BTC $82,986.00 -0.76%
ETH $2,660.42 +0.20%
BNB $756.68 -2.15%
XRP $1.47 -2.55%
SOL $116.76 -3.41%
TRX $0.3348 +0.19%
DOGE $0.0922 -3.22%
ADA $0.2417 -4.94%
BCH $304.80 -6.37%
LINK $15.15 +8.02%
HYPE $86.20 -4.39%
AAVE $147.00 -3.81%
SUI $1.11 -11.12%
XLM $0.2271 +5.48%
ZEC $1,398.07 -11.33%
AAPL $338.35 -0.58%
AMZN $246.36 -1.08%
GOOGL $342.50 +0.16%
MSFT $509.36 -1.61%
META $716.79 -2.60%
NVDA $228.80 +1.88%
TSLA $357.72 -3.41%
SNDK $1,703.17 -2.31%
INTC $114.77 -5.05%
SPCX $145.81 -2.23%
MU $1,050.56 -2.07%
AMD $607.22 -2.65%
BTC $82,986.00 -0.76%
ETH $2,660.42 +0.20%
BNB $756.68 -2.15%
XRP $1.47 -2.55%
SOL $116.76 -3.41%
TRX $0.3348 +0.19%
DOGE $0.0922 -3.22%
ADA $0.2417 -4.94%
BCH $304.80 -6.37%
LINK $15.15 +8.02%
HYPE $86.20 -4.39%
AAVE $147.00 -3.81%
SUI $1.11 -11.12%
XLM $0.2271 +5.48%
ZEC $1,398.07 -11.33%
AAPL $338.35 -0.58%
AMZN $246.36 -1.08%
GOOGL $342.50 +0.16%
MSFT $509.36 -1.61%
META $716.79 -2.60%
NVDA $228.80 +1.88%
TSLA $357.72 -3.41%
SNDK $1,703.17 -2.31%
INTC $114.77 -5.05%
SPCX $145.81 -2.23%
MU $1,050.56 -2.07%
AMD $607.22 -2.65%

Bitget disclosed the reason for the theft of 388 million: hackers exploited a zero-day vulnerability in a third-party security product to access the internal key management system

Core Viewpoint
Summary: Bitget suffered a third-party security vulnerability attack, approximately 388 million USD was transferred out, but the private keys and cold wallets were not affected, user balances remain intact, and the protection fund will be replenished to 300 million USD within a week.
Wu Says Blockchain
2026-09-29 09:12:24
Bitget suffered a third-party security vulnerability attack, approximately 388 million USD was transferred out, but the private keys and cold wallets were not affected, user balances remain intact, and the protection fund will be replenished to 300 million USD within a week.

Editor | Wu Says Blockchain

The content of this article comes from a public live broadcast between Bitget CEO Gracy Chen and the head of Greater China, Xie Jiayin, regarding recent security incidents. Bitget disclosed that attackers exploited vulnerabilities in third-party security products to obtain internal high-privilege credentials, subsequently forging withdrawal instructions and bypassing risk control, transferring approximately $388 million in assets from multiple hot and warm wallets. Bitget stated that private keys and cold wallets were unaffected, user balances were not compromised, and related losses would be covered by the user protection fund.

The live broadcast detailed the attack and emergency response process. Bitget indicated that the attackers first conducted small transfer tests, then initiated large transfers on multiple chains including Ethereum, XRP, BSC, Arbitrum, and Avalanche, and deleted relevant traces after the operations. Upon discovering the anomaly, the platform suspended withdrawals, transferred remaining funds, and investigated the system, ultimately tracing the attack path to a zero-day vulnerability in a third-party security product. Bitget has since isolated the affected systems, reset internal credentials, and strengthened high-sensitivity permissions and withdrawal verification.

Regarding the stolen funds, Bitget stated that it would not rely on asset recovery as the primary means of safeguarding user funds, but would depend on the protection fund to cover losses, planning to replenish the protection fund to at least $300 million within a week. Additionally, the platform has initiated a bounty for asset recovery and is collaborating with organizations such as Mandiant and Slow Mist for investigations and on-chain tracking.

