Bitget lays out timeline of security incident, says full report will be released this week

Bitget lays out timeline of security incident, says full report will be released this week

N
News Editor
2026-09-28 07:55:47
Bitget CEO Gracy Chen used a livestream titled "Security Incident Review" to disclose a detailed timeline of the exchange’s recent security breach and said a formal investigation report is expected this week. According to the account, the attacker first sent two small test transfers at 2:31 on Sept. 25 — 0.84 ETH on Ethereum and 93 TRX on Tron — both below the platform’s risk-control threshold, so no alert was triggered at that point. Between 2:58 and 4:09, the attacker then initiated 17 large transfers across XRP, ZEC, BSC, Base, Arbitrum and Optimism, worth about $360 million in total. Bitget said its reconciliation system detected a major discrepancy at 3:05, which triggered an automatic block on user withdrawal requests. A P0 emergency response was launched at 3:14, and technical loss-control measures followed at 3:40. Later, a second wave of seven transfers across Avalanche and other chains took place between 4:55 and 5:13, valued at about $28 million. The exchange said deposits reopened around 12:00 on Sept. 26 after patching the vulnerability, isolating services and completing security checks. BTC withdrawals are scheduled to resume today, with ETH, USDT and fiat services to follow over the next few days. In its preliminary root-cause analysis, Bitget said the attacker exploited a zero-day flaw in a third-party security product, stole internal network credentials, entered critical internal management systems using valid identity access, and then wrote forged withdrawal instructions directly into wallet-related backend services. The exchange said private keys were not compromised and that insider involvement has been preliminarily ruled out.

Bitget CEO Gracy Chen disclosed a detailed timeline of the exchange’s security incident during a livestream titled "Security Incident Review," saying a formal investigation report is expected later this week.

Small test transfers came first

According to Chen’s account, at 2:31 on Sept. 25 the attacker initiated two small transfers from Bitget hot wallets: 0.84 ETH on Ethereum and 93 TRX on Tron. Both amounts were below the platform’s risk-control threshold, so the system did not trigger an alert.

From 2:58 to 4:09, the attacker moved on to 17 large transfers across XRP, ZEC, BSC, Base, Arbitrum and Optimism, with a total value of about $360 million.

How the emergency response unfolded

At 3:05, Bitget’s reconciliation system detected a large discrepancy, and the risk-control system automatically blocked user withdrawal requests. The platform activated a P0 emergency response at 3:14. At 3:40, the technical team began taking loss-control measures.

By 4:40, because the company said it still could not fully rule out the risk of private key compromise, the wallet team started moving funds into cold wallets.

Between 4:55 and 5:13, the attacker launched a second round of seven transfers on Avalanche and other chains, worth about $28 million.

At 5:44, the technical team halted wallet withdrawal services including the signing machine and isolated inbound and outbound flows for security purposes. Between about 5:00 and 6:00, the platform began issuing public statements.

Later that day, the security team identified the root cause at 16:43, and the legal team reported the case to the jurisdiction where the operating entity is located at 21:42.

Service recovery plan

Bitget said deposits reopened at around 12:00 on Sept. 26 after the platform completed vulnerability remediation, service isolation and security checks.

The exchange said BTC withdrawals would reopen today. ETH, USDT and other token withdrawals, along with fiat services, will be restored gradually over the next few days.

Preliminary root-cause analysis

According to Bitget’s security team, the attacker exploited a zero-day vulnerability in a third-party security product to steal internal network credentials. Using valid identity access, the attacker entered critical internal management systems, then moved into wallet-related backend services and directly wrote forged withdrawal instructions.

Bitget said that let the attacker bypass risk checks that take place before withdrawal records are generated, transfer funds out of warm and hot wallets, and remove traces after each transfer.

The exchange said the attack did not involve common viruses or malware and described it as a highly sophisticated targeted operation. It also said private keys were not leaked and that the possibility of insider involvement has been preliminarily ruled out.

Before the formal report is released, Bitget said it will not speculate on the attacker’s identity.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.