How Did The Attacker Get Past Bitget’s Controls?
The attacker behind Bitget’s roughly $388 million security breach exploited a zero-day vulnerability in a third-party security product, obtained valid administrative credentials and inserted fraudulent withdrawal instructions directly into the exchange’s wallet backend, according to CEO Gracy Chen.
The new account provides a more detailed explanation of the Sept. 24 attack, which initially led Bitget to report about $351.6 million in affected assets. Subsequent reconciliation increased the estimate to approximately $387.5 million after additional Zcash and TRON transactions were identified.
Chen said the attacker first tested the compromised infrastructure at 18:31 UTC with two small unauthorized transfers: 0.184 ETH from an Ethereum hot wallet and 193 TRX from a Tron wallet. Both fell below Bitget’s risk-control threshold and generated no system alert.
About 30 minutes later, the operation escalated. Chen said 17 larger transactions were executed between 18:58 UTC and 20:09 UTC across Ethereum, XRP, Zcash, BNB Chain, Base, Arbitrum, Optimism and Avalanche, transferring about $361 million.
Bitget’s reconciliation system identified a major discrepancy at 19:05 UTC, seven minutes after the larger withdrawals began. The exchange then blocked user-initiated withdrawals across the platform.
Why Were The Transactions Treated As Legitimate?
The breach did not depend on stealing Bitget’s private keys. Chen said the zero-day allowed the attacker to enter an internal management system using valid administrative credentials and inject withdrawal commands into wallet-related backend systems.
That account is consistent with a separate technical assessment from GoPlus Security, which said the breach targeted Bitget’s transaction-signing trust chain rather than its private keys. Fraudulent transaction data could therefore pass through authorized signing infrastructure as if it had originated from legitimate internal systems.
The attacker also deleted traces associated with the fraudulent commands after executing them, making forensic reconstruction more difficult.
“It’s also, in my opinion, the trickiest part,” Chen said, referring to the deletion of those traces.
Bitget maintains that its cold wallets and private keys were not compromised. Mandiant and SlowMist are assisting with the investigation, while the exchange has said the underlying vulnerability has been identified and remediated.
Investor Takeaway
The breach shows why exchange security cannot be reduced to private-key protection. An attacker who compromises the systems that decide what should be signed can potentially produce valid transactions without ever obtaining the keys themselves.
Why Did The Small Test Transfers Matter?
The two low-value transfers offer one of the clearest clues about how the attacker validated access before committing to the larger drain. Because both transactions remained below Bitget’s alert threshold, they allowed the attacker to test whether unauthorized instructions would reach the signing and withdrawal systems without triggering an immediate response.
The episode also exposes the limits of controls built primarily around transaction size. Once the attacker confirmed that the underlying authorization route worked, the operation quickly moved from negligible test payments to hundreds of millions of dollars in transfers across multiple chains.
Recovery has become a separate challenge. FinanceFeeds previously reported that the attacker moved about $83 million in stolen XRP, while only a small portion of the wider haul has been immobilized through issuer-level freezes.
Chen declined to identify the suspected attackers before publication of the formal incident report, saying only that Bitget continues to suspect the same group investigators have been examining.
Can Bitget Absorb The Financial Hit?
Bitget says its User Protection Fund will absorb the loss. The fund was valued at about $465 million on Sept. 25, and Chen said the company intends to replenish it to at least $300 million within a week using corporate reserves. Bitget reported corporate reserves of more than $1.4 billion as of an Aug. 31 audit.
“An incident like this scale is very serious,” Chen said. “But serious doesn’t mean existential.”
The operational recovery has also started. Bitget resumed BTC withdrawals on Monday as part of a phased restoration, with the exchange saying more than 3,000 BTC were processed during the first hour.
ETH withdrawals are scheduled to reopen on Sept. 29 across Ethereum, BSC, Arbitrum, Base and Optimism. USDT withdrawals follow on Sept. 30, while other tokens, fiat withdrawals and peer-to-peer services are due to return on Oct. 2.
Investor Takeaway
Bitget appears able to cover the financial loss, but the longer-term test is operational: whether the exchange can restore withdrawals on schedule and show that the backend authorization weakness has been fully closed.
The formal forensic report will now carry unusual weight. Beyond attribution, traders and counterparties will be looking for a precise account of the third-party vulnerability, how administrative access bypassed existing controls and what changes Bitget has made to prevent valid credentials from being used to authorize fraudulent transactions again.
