Bitget reopens withdrawals after $388 million stolen
Summarize this article with:

Four days after suspending its withdrawals, Bitget is starting to let bitcoins out again. In the meantime, the exchange had to endure a theft of $388 million. No broken private key, no emptied cold wallet: the attacker used a security product provided by an external company. Two small transfers first allowed him to test the defenses. Then the big movements left. Today, customers can recover their funds. But the story is far from over.

A hooded hacker watches two small Bitcoin transactions on a computer, while a chest overflows with glowing Bitcoins behind him.

In brief

  • Bitget gradually reopens withdrawals four days after an attack that resulted in nearly $388 million in losses.
  • The attacker would have exploited a zero-day flaw in a third-party provider to obtain internal access and bypass several controls.
  • Two small transactions served as a test before seventeen massive transfers spread across eight different blockchain networks.
  • The stolen funds pass through THORChain in particular, which refuses to block the addresses despite public requests from Bitget.
  • The Protection Fund exceeds $464 million, while Bitget promises to fully preserve its users’ balances.

The front door wasn’t the one Bitget was watching

On September 24, at 6:31 p.m. UTC, two transactions went almost unnoticed. 0.184 ETH on one side, 193 TRX on the other. Nothing like a $388 million heist. That’s precisely the goal.

These two movements remain below the thresholds provided for by Bitget’s risk controls. No warning signal is triggered. About thirty minutes later, the attacker moves on. Seventeen transactions are sent across eight networks, including Ethereum, XRP Ledger, Zcash, BNB Chain, Base, Arbitrum, Optimism and Avalanche. Around 361 million dollars then go to addresses controlled by the attacker.

The reconciliation system eventually identifies an anomaly. Seven minutes after the first big transfer, Bitget starts blocking withdrawals.

The most surprising thing is elsewhere. Private keys have not been compromised and cold wallets have not been affected. The attacker allegedly exploited a zero-day flaw in a third-party security product to obtain internal credentials. With these accesses, he could inject withdrawal orders into the backend of the wallets. The system treated them as legitimate requests.

In other words, no one broke into the trunk. Someone found a way to talk to the guard.

The investigation established that the attacker exploited a vulnerability in a third-party security product to obtain high-level internal credentials. Private keys have not been compromised and cold wallets have not been affected. — Bitget, September 28, 2026

The attack began with two almost ridiculous transactions

The 0.184 ETH and 193 TRX take on another meaning when looking at the full timeline. These are probably not funds intended to be stolen. They are used to see if anyone is watching.

The attacker then waits approximately thirty minutes before launching main operations. Between 6:58 p.m. and 8:09 p.m. UTC, seventeen transactions are executed on multiple blockchains. The amount initially estimated at $351.6 million was ultimately increased to around $388 million after analyzing movements on Zcash and Tron.

Bitget quickly realizes that something is going on. But the internal access used to initiate withdrawals also allows the attacker to delete certain traces of his orders. For the teams responsible for understanding the incident, this necessarily complicates the reconstruction of events.

Your first cryptos with Bitget
This link uses an affiliate program

Gracy Chen, Bitget’s boss, recognized him during a interview with The Block : “ This is also, in my opinion, the most delicate part “.

Mandiant and SlowMist are now participating in the investigation. Bitget says it identified the vulnerability, fixed the problem and strengthened its controls. The North Korean trail is also being studied, but remains a hypothesis until the full report has been published.

The difference with many recent crypto hacks is therefore quite clear. This time, the problem did not come directly from the mechanism that protects the assets. It came from the accesses which allow them to be moved.

The funds go through THORChain and the controversy grows

Once out of Bitget, the assets obviously did not stay quiet. Investigators followed part of the movements through different networks. Certain amounts notably passed through THORChain before being converted into Bitcoin.

Bitget then publicly asked the protocol to no longer process addresses associated with the theft. Gracy Chen formulated the request directly onwith a sentence that didn’t really leave users indifferent:

Decentralization is a design principle, not a shield to facilitate known stolen funds. The industry is watching.

Gracy Chen, X, September 26, 2026

The problem is that THORChain is not designed to function like a bank that blocks an account upon request. Users immediately recalled this in responses to the Bitget manager. Some even highlighted an embarrassing episode for the exchange: Bitget had removed RUNE from its platform a few days earlier.

The scene is quite revealing of the crypto world. Bitget wants to recover funds whose movements are publicly visible. THORChain defends its permissionless operation. So both parties can look at the exact same transactions and come to very different conclusions about what should be done.

Meanwhile, funds continue to move.

464 million in the fund, but a bill of 388 million

Bitget had at least one card to play: its User Protection Fund. The fund exceeded $464 million at the time of the attack. It is therefore large enough to absorb the approximately $388 million missing without asking customers to pay the difference.

The platform also claims that user balances have not been affected. She also began to gradually reopen withdrawals. Bitcoin returned on September 28 at 8 a.m. UTC on Bitcoin and BSC. Ethereum is due to follow on September 29, then other assets and services in the following days.

The restart was quick. As of 9 a.m. UTC, Bitget reported having already processed 9,585 withdrawals representing approximately 4,098 BTC.

But the figure of 464 million also gives an idea of ​​the fragility of the system. There remains a difference between having a protection fund and preventing another incident. The first helps absorb the shock. The second requires understanding how the attacker obtained access.

Bitget plans to publish its security report this week. The exchange has also launched a recovery program: 5% of the frozen funds and 5% of the sums recovered can be paid in the form of a bounty to people or organizations whose intervention will have directly enabled their recovery.

The biggest work begins now. It is no longer just a matter of counting what was stolen, but of understanding why the system let the first transaction go through.

Key figures

  • $388 million disappeared during the September 24 attack.
  • $464 million was available in the User Protection Fund.
  • 9,585 Bitcoin withdrawals were processed in the first hour.
  • 17 major trades were executed on eight different networks.
  • 4,098 BTC were withdrawn after withdrawals gradually reopened.

The Bitget case adds to an already particularly difficult year for crypto security. Ethereum accounts for 53% of the losses recorded in 2026, while Solana is also among the preferred targets of attackers. The attack above all reminds us of one thing: protecting the keys is no longer enough. In a crypto exchange, access, service providers and intermediary systems are now part of the perimeter to be defended.

Maximize your Tremplin.io experience with our ‘Read to Earn’ program! For every article you read, earn points and access exclusive rewards. Sign up now and start earning benefits.

Similar Posts