Bitget restores withdrawals and sees inflows return days after $388 million security incident

Bitget restores withdrawals and sees inflows return days after $388 million security incident

N
News Editor
2026-10-03 08:25:43
Bitget said roughly $388 million in assets were affected by a Sept. 25 security incident that investigators traced to a zero-day vulnerability in a third-party security product, not a private key leak or cold wallet compromise. The exchange said its user protection fund, established in 2022 and holding 5,500 BTC worth more than $464 million at the time, would absorb the loss, with CEO Gracy Chen pledging to replenish the fund to its $300 million baseline within one week. That refill was completed by Sept. 30. Withdrawals resumed in stages under a previously published timetable, with BTC reopening on Sept. 28, ETH on Sept. 29, USDT-related networks on Sept. 30, and other tokens, fiat and C2C services on Oct. 2. After ETH withdrawals resumed, on-chain data cited in the report showed related hot wallets quickly shifted from net outflows to net inflows. Bitget later said ETH saw about 9,674 in inflows and 9,023 in outflows during the first hour after reopening, for net inflows of around 651 ETH. On Sept. 30, the exchange also reported $231 million in 24-hour inflows and published its 47th proof-of-reserves report, showing a total reserve ratio of 131% across 19 assets.

Bitget said about $388 million in assets were affected in a Sept. 25 security incident, then reopened withdrawals in stages over the following days as funds began flowing back onto the platform. CEO Gracy Chen said in a livestream that it was the first security event of this kind in the exchange's eight years of operation. Investigations disclosed by SlowMist said the earliest confirmed malicious activity involved a zero-day vulnerability on a node tied to a third-party security product. Findings from both Mandiant and SlowMist pointed to a breach of third-party security infrastructure that later reached Bitget's wallet environment.

Bitget restores withdrawals and sees inflows return days after $388 million security incident 2

After the incident, Bitget said losses would be covered by its user protection fund. The fund, established in 2022, held 5,500 BTC worth more than $464 million at the time. Gracy said the fund would be replenished to $300 million within one week after use, restoring the baseline level set when it was created in 2022. That commitment had been fulfilled by Sept. 30.

Withdrawals resumed according to the schedule Bitget had published earlier. BTC withdrawals reopened first at 16:00 on Sept. 28. After ETH withdrawals resumed on Sept. 29, related hot wallets quickly moved from net outflows to net inflows, with balances soon edging above the level seen before withdrawals reopened. By press time, withdrawals for all tokens had been restored.

The period between the theft of nearly $400 million and the return of withdrawals and fresh inflows lasted only a few days. The report frames the episode around three questions: how assets were moved without a private key leak, how a protection fund prepared years in advance was actually deployed, and what Bitget did to turn the situation around.

A zero-day flaw in a third-party security product opened the door

One unusual element of the attack, according to the report, is that Bitget's private keys were not leaked, its cold wallets were not breached, and the event was not caused by a smart contract vulnerability. The entry point was instead a third-party security product used by the platform.

Bitget restores withdrawals and sees inflows return days after $388 million security incident 3

Under the findings Bitget has disclosed so far, the earliest confirmed small on-chain transfer linked to the incident appeared at around 02:31 Beijing time on Sept. 25. Larger asset transfers followed.

In comments to The Block, Gracy said the attacker carried out 17 large transactions across Ethereum, XRP, Zcash, BNB Chain, Base, Arbitrum, Optimism and Avalanche between 02:58 and 04:09. As later accounting was added, Bitget put the final impact at about $388 million in assets.

At 03:05, about seven minutes after the first large transfer, Bitget's reconciliation system detected a clear discrepancy in funds and triggered a platform-wide withdrawal block. At 03:14, the exchange activated its highest-level emergency response. Because a private key leak could not yet be ruled out at that point, the wallet team moved assets to cold wallets and shut down withdrawal and signing services.

