Bitget has begun restoring exchange withdrawals in stages after an exploit drained about $388 million from its hot and warm wallets on Sept. 24. The exchange says it has patched the vulnerability and will cover losses through its user protection fund, while Mandiant and SlowMist investigate the breach.
Bitget started processing BTC withdrawals on the Bitcoin network at 8 a.m. UTC on Monday, the first step in a phased restart following the Sept. 24 hot wallet exploit. The exchange says each blockchain must clear a round of security checks before its withdrawals reopen.
A staggered restart across chains
Following Monday's Bitcoin withdrawals, Bitget said ETH withdrawals on Ethereum, BSC, Arbitrum, Base, and Optimism open on Sept. 29 at 8 a.m. UTC. USDT withdrawals on Ethereum, BSC, Solana, and Tron follow a day later at the same time, and the exchange says all remaining assets, fiat withdrawals, and P2P transactions return on Oct. 2.
How the exploit unfolded
Unauthorized transfers hit Bitget's wallet infrastructure across multiple networks starting at around 6:31 p.m. UTC on Sept. 24. The exchange says the attacker targeted a vulnerability in a third-party security product to obtain high-level internal credentials, then used them to send fraudulent withdrawal commands to the wallet system.
According to Bitget: "these credentials to send fraudulent withdrawal commands to the wallet system" triggered transfers that bypassed the exchange's risk controls. Bitget has not named the stolen assets in its latest statement, though The Block previously reported that ether, USDT, USDC, AVAX, and BNB were among the assets moved. The exchange says its private keys were not compromised and that user balances and cold wallets were unaffected.
Recovery and fund coverage
Bitget says the $388 million loss makes this the largest reported crypto theft so far this year, above exploits on KelpDAO and Drift Protocol. However, losses will be fully covered by the Bitget User Protection Fund, which holds 5,500 BTC.
The exchange has also launched a bounty program, offering 5% of any attacker funds successfully frozen or recovered to parties whose actions lead to recovery. Mandiant and SlowMist are assisting with the investigation, and Bitget says it will review how it assesses and deploys third-party security products.
Bitget says it will not speculate about the attackers' identity until the investigation concludes, but it described them as sophisticated and state-backed. It has previously told media that it suspects North Korea was behind the attack.
Source: The Block
Trading involves risk.