This content is based on Bitget's public statement regarding the security incident, and the reasons for the attack and investigation conclusions are disclosed by Bitget. Future updates will rely on an independent security investigation report. This does not represent Wu Says' viewpoint and does not constitute any investment advice; please strictly adhere to local laws and regulations.

Bitget CEO Responds to $388 Million Security Incident

Gracy Chen: Hello everyone, I am Bitget CEO Gracy Chen. Today's live broadcast is mainly to share with you the security incident that occurred on September 24, which is September 25 in the Asian time zone. We will introduce the current investigation results, handling and recovery progress, future arrangements, and answer questions of concern.

First, let’s summarize the incident. At 2:31 AM on September 25 in the UTC+8 time zone, some assets in Bitget's hot and warm wallet infrastructure experienced unauthorized transfers across multiple chains. After investigation, it was found that the attackers exploited vulnerabilities in third-party security products to obtain high-privilege internal credentials and forged withdrawal instructions to the wallet system, bypassing risk verification. No private keys were leaked, and cold wallets were not affected.

The attack path has been clarified, the vulnerability has been fixed, and the incident has been brought under control, with no further unauthorized transfers detected. It has been confirmed that the total value of the transferred assets is approximately $388 million. Mandiant and Slow Mist are assisting us in the investigation and on-chain tracking, and the attacker's address and related tracking data have been made public, hoping to promote collaboration across the industry.

For users, the most important thing is that all user balances will not be affected. This loss will be fully covered by the Bitget user protection fund. After the protection fund is utilized, the company will use its own funds to replenish the protection fund to at least $300 million worth of assets within a week.

We have also initiated an asset recovery bounty program and are collaborating with security companies, law enforcement agencies, trading platforms, public chain projects, and other industry partners to track and recover related assets. Confirmed vulnerabilities and attack information will also be shared with more industry participants, and we will continue to publish updates on asset tracking and recovery progress.

This incident is a very severe test for Bitget. We will not avoid it, hope to learn from it, and will not let this incident define Bitget. The investigation, recovery, and rectification processes will be kept as transparent as possible, allowing users and the entire industry to supervise.

From Small Tests to Large Asset Transfers Across Multiple Chains

Gracy Chen: Next, I will detail the timeline of the attack.

According to the UTC+8 time zone, at 2:31 AM on September 25, the hackers first conducted two very small fund transfers: transferring 0.84 ETH from the Ethereum hot wallet and 93 TRX from the TRON hot wallet. Because the amounts were very small, below the risk control threshold at the time, no system alerts were triggered.

From 2:58 AM to 4:09 AM was a critical phase. The hackers initiated 17 large fund transfers across multiple chains including Ethereum, XRP, ZEC, BSC, Base, Arbitrum, Optimism, and Avalanche, with a total value of approximately $360 million.

The first large transfer occurred 7 minutes later, at 3:05 AM, when the platform's reconciliation system detected a large discrepancy, and the risk system automatically blocked all withdrawal requests initiated by users across the platform. At 3:14 AM, the platform initiated the highest-level emergency response (P0); at 3:40 AM, the technical team began to take loss prevention measures.

At 4:40 AM, as the risk of private key theft could not be completely ruled out, the wallet team began to consolidate funds into cold wallets. From 4:55 AM to 5:23 AM, the hackers initiated a second round of 7 fund transfers, valued at approximately $28 million, involving Avalanche, XRP, Ethereum, ZEC, ALGO, TIA, and ATOM.

At 5:44 AM, the technical team stopped withdrawal services such as signature machines and isolated access related to withdrawals, while initially determining that no private keys had been leaked. By 4:43 PM that day, the security team had already pinpointed the root cause of the entire incident. At 9:42 PM that evening, the legal team reported the incident to the relevant authorities.

The next day, after completing vulnerability fixes, service isolation, and security checks, we confirmed the plan to resume withdrawals. Withdrawals will be gradually restored in the order of Bitcoin, Ethereum, USDT, other tokens, and fiat services.

How Hackers Forged Withdrawal Instructions and Cleared Traces

Gracy Chen: The entire attack can be roughly broken down into several steps.

