Hack Investigation Widens
Read on Bitcoin.com →
Comments
More in Technology
See all →Orbital Infrastructure
Starship Reaches Orbit and Deploys Starlink V3 Satellites Before Early Mission Termination
6 sources
Foundry Race
Intel Claims 1.4nm Process Will Achieve Performance Parity With TSMC's A14 Node, Signaling Foundry Race Turning Point
3 sources
Software Architecture
How Software Development Discounts Future Rework Costs Through Technical Debt
6 sources
Agentic Security
The Mechanics of AI Agent Memory Poisoning: How Sleeper Attacks Corrupt Autonomous Systems
8 sources
Every angle. Every day.
Get Technology stories with full source coverage and perspective breakdowns delivered to your inbox.




