Bitget CEO Gracy Chen disclosed a detailed timeline of the exchange’s security incident during a livestream titled "Security Incident Review," saying a formal investigation report is expected later this week.
Small test transfers came first
According to Chen’s account, at 2:31 on Sept. 25 the attacker initiated two small transfers from Bitget hot wallets: 0.84 ETH on Ethereum and 93 TRX on Tron. Both amounts were below the platform’s risk-control threshold, so the system did not trigger an alert.
From 2:58 to 4:09, the attacker moved on to 17 large transfers across XRP, ZEC, BSC, Base, Arbitrum and Optimism, with a total value of about $360 million.
How the emergency response unfolded
At 3:05, Bitget’s reconciliation system detected a large discrepancy, and the risk-control system automatically blocked user withdrawal requests. The platform activated a P0 emergency response at 3:14. At 3:40, the technical team began taking loss-control measures.
By 4:40, because the company said it still could not fully rule out the risk of private key compromise, the wallet team started moving funds into cold wallets.
Between 4:55 and 5:13, the attacker launched a second round of seven transfers on Avalanche and other chains, worth about $28 million.
At 5:44, the technical team halted wallet withdrawal services including the signing machine and isolated inbound and outbound flows for security purposes. Between about 5:00 and 6:00, the platform began issuing public statements.
Later that day, the security team identified the root cause at 16:43, and the legal team reported the case to the jurisdiction where the operating entity is located at 21:42.
Service recovery plan
Bitget said deposits reopened at around 12:00 on Sept. 26 after the platform completed vulnerability remediation, service isolation and security checks.
The exchange said BTC withdrawals would reopen today. ETH, USDT and other token withdrawals, along with fiat services, will be restored gradually over the next few days.
Preliminary root-cause analysis
According to Bitget’s security team, the attacker exploited a zero-day vulnerability in a third-party security product to steal internal network credentials. Using valid identity access, the attacker entered critical internal management systems, then moved into wallet-related backend services and directly wrote forged withdrawal instructions.
Bitget said that let the attacker bypass risk checks that take place before withdrawal records are generated, transfer funds out of warm and hot wallets, and remove traces after each transfer.
The exchange said the attack did not involve common viruses or malware and described it as a highly sophisticated targeted operation. It also said private keys were not leaked and that the possibility of insider involvement has been preliminarily ruled out.
Before the formal report is released, Bitget said it will not speculate on the attacker’s identity.