First, the hackers exploited a zero-day vulnerability in third-party security products to steal our internal network credentials and accessed key management systems within the platform. Since the identity credentials used by the attackers were real and valid, the system recognized it as normal login behavior.

In the second step, the attackers used the stolen high-privilege credentials to access wallet-related backend services, directly writing forged withdrawal commands to the wallet system, causing the wallet to execute them as normal withdrawals, bypassing the risk verification process that should have occurred before generating withdrawal records, thus transferring funds from hot and warm wallets.

The third step was to clear traces. After each transfer was completed, the attackers would delete any records that the forged withdrawal commands might have left behind, attempting to cover up their actions and complicate our efforts to locate the root cause. Due to the lack of direct evidence, we had to investigate a broader range of systems, and the verification after repairs needed to cover more systems, making the entire investigation and recovery process take some time.

Throughout the process, the attackers did not use common viruses or malware but instead utilized real credentials to disguise the attack as routine operational activities and cleared traces after completing the operations. In our view, this was a very high-level targeted attack.

Currently, the possibility of private key leakage has been ruled out, and the likelihood of internal collusion has also been initially excluded. This attack was carried out by hackers exploiting vulnerabilities in third-party security products to steal internal credentials and impersonate identities. Further investigations are being assisted by Mandiant and Slow Mist, and we will not speculate too much on the identity of the attackers until the formal report is released; we hope to publish the investigation report within a week.

How the Protection Fund Will Cover the $388 Million Loss

Xie Jiayin: Hello everyone, I am Xie Jiayin, the head of Greater China for Bitget.

Gracy has already introduced the basic situation of this incident. We have completed a thorough tracing; the hackers exploited vulnerabilities in third-party security products to steal internal network access credentials, forged withdrawal orders to the wallet system, deceived the wallet into executing them, and bypassed risk control verification, ultimately completing the unauthorized transfers.

Throughout the process, the attackers did not use common viruses or malicious programs but disguised themselves using real identity credentials and routine operational actions while clearing traces. After the incident, we have ruled out the possibility of private key loss. This incident was caused by a breach of the key backend systems within the wallet infrastructure. After preliminary investigations, we have also ruled out the possibility of internal collusion.

Currently, third-party security teams such as Slow Mist and Mandiant are assisting in the investigation. Information regarding the identity of the attackers and more detailed attack processes will be further disclosed in the preliminary security report.

Many users are also asking whether the protection fund will be replenished after being used. The answer is yes. Since the establishment of the protection fund in 2022, we have promised to maintain a scale of at least $300 million every month to quickly safeguard user assets in the event of black swan incidents. Within this week, we will replenish the protection fund to over $300 million.

Why Withdrawals Need to Be Restored in Phases

Xie Jiayin: Because this incident involves multiple chains and currencies, to ensure security after restoration, multiple core verifications must be completed for each chain before restoration, so we have adopted a phased and orderly approach to resume withdrawals.

We will first open Bitcoin withdrawals, followed by restoring withdrawals for Ethereum and assets related to networks such as BSC, Arbitrum, Base, and Optimism, then restore USDT, and finally restore withdrawals for all other tokens and fiat currencies across the platform.

All users, including institutional clients, VIP clients, and regular clients, will use the same withdrawal channel, and no one will have priority. The original minimum withdrawal amount and maximum withdrawal limit within 24 hours will remain unchanged. Users do not need to take any additional actions; once restored, the platform will display it directly.

The withdrawal suspension lasted about three and a half days, and many people asked why it took so long. The main reason is that this attack affected the key backend systems within the infrastructure, involving the entire withdrawal process. Until every step of the investigation and verification is completed, we do not wish to continue exposing potential risks.

Additionally, this incident involves multiple mainnets and various assets, and each chain needs to complete repairs and security verifications individually, so it must be restored in phases according to chains and assets.

It is important to emphasize that the suspension of withdrawals is not related to the sufficiency of funds. At that time, the Bitget protection fund was approximately $464 million, with an asset reserve rate of 127%. All related data is publicly transparent and can be queried.

How Bitget Fixes Vulnerabilities and Adjusts Risk Control

Xie Jiayin: Next, I will introduce the progress in fixing vulnerabilities and risk control.

