{"id":78785,"date":"2026-09-28T16:22:53","date_gmt":"2026-09-28T16:22:53","guid":{"rendered":"https:\/\/crowdfundjunction.com\/blog\/bitget-restarts-bitcoin-withdrawals-as-388m-hack-investigation-widens\/"},"modified":"2026-09-28T16:22:53","modified_gmt":"2026-09-28T16:22:53","slug":"bitget-restarts-bitcoin-withdrawals-as-388m-hack-investigation-widens","status":"publish","type":"post","link":"https:\/\/crowdfundjunction.com\/blog\/bitget-restarts-bitcoin-withdrawals-as-388m-hack-investigation-widens\/","title":{"rendered":"Bitget Restarts Bitcoin Withdrawals as $388M Hack Investigation Widens"},"content":{"rendered":"<p><b>(Originally posted on : Bitcoin News )<\/b><br \/>\n<\/p>\n<div>\n<div class=\"@container mb-[25px] rounded-sm overflow-clip py-0.5 pr-0.5 pl-2.5 bg-success-100\">\n<div class=\"flex flex-col gap-m overflow-clip rounded-[6px] !bg-success-10 p-3 @[420px]:p-m\">\n<h2 class=\"m-0 flex items-center gap-s text-[19px] !text-[#1c1c1c] md:text-[20px]\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"16\" height=\"10\" viewbox=\"0 0 16 10\" fill=\"none\" class=\"shrink-0 text-success-100\" aria-hidden=\"true\"><path d=\"M1 1.5h14\" stroke=\"currentColor\" stroke-width=\"2.5\" stroke-linecap=\"round\"\/><path d=\"M1 8.5h10\" stroke=\"currentColor\" stroke-width=\"2.5\" stroke-linecap=\"round\"\/><\/svg><span>Key Takeaways<\/span><\/h2>\n<ul class=\"m-0 flex list-none flex-col gap-m pl-0\">\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">Bitget\u2019s statement shared with Bitcoin.com News explains that the exchange traced its $388M breach to stolen credentials obtained through a third-party security flaw.<\/span><\/li>\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">Bitget processed 9,585 BTC withdrawals totaling 4,098 BTC by 9 a.m. UTC on Sept. 28.<\/span><\/li>\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">Bitget plans to restore ETH withdrawals Sept. 29 and release its security report this week.<\/span><\/li>\n<\/ul>\n<\/div>\n<\/div>\n<h2>Bitget\u2019s $388M Breach Traced to Third-Party Security Flaw<\/h2>\n<p>Eight years without a security incident of this magnitude came to a <a href=\"https:\/\/news.bitcoin.com\/security\/bitget-hit-by-351m-hack-withdrawals-frozen-as-probe-begins\/\">screeching halt for Bitget<\/a> on Sept. 24, when attackers exploited a vulnerability in a third-party security product and made off with approximately $388 million.<\/p>\n<p>Four days later, according to a statement shared with Bitcoin.com News, the exchange is reopening its withdrawal gates, beginning with bitcoin. Bitget says its $464 million-plus User Protection Fund remains available to protect customers, while onchain investigators continue tracing the stolen assets. The latest disclosure also reveals a peculiar twist: The attackers didn\u2019t need to steal private keys to pull off the heist.<\/p>\n<p>In its Sept. 28 statement, <a href=\"https:\/\/news.bitcoin.com\/featured\/bitget-ceo-wants-thorchain-to-block-hackers-but-theres-a-catch\/\">attributed to CEO Gracy Chen<\/a>, the exchange acknowledged the gravity of the incident, explaining that its previous security record was no excuse for what happened.<\/p>\n<p>\u201cThe September 24 incident is the first time in eight years that an attack of this nature has breached Bitget Exchange\u2019s infrastructure,\u201d the company stated. \u201cThat record does not diminish the seriousness of the incident. It sets the standard against which Bitget\u2019s response should now be measured.\u201d<\/p>\n<h2>Stolen Credentials Let Attackers Bypass Wallet Safeguards<\/h2>\n<p>Bitget\u2019s initial investigation found that the attackers obtained high-level internal credentials through a vulnerability in an external security product. Those credentials allowed them to issue fraudulent withdrawal commands to the exchange\u2019s wallet system, circumventing existing risk controls.<\/p>\n<p>Bitget explained:<\/p>\n<blockquote>\n<p>\u201cThe investigation found that the attacker exploited a vulnerability in a third-party security product to obtain high-level internal credentials.\u201d<\/p>\n<\/blockquote>\n<p>The company added that those credentials enabled unauthorized transfers, while emphasizing that \u201cprivate keys were not compromised and cold wallets were not affected.\u201d The compromised infrastructure facilitated unauthorized transfers across multiple blockchain networks, including Ethereum, XRP Ledger, and Tron. Alongside this, <a href=\"https:\/\/news.bitcoin.com\/crypto-news\/thorchain-faces-heat-as-bitget-hack-revives-bybit-controversy\/\">platforms such as Thorchain<\/a> and other rails like Uniswap, 1inch Fusion, and Stargate have been leveraged.