Security teams later identified the root cause. Under the attack chain now disclosed, the attacker exploited a previously unknown zero-day vulnerability in a third-party security product. In this context, a zero-day means a security flaw that neither the vendor nor the user had identified in advance and for which no patch was available beforehand.

Bitget said the attacker used that flaw to steal credentials for internal network permissions, forge withdrawal instructions to the wallet system and trick the wallet into executing abnormal transfers that bypassed risk checks. Throughout the process, private keys were not exposed and cold wallets were not affected. Gracy later added that the attacker deleted part of the related traces after completing the operation, making forensic work and reconstruction more difficult.

Bitget restores withdrawals and sees inflows return days after $388 million security incident 4

Bitget then disabled the affected third-party function, reissued internal credentials, revoked and repartitioned highly sensitive permissions, and added independent checks for withdrawals. Mandiant and SlowMist are still involved in independent forensics and fund tracing.

The direct warning for the industry is that an exchange's security perimeter no longer stops at private keys and cold wallets. Security software, wallet infrastructure and other third-party services that can touch core systems may also become attack surfaces.

The protection fund absorbed the loss, and withdrawals resumed on schedule

After the incident, Bitget first turned to its protection fund. The fund was created in 2022 and has long used $300 million as its baseline size. At the time of the incident, it held 5,500 BTC worth more than $464 million, enough to cover the roughly $388 million ultimately confirmed as affected.

Bitget then said the financial impact of the incident would be borne by the protection fund and that user account balances would not be affected. Before BTC withdrawals resumed on Sept. 28, on-chain activity already showed the fund beginning to move assets into hot wallets. On-chain analyst Ai Yi said an initial 2,042.28 BTC was transferred from a related protection fund address into a Bitget hot wallet.

The report describes this as one of the most instructive parts of Bitget's response. The protection fund was not a compensation package announced after the fact. It had been set up years earlier, funded over time, made visible through public wallet addresses and anchored to a stated size benchmark. When the incident happened, it was used. Afterward, it was replenished to the prior standard.

Bitget restores withdrawals and sees inflows return days after $388 million security incident 5

Gracy said Bitget would restore the protection fund to at least $300 million within one week. Based on on-chain tracking cited in the report, that pledge was carried out on schedule.

On Sept. 30, Bitget also released its 47th proof-of-reserves report, showing a total reserve ratio of 131% across 19 assets. The reserve ratios for BTC, ETH, USDT and USDC were 142%, 110%, 107% and 154%, respectively.

Funding was only one part of the response. The report also highlights Bitget's communication over those days. Gracy spent about three hours answering questions in a community livestream, while Xie Jiayin kept posting updates through social media channels and community groups. During the most chaotic phase of the incident, management stayed visible and kept addressing questions.

Key public statements were paired with concrete information or next steps. The question of who would bear the loss was answered quickly: the protection fund would cover it. When the affected amount was revised from $351.6 million to $388 million, Bitget explained why the number had changed. Before the attack vector was confirmed, the exchange did not rush to define the attacker's identity or method. As the investigation progressed, it released more details about the third-party security product, the zero-day flaw, high-privilege credentials and forged withdrawal instructions.

Bitget restores withdrawals and sees inflows return days after $388 million security incident 6

Withdrawal recovery followed the same pattern. Because the incident involved multiple assets and multiple networks, the review was not limited to a single wallet. Bitget did not restore all withdrawals at once. It reopened them in batches only after checking the relevant wallets, networks and risk conditions one by one.

  • On Sept. 26, the platform published a detailed recovery schedule.
  • BTC was set to return on Sept. 28.
  • ETH and related networks were scheduled for Sept. 29.
  • USDT and related networks were scheduled for Sept. 30.
  • Other tokens, fiat and C2C services were scheduled for Oct. 2.

Before publication, the report said all of those services had been verified as restored on time. For a large-scale security incident spanning multiple assets, multiple networks, third-party software and internal permissions, publishing a dated timetable first and then meeting it item by item became a key part of the response.