First, we have isolated the affected systems. All related servers have been isolated from the network to prevent the attack from continuing to spread while preserving evidence for subsequent tracing.

Second, we have reset internal credentials and further tightened high-sensitivity permissions. All internal login credentials have been invalidated and reissued, so the credentials previously stolen by the attackers are now invalid. High-sensitivity permissions have also been fully revoked and re-split, requiring multiple approvals for key operations.

Third, we have reported the details of the vulnerabilities to relevant third-party security vendors to assist them in analysis and repair. Until repairs are completed, we have stopped using related functions.

Fourth, we have further strengthened withdrawal verification, requiring independent verification for all withdrawals.

Currently, the incident has been brought under control, and no new unauthorized transfers have been detected. The affected systems have been isolated, the vulnerabilities have been fixed, but multiple core security verifications still need to be completed for each chain before resuming withdrawals.

How to Reduce Risks from Third-Party Security Products

Xie Jiayin: Since Bitget was established eight years ago, this is the first time a security incident has occurred, and it is the first time we have encountered such a significant event. This has also sounded a very heavy alarm for us: how to reduce similar risks in the future, how to detect them earlier, and how to block them faster?

First, before introducing third-party security products, we will adopt stricter evaluation standards. Second, during the deployment phase of third-party products, we will strengthen security measures and isolation mechanisms to compensate for potential system flaws in the third-party products themselves. Third, we will further improve abnormal monitoring to ensure the availability and stability of alerts, while enhancing the accuracy of alert judgments to reduce false positives and missed detections.

Some have asked whether third-party audits and penetration tests were conducted previously. We have always been doing this, and every year we conduct security tests with organizations like Hacken.

We have also announced a white hat bounty program. If someone can help actively freeze the attackers' funds, they can receive a bounty of 5% of the corresponding funds; if they can directly help recover the funds, they can also receive a bounty of 5% of the corresponding funds. The attackers' addresses have been made public, and we are tracking them in real-time; relevant information and submission portals are also public.

How Much Stolen Funds Can Be Recovered

Xie Jiayin: Some have asked what the probability is of recovering funds, such as whether we can recover 30%. Frankly, we are not that optimistic.

Taking past security incidents from other trading platforms as examples, even a year later, the proportion of assets that are frozen and actually recovered may be very limited. These attackers are very professional and know how to transfer and obscure funds.

This highlights the necessity of the user protection fund. The protection fund has been operational for four years, and we promise to maintain at least $300 million in scale to quickly safeguard user assets in similar situations.

What we can do now is to increase the difficulty for attackers to cash out. Every trading platform monitoring related addresses, stablecoin issuers freezing addresses, and cross-chain bridges are all compressing the attackers' funding outlets. For the $388 million stolen this time, we will not assume how much can definitely be recovered, but we will do our best to track and recover it, and we are very grateful for the assistance provided by trading platforms, public chains, and project parties.

Because this incident involves vulnerabilities in third-party security products, we are collaborating with Mandiant and SlowMist to investigate and hope to release a complete security report within a week.

Issues with Bitcoin Withdrawals After Recovery

Gracy Chen: Now that Bitcoin withdrawals have resumed, let me explain why some users may not have received their funds yet.

Withdrawals are actually divided into two parts. The first part is processing by the trading platform. After users initiate a withdrawal on the app or web, it usually takes a few minutes from order creation to the platform packaging and broadcasting it on-chain. If a withdrawal order has a TXID, it means the transaction has been broadcast to the blockchain network and can be checked for real-time status via a blockchain explorer. If there is no TXID yet, it means the order is still being processed by the platform.

The second part is the processing by the Bitcoin network itself. The Bitcoin network is relatively slow, with a target block time of about 10 minutes, but it can actually vary from a few minutes to several tens of minutes. After users withdraw Bitcoin from Bitget to other trading platforms, the counterpart usually needs to wait for at least one block confirmation.

Therefore, if there is already a TXID but the funds have not yet arrived, it is likely waiting for confirmation from the Bitcoin network and does not mean the withdrawal is still pending at Bitget.