<\/p>\n<p>Bitget initially pegged <a href=\"https:\/\/news.bitcoin.com\/featured\/everything-we-know-about-bitgets-massive-351m-hack\/\">the damage at $351.6 million<\/a> before subsequent reconciliation raised the figure to approximately $388 million. Rather than cracking the cryptographic mechanisms protecting customer assets, the attackers exploited trusted access to the infrastructure responsible for authorizing withdrawals. \u201cBitget has identified the attack path, remediated the vulnerability, and strengthened controls across its withdrawal infrastructure,\u201d the company explained on Monday.<\/p>\n<p>The exchange is now reviewing its third-party security dependencies, internal access controls, withdrawal verification and abnormal activity detection. It maintains that customer account balances remain unaffected.<\/p>\n<h2>Bitcoin Withdrawals Return as Investigators Hunt Stolen Funds<\/h2>\n<p>Bitget said it began restoring BTC withdrawals across the Bitcoin and BSC networks at 8 a.m. UTC on Sept. 28. By 9 a.m., the exchange reported processing 9,585 BTC withdrawals totaling approximately 4,098 BTC. Regarding the updated loss estimate, the company clarified that it \u201cdoes not represent additional unauthorized transfers following containment.\u201d<\/p>\n<p>Meanwhile, forensic specialists Mandiant and <a href=\"https:\/\/news.bitcoin.com\/security\/slowmist-warns-darksword-ios-exploit-targets-crypto-wallet-keys\/\">Slowmist are assisting<\/a> with the investigation, examining the attack methods, validating remediation measures and tracking the missing cryptocurrency. \u201cSome affected assets have already been frozen through coordination with industry partners,\u201d Bitget disclosed on Monday.<\/p>\n<p>The exchange has also shared identified attacker addresses and tracing information to help investigators follow the money. CEO Gracy Chen previously indicated that the attack methodology appeared highly consistent <a href=\"https:\/\/news.bitcoin.com\/lazarus-group-suspected-of-moving-175m-in-eth-after-arbitrum-freezes-71m-from-kelpdao-exploit\/\">with North Korean-linked groups<\/a>, although the investigation remains underway.<\/p>\n<p>The company stated:<\/p>\n<blockquote>\n<p>\u201cBitget expects to complete an official security report this week and will share further findings as they are verified.\u201d<\/p>\n<\/blockquote>\n<h2>Bitget\u2019s $464M Protection Fund Faces Its Biggest Test<\/h2>\n<p>The exchange\u2019s statement reports a comprehensive reserve ratio of 127%, alongside a User Protection Fund exceeding $464 million. Its latest disclosure maintains that customer balances remain unaffected, despite the incident representing its first <a href=\"https:\/\/news.bitcoin.com\/interview\/nexus-id-breach-exposes-a-blueprint-for-fraud-experts-warn\/\">security breach<\/a> of this nature in eight years.<\/p>\n<p>\u201cBitget\u2019s response to this incident will therefore extend beyond remediation of the vulnerability itself,\u201d the company explained in the notice. ETH withdrawals are scheduled to resume Sept. 29, followed by USDT on Sept. 30 and other supported tokens, fiat and peer-to-peer services on Oct. 2.<\/p>\n<p>\u201cThe focus now is on applying the findings from this incident across the platform and strengthening the safeguards required as Bitget\u2019s infrastructure and product offerings continue to expand,\u201d the statement shared with our newsdesk concludes.<\/p>\n<\/p><\/div>\n<p><a href=\"https:\/\/news.bitcoin.com\/exchanges\/bitget-restarts-bitcoin-withdrawals-388m-hack-investigation-widens\/\">Source link <\/a><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>(Originally posted on : Bitcoin News ) Key Takeaways Bitget\u2019s statement shared with Bitcoin.com News explains that the exchange traced its $388M breach to stolen credentials obtained through a third-party security flaw. Bitget processed 9,585 BTC withdrawals totaling 4,098 BTC by 9 a.m. UTC on Sept. 28. Bitget plans to restore ETH withdrawals Sept. 29 [&hellip;]<\/p>\n","protected":false},"author":19,"featured_media":78786,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0},"categories":[32],"tags":[],"_links":{"self":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/78785"}],"collection":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/users\/19"}],"replies":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/comments?post=78785"}],"version-history":[{"count":0,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/78785\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media\/78786"}],"wp:attachment":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media?parent=78785"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/categories?post=78785"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/tags?post=78785"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}