Table of Contents

BITGET ATTACKER TESTED RISK CONTROLS BEFORE $388M THEFT

Hooded figure typing on a laptop

Bitget CEO Gracy Chen says the attacker behind the exchange’s roughly $388 million security incident first tested its withdrawal controls with two small transfers before escalating to a much larger theft.

The initial transfers were made at about 6:31 p.m. UTC on Sept. 24, involving 0.184 ETH from an Ethereum hot wallet and 193 TRX from a Tron hot wallet. Both transactions were below Bitget’s risk control threshold and did not trigger alerts, according to Chen.

About 30 minutes later, the attacker began sending significantly larger amounts across multiple blockchain networks. Chen said 17 transactions between 6:58 p.m. and 8:09 p.m. UTC involved Ethereum, XRP, Zcash, BNB Chain, Base, Arbitrum, Optimism and Avalanche, with a combined value of about $361 million.

KEY TAKEAWAYS

  • The attacker used two small transfers to test Bitget’s risk controls before the larger theft.
  • The breach ultimately affected approximately $387.5 million in assets, according to Bitget’s latest accounting.
  • The attacker exploited a vulnerability in a third party security product to obtain high level internal credentials.
  • Bitget’s reconciliation system detected a major discrepancy seven minutes after the first large transfer.
  • Mandiant and SlowMist independently confirmed that compromised third party security products provided the route into Bitget’s wallet environment.
  • Bitget says its cold wallets and private keys were not compromised, while its Protection Fund has since been replenished to more than $300 million.

SMALL TRANSFERS PRECEDED THE MAIN ATTACK

The two early transactions appear to have provided the attacker with an opportunity to determine whether unauthorized withdrawal commands could pass through Bitget’s controls without immediately attracting attention. Once those transfers generated no alerts, the attacker moved to larger transactions. Bitget’s reconciliation system detected a significant discrepancy at 7:05 p.m. UTC, seven minutes after the first major transfer, prompting the exchange to block user initiated withdrawals across the platform.

Bitget later revised its estimated affected amount from $351.6 million to $387.5 million after incorporating additional transfers involving assets on Zcash and TRON. The exchange said the revision reflected more complete accounting of the same incident rather than additional unauthorized transfers.

THIRD PARTY SECURITY PRODUCTS PROVIDED THE ENTRY POINT

The investigation has since provided more detail about how the attacker reached Bitget’s wallet infrastructure. Bitget initially said the attacker exploited a vulnerability in a third party security product to obtain internal access credentials. Those credentials were then used to submit fraudulent withdrawal commands to wallet related backend systems, causing abnormal transfers to pass through existing processes.

The findings have now received independent support from Mandiant, part of Google Cloud, and blockchain security firm SlowMist. Bitget said both investigations identified compromises involving third party security products that ultimately enabled unauthorized access to its wallet environment. The incident therefore did not depend on the attacker obtaining Bitget’s private keys. The exchange maintains that its cold wallets were unaffected and that the vulnerability involved in the incident has been remediated.

The attacker also deleted traces associated with the fraudulent commands, according to Chen, complicating the forensic investigation.

“It’s also, in my opinion, the trickiest part,” Chen said, referring to the deletion of traces.

Mandiant and SlowMist have continued examining the attack path, while Bitget has published information on affected addresses and launched a recovery program for assets transferred to attacker controlled wallets.

BITGET RESTORES WITHDRAWALS AND REBUILDS PROTECTION FUND

The exchange began restoring withdrawals in stages after completing additional security checks. BTC withdrawals resumed on Sept. 28, followed by ETH on Sept. 29, USDT on Sept. 30 and other supported assets, fiat withdrawals and P2P services on Oct. 2. Bitget said the phased approach was designed to allow individual blockchain networks and withdrawal infrastructure to undergo separate security validation.

The financial impact is being covered by Bitget’s Protection Fund. The fund held more than $464 million before the incident, and Bitget said on Sept. 30 that it had replenished the fund to more than $300 million using company capital. Bitget has also published an updated proof of reserves following the incident, saying user assets remain fully backed on a 1:1 basis.

CONCLUSION

The Bitget breach highlights a security risk that extends beyond protecting private keys. The attacker reportedly entered through compromised third party security infrastructure, obtained legitimate internal credentials and then used those credentials to issue fraudulent withdrawal commands.

The two small transfers before the main theft also show how attackers can probe automated controls before committing to larger transactions. Bitget’s detection system eventually identified the abnormal activity within minutes, but by then substantial transfers had already taken place.

With Mandiant and SlowMist now having completed independent investigations, the next focus will be on how Bitget strengthens third party access, administrative permissions and withdrawal verification to prevent a similar attack path from being used again.

Disclaimer: This article is intended solely for informational purposes and should not be considered trading or investment advice. Nothing herein should be construed as financial, legal, or tax advice. Trading or investing in cryptocurrencies carries a considerable risk of financial loss. Always conduct due diligence before making any trading or investment decisions.

Trade with proof of Reserves

UEEx publish monthly audits and third party verification on every listed market.

COLD STORAGE
0 %
AUDIT
Monthly 0

UEEx Weekly Digest

Market analysis and security alerts, read by 10,000 traders

UEEx Weekly Digest

Market analysis, trading strategies, futures insights, and security alerts delivered weekly. Read by 10,000+ crypto traders.

No spam. Unsubscribe anytime