Xie Jiayin: Currently, some users have reported successful withdrawals, and more withdrawals have been approved and are being packaged. If the speed is relatively slow, we ask everyone to be patient. Today we have also increased our manpower to handle withdrawals by about five times.

Gracy Chen: Currently, the overall operation of withdrawals is normal, and we have received over 6,000 withdrawal requests corresponding to more than 2,700 Bitcoins, with no significant backlog. The first batch of two to three thousand withdrawals has already received blockchain confirmations.

As the recovery continues, we have also opened up Bitcoin withdrawals through the BSC network. The Bitcoin mainnet is relatively slow and has higher fees, while BSC is faster and cheaper, so users can now choose different networks as needed.

Subsequent data shows that the number of withdrawal orders we received has further increased to over 6,800, corresponding to about 3,300 Bitcoins. Some of these have received at least one block confirmation, while the rest have been broadcast and received TXIDs, and are waiting for on-chain confirmation.

Why Asset Recovery is Not the Main Way to Protect Users

Gracy Chen: For this loss, we will not consider recovering stolen assets as the main way to protect user funds.

The reality is that especially when facing very professional hackers who are familiar with money laundering and asset transfer methods, recovering stolen assets is very difficult. Therefore, user asset security cannot rely on whether we can ultimately recover the money from the attackers, which is also the reason why Bitget established the protection fund.

The purpose of the asset recovery bounty program is to increase the difficulty for attackers to handle funds as much as possible. If trading platforms, stablecoin issuers, and cross-chain bridges collectively refuse to process related funds and freeze suspicious addresses, the options available to attackers will become fewer and fewer.

But regardless of how much is ultimately recovered, we will protect user assets through the protection fund, rather than waiting for recovery results before addressing user losses.

Gracy Chen: This time we will use the protection fund to cover the losses, so we will use a portion of the original protection fund of over $400 million. We will replenish the protection fund to over $300 million within a week.

The replenished assets will still be kept in a public wallet, and users can verify them in real-time on-chain.

Since Bitget was established eight years ago, this is our first security incident. There is no technology, network, or software that is absolutely unbreakable. This incident has occurred, and we sincerely apologize for it. The most important thing now is to complete the repairs, bear the losses, and continue to improve security standards.

If this incident has caused some users to lose trust in us, we hope to win it back through our actions in the future.

Will There Be Accountability for Third-Party Security Vendors?

Gracy Chen: Some users have asked whether the third-party security products involved in this incident need to bear responsibility and whether we will seek compensation from them.

This question needs further discussion by the legal team. Although there are relevant vulnerabilities in the third-party products, as a trading platform, we also have responsibilities. Therefore, whether to hold them accountable and in what manner still needs to be confirmed by the legal team.

This is similar to the logic of recovering stolen assets. Whether it is the bounty program or collaborating with the entire industry to increase the difficulty for hackers to launder money, we will not consider these as prerequisites for compensation and protecting users. User protection still relies on the Bitget protection fund and the platform's own security mechanisms.

Currently, Mandiant and SlowMist are conducting independent evidence collection, including assessing the affected systems and asset scope, attack paths and methods, as well as verifying our stop-loss and repair measures, while supporting fund tracking. The independent investigation report is expected to be released within a week.

Withdrawal Data Update and Event Summary

Gracy Chen: Finally, let me update the withdrawal data once more. As of 16:50 UTC+8, we have received 7,683 Bitcoin withdrawal orders, corresponding to 3,609 Bitcoins. Among these, 6,946 have received at least one block confirmation, corresponding to 3,326 Bitcoins; another 737 have been broadcast and are waiting for on-chain confirmation, corresponding to 283 Bitcoins.

The first batch of Bitcoin withdrawals has been relatively smooth, with no significant backlog. In addition to the Bitcoin mainnet, we have also received some orders for withdrawals through BSC, which are currently also running smoothly.

This is the first security incident in Bitget's eight-year history. According to the current investigation, the main cause of the attack is vulnerabilities in third-party security products, and more details will be disclosed in the independent security report.

Join ChainCatcher Official
Telegram Feed: @chaincatcher
X (Twitter): @ChainCatcher_
warnning Risk warning
app_icon
ChainCatcher Building the Web3 world with innovations.