TL;DR
-
Bitget resumed BTC withdrawals on Bitcoin and BSC on Sept. 28, four days after an exploit drained about $388 million.
-
ETH withdrawals are scheduled for Sept. 29, USDT withdrawals for Sept. 30, and remaining services for Oct. 2, subject to security checks.
-
Bitget says the attacker exploited a third-party security product to obtain internal credentials. The investigation remains open.
Bitget has begun restoring withdrawals after a Sept. 24 security breach led to approximately $388 million in unauthorized transfers. The exchange said BTC withdrawals on the Bitcoin and BSC networks resumed at 8 a.m. UTC on Monday, Sept. 28.
Withdrawals are returning in stages because each network must pass security checks before reopening, according to Bitget.
The exchange said ETH withdrawals on Ethereum, BSC, Arbitrum, Base and Optimism are scheduled to resume at 8 a.m. UTC on Sept. 29. USDT withdrawals on Ethereum, BSC, Solana and Tron are scheduled for the same time on Sept. 30.
Bitget plans to restore withdrawals for all remaining assets, along with fiat withdrawals and peer-to-peer transactions, on Oct. 2.
How the Exploit Occurred
The breach began at approximately 6:31 p.m. UTC on Sept. 24, when unauthorized transfers were made from Bitget’s hot and warm wallet infrastructure across multiple networks.
Bitget said the attacker exploited a vulnerability in a third-party security product to obtain high-level internal credentials. Those credentials were then used to issue fraudulent withdrawal commands that bypassed the exchange’s risk controls.
The exchange said its private keys were not compromised and that customer balances and cold wallets were unaffected. It also said it has patched the vulnerability, contained the incident, and detected no further unauthorized transfers. Previous reporting identified ETH, USDT, USDC, AVAX and BNB among the assets moved.
The Bitget hacker moved about $83 million in stolen XRP from initial holding wallets. Bitget says its protection fund covers the $387.5 million breach.
Bitget Promises to Cover Losses
Bitget said it will fully cover the losses through its User Protection Fund, which it said holds 5,500 BTC. The exchange has also offered a bounty equal to 5% of any attacker funds successfully frozen or recovered through a participant’s direct actions.
Some affected assets have already been frozen with help from industry partners, Bitget said, though it has not disclosed their value. Mandiant and SlowMist are assisting with the investigation, and the exchange expects to publish a security report this week.
Bitget has previously said it suspects North Korean involvement but has not reached a firm conclusion about the attacker’s identity.
The investigation’s findings may provide a clearer account of how the third-party vulnerability was exploited and how the stolen funds were moved.
Hassan Maishera