Bitget began a phased restoration of withdrawal services on Sept. 28, following a security incident identified four days earlier. BTC withdrawals on the Bitcoin and BSC networks resumed at 08:00 UTC as scheduled, with ETH withdrawals expected to follow on Sept. 29.
According to Bitget, the incident was contained after the company identified and remediated the vulnerability involved in the attack. The exchange said it has not identified further unauthorized transfers since containment and that user account balances were not affected.
The company said the attacker exploited a vulnerability in a third-party security product to obtain high-level internal credentials. Those credentials were then used to issue fraudulent withdrawal commands to the wallet system, resulting in abnormal transfers that bypassed existing risk controls.
Bitget said private keys were not compromised and that its cold wallets were not affected.
The exchange has since strengthened controls across its withdrawal infrastructure and is reviewing its use of third-party security products, internal access controls, withdrawal verification procedures and abnormal-activity monitoring.
The incident is described by Bitget as the first security breach of this nature affecting its exchange infrastructure in eight years of operation.
Investigation and asset recovery continue
Bitget said approximately $388 million in assets were transferred during the incident. The figure represents its latest reconciliation of transactions associated with the original attack and does not include additional transfers after containment.
Mandiant and SlowMist are supporting the forensic investigation, including analysis of the attack vector, validation of containment and remediation measures, and asset tracking. Bitget is also working with law enforcement agencies, other exchanges, blockchain projects and security specialists on tracing and recovery efforts.
According to the exchange, some affected assets have already been frozen through coordination with industry participants. Bitget has also published identified attacker addresses and related tracing data to support recovery efforts.
The company expects to publish an official security report during the week of Sept. 28, subject to verification of its findings.
Bitget said its security measures have expanded over the past eight years as the digital-asset industry has become more interconnected. The exchange currently reports a 127% reserve ratio and a User Protection Fund exceeding $464 million. These figures are Bitget's own reported metrics.
As of 09:00 UTC on Sept. 28, Bitget said it had processed 9,585 BTC withdrawals across the Bitcoin and BSC networks, totaling approximately 4,098 BTC.
ETH withdrawals are scheduled to resume on Sept. 29, followed by USDT withdrawals on Sept. 30. Other supported tokens, fiat withdrawals and P2P services are scheduled to resume on Oct. 2, with availability shown directly on the platform.
Separately, Bitget has launched a limited-time Alliance Program for eligible users running from Sept. 28 to Oct. 30. The exchange is also offering temporary fee benefits and extended PRO-level protection to eligible PRO clients and market makers through Project Stand Together.
Bitget said it will continue publishing updates on withdrawal restoration, the forensic investigation and asset recovery as additional information is verified.






