Bitget Resumes Bitcoin Withdrawals Following Major Security Breach
The cryptocurrency exchange Bitget has taken significant steps towards restoring user confidence by resuming Bitcoin withdrawals just four days after an alarming security breach that resulted in unauthorized transfers amounting to approximately $387.5 million from part of its hot and warm wallet infrastructure. This incident, which was first detected on September 24, has raised serious concerns about the security measures in place at one of the industry’s prominent exchanges.
Starting at 08:00 UTC on September 28, Bitget announced the reopening of Bitcoin withdrawals after implementing additional security protocols and conducting extensive investigations. On September 26, the exchange issued a statement admitting that the vulnerability responsible for the breach had been identified and addressed. To ensure that such incidents don’t occur in the future, Bitget enlisted the help of cybersecurity firm Mandiant and blockchain security specialist SlowMist to aid in its analysis of the breach.
Tracing the Breach: A Flaw in Third-Party Security
The events leading up to this breach showcase the vulnerabilities that can arise from relying on external security products. Bitget’s internal security systems detected unauthorized transfers from several hot wallets, initially estimating the stolen amount at $351.6 million. However, as investigators classified the transactions more carefully, this figure was later revised to $387.5 million. Despite this revision, Bitget reassured its users that the increased estimate did not stem from additional illegal transfers, as the incident had been contained promptly.
Importantly, Bitget clarified that its cold wallets remained unaffected and that customer account balances had not been compromised, providing some reassurance to anxious users. The exchange had temporarily suspended withdrawals as a precautionary measure while it assessed its withdrawal infrastructure, although trading and deposits continued uninterrupted.
In a statement released on September 28 via social media platform X, Bitget specified that the breach stemmed from a flaw within a third-party security product. This vulnerability granted the attackers elevated internal credentials, enabling them to issue fraudulent withdrawal commands that evaded the company’s risk control measures.
Bitget’s Protection Fund, which was initially valued at over $464 million, has been invoked to cover the losses incurred during this breach. This fund aims to protect users’ assets in cases of significant incidents, creating a safety net that is critical in the volatile world of cryptocurrency.
The Road to Recovery: Phased Restoration of Services
Looking ahead, Bitget has outlined plans to gradually restore other withdrawal services as part of its recovery process. According to the schedule provided on September 26, the exchange is set to resume withdrawals for Ether (ETH) on September 29 across several networks, including Ethereum, BNB Smart Chain, Arbitrum, Base, and Optimism.
Following this, Tether (USDT) withdrawals are expected to resume on September 30 across various platforms, such as Ethereum, BNB Smart Chain, Solana, and TRON. By October 2, all other tokens, fiat withdrawals, and peer-to-peer (P2P) services are scheduled to come back online, which should help restore normalcy for users relying on the platform.
Bitget has also confirmed that the incident remains contained and has assured users that no further unauthorized transfers will occur. The exchange has promised to keep users informed and has expressed its commitment to ensuring the safety and integrity of user funds.
Ongoing Investigations and Future Precautions
As the investigation continues, the full scope of the incident remains unclear, including the identity of the attackers and the extent of the breach. Bitget has ruled out private-key compromise based on current findings, suggesting that the issue lay primarily with the third-party security product. The exchange has stated that it will undertake a review of how it assesses and implements third-party security solutions moving forward.
Additionally, Bitget has initiated a recovery bounty program and is actively coordinating efforts with law enforcement and various blockchain security firms to trace and recover the affected assets. Notably, some of the assets impacted by the breach have already been frozen, which may aid in the recovery process.
The incident serves as a stark reminder of the vulnerabilities present in the cryptocurrency ecosystem and the need for stringent security measures. As Bitget navigates this challenging period, the focus remains on safeguarding user assets and regaining their trust through transparency and diligence.

