Bitget CEO Gracy Chen says the attacker behind the exchange’s roughly $388 million security incident first tested its withdrawal controls with two small transfers before escalating to a much larger theft.
The initial transfers were made at about 6:31 p.m. UTC on Sept. 24, involving 0.184 ETH from an Ethereum hot wallet and 193 TRX from a Tron hot wallet. Both transactions were below Bitget’s risk control threshold and did not trigger alerts, according to Chen.
About 30 minutes later, the attacker began sending significantly larger amounts across multiple blockchain networks. Chen said 17 transactions between 6:58 p.m. and 8:09 p.m. UTC involved Ethereum, XRP, Zcash, BNB Chain, Base, Arbitrum, Optimism and Avalanche, with a combined value of about $361 million.
KEY TAKEAWAYS
- The attacker used two small transfers to test Bitget’s risk controls before the larger theft.
- The breach ultimately affected approximately $387.5 million in assets, according to Bitget’s latest accounting.
- The attacker exploited a vulnerability in a third party security product to obtain high level internal credentials.
- Bitget’s reconciliation system detected a major discrepancy seven minutes after the first large transfer.
- Mandiant and SlowMist independently confirmed that compromised third party security products provided the route into Bitget’s wallet environment.
- Bitget says its cold wallets and private keys were not compromised, while its Protection Fund has since been replenished to more than $300 million.
SMALL TRANSFERS PRECEDED THE MAIN ATTACK
The two early transactions appear to have provided the attacker with an opportunity to determine whether unauthorized withdrawal commands could pass through Bitget’s controls without immediately attracting attention. Once those transfers generated no alerts, the attacker moved to larger transactions. Bitget’s reconciliation system detected a significant discrepancy at 7:05 p.m. UTC, seven minutes after the first major transfer, prompting the exchange to block user initiated withdrawals across the platform.
Bitget later revised its estimated affected amount from $351.6 million to $387.5 million after incorporating additional transfers involving assets on Zcash and TRON. The exchange said the revision reflected more complete accounting of the same incident rather than additional unauthorized transfers.
THIRD PARTY SECURITY PRODUCTS PROVIDED THE ENTRY POINT
The investigation has since provided more detail about how the attacker reached Bitget’s wallet infrastructure. Bitget initially said the attacker exploited a vulnerability in a third party security product to obtain internal access credentials. Those credentials were then used to submit fraudulent withdrawal commands to wallet related backend systems, causing abnormal transfers to pass through existing processes.
The findings have now received independent support from Mandiant, part of Google Cloud, and blockchain security firm SlowMist. Bitget said both investigations identified compromises involving third party security products that ultimately enabled unauthorized access to its wallet environment. The incident therefore did not depend on the attacker obtaining Bitget’s private keys. The exchange maintains that its cold wallets were unaffected and that the vulnerability involved in the incident has been remediated.
The attacker also deleted traces associated with the fraudulent commands, according to Chen, complicating the forensic investigation.
“It’s also, in my opinion, the trickiest part,” Chen said, referring to the deletion of traces.
Mandiant and SlowMist have continued examining the attack path, while Bitget has published information on affected addresses and launched a recovery program for assets transferred to attacker controlled wallets.
BITGET RESTORES WITHDRAWALS AND REBUILDS PROTECTION FUND
The exchange began restoring withdrawals in stages after completing additional security checks. BTC withdrawals resumed on Sept. 28, followed by ETH on Sept. 29, USDT on Sept. 30 and other supported assets, fiat withdrawals and P2P services on Oct. 2. Bitget said the phased approach was designed to allow individual blockchain networks and withdrawal infrastructure to undergo separate security validation.
The financial impact is being covered by Bitget’s Protection Fund. The fund held more than $464 million before the incident, and Bitget said on Sept. 30 that it had replenished the fund to more than $300 million using company capital. Bitget has also published an updated proof of reserves following the incident, saying user assets remain fully backed on a 1:1 basis.
CONCLUSION
The Bitget breach highlights a security risk that extends beyond protecting private keys. The attacker reportedly entered through compromised third party security infrastructure, obtained legitimate internal credentials and then used those credentials to issue fraudulent withdrawal commands.
The two small transfers before the main theft also show how attackers can probe automated controls before committing to larger transactions. Bitget’s detection system eventually identified the abnormal activity within minutes, but by then substantial transfers had already taken place.
With Mandiant and SlowMist now having completed independent investigations, the next focus will be on how Bitget strengthens third party access, administrative permissions and withdrawal verification to prevent a similar attack path from being used again.
Related Posts:
Related posts:
- Circle Introduces Bridge Kit to Simplify Crosschain USDC Transfers
- Layerzero Introduced Zero, a New Blockchain to Target up to 2M Transactions per Second
- FDIC Chair Travis Hill Says, Stablecoins Under the Genius Act Will Not Qualify for Pass-Through Deposit Insurance
- New York’s Attorney General Secured $5M From Uphold for Promoting a Misleading Crypto Yield Product.
- Senator Schumer Proposes Agency to Address Corruption, Including Trump’s Crypto Ventures