Net inflows returned after ETH withdrawals reopened

After ETH withdrawals resumed on Sept. 29, on-chain data showed a notable change. According to Ai Yi, related hot wallets prepared for ETH withdrawals climbed back above 30,000 ETH within half an hour of reopening, surpassing their initial balance.

Bitget later said that in the first hour after withdrawals resumed, ETH inflows were about 9,674 while outflows were about 9,023, leaving net inflows of around 651 ETH. Data released on Sept. 30 showed 24-hour platform inflows of $231 million, close to the average daily inflow of $245 million in August this year. The report says that outcome did not match earlier fears of one-way outflows and instead pointed to recovering confidence.

At the same time, Bitget rolled out a series of incentive campaigns. ETH PoolX offered a 500,000 USDT reward pool, with users able to lock ETH and share the rewards. The early campaign page at one point showed an estimated APR of about 37.11%, which later moved lower as participation increased. BTC PoolX followed with a 100,000 BGB reward pool and extra boosts tied to users' BTC holdings over the previous 15 days.

Bitget restores withdrawals and sees inflows return days after $388 million security incident 7

For stablecoins, Bitget launched flexible yield campaigns for USDT and USDGO that allowed deposits and withdrawals at any time, with limited-time APRs of 10% and 12%, respectively. A separate "peer program" allocated 30% of eligible trading fee revenue during the campaign to a user reward pool, with 60% distributed by trading volume and 40% by asset size. On Oct. 2, Bitget said the first batch of rewards had been distributed, with 1,907,455 USDT paid to 763,543 users.

The report's reading is direct. Restoring withdrawals answered the question of whether users could leave. The campaigns that followed were aimed at restarting trading, savings products and capital retention. A few days earlier, the market's main concern had been when funds could be withdrawn. After withdrawals resumed, attention began shifting to which activity offered the better APR. In the report's framing, that marked a turning point.

Industry support extended beyond Bitget itself

The report says Bitget received backing from a broad range of industry participants after the incident, with Bybit highlighted as the most notable case.

In February 2025, Bybit suffered a security incident involving about $1.4 billion. Roughly five hours after that attack, Bitget provided 40,000 ETH to Bybit, valued at more than $100 million at the time. That 40,000 ETH carried no interest, no collateral requirement and no fixed repayment deadline. Bybit repaid the full amount within three days.

More than a year later, the positions were reversed. After Bitget was hit, Bybit CEO Ben Zhou quickly said he was willing to help and added: 「When we were hacked, Bitget helped us.」 Bybit then added the related stolen funds to the LazarusBounty tracking system.

Bitget restores withdrawals and sees inflows return days after $388 million security incident 8

Support also came from elsewhere. CZ publicly voiced support after the incident. Binance's security team then worked with Bitget on threat intelligence sharing, tracing stolen funds and supporting asset recovery. MEXC CEO Vugar Usi also reached out to Bitget to offer support. Outside the exchanges, Mandiant and SlowMist joined the investigation and evidence collection, while Circle and Tether took part in related asset freezes.

What the incident left behind for the exchange sector

The report argues that the significance of the incident goes beyond a show of solidarity. Crypto has no single institution that backstops losses, but protection funds, peer coordination, security firms and on-chain tracing are forming a risk-response network of their own. At the same time, exchanges now have to defend a wider perimeter, from hot wallets and signing systems to third-party software and internal permissions, as attacks grow more complex.

Setting up a protection fund in advance, staying transparent afterward, following through on commitments and cooperating across the industry are presented as a working crisis-response model. Over the past two years, the industry has talked constantly about mass adoption. ETFs, stablecoins, RWA and tokenized securities have brought in more traditional financial capital, while the U.S. regulatory framework has continued to take shape. At this stage, the report says, crypto needs to prove not only that it can innovate and grow, but also that it can manage risk.

In that sense, Bitget's response turned a loss of roughly $400 million into a test of a platform's sense of responsibility, its ability to absorb losses, communicate clearly and restore operations. The report ends on a broader point: how the financial world judges crypto may depend on how it handles its worst day.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.