Bitget Exchange Reveals Details on $388 Million Security Incident
Bitget Exchange has revealed more details about its recent security incident that affected nearly $388 million in assets. According to Bitget CEO Gracy Chen, the attacker exploited a vulnerability in a third-party security product to obtain high-level internal credentials.
The attacker then used these credentials to send fraudulent withdrawal commands to Bitget's wallet system, triggering abnormal transfers that bypassed existing risk controls. The exchange confirmed that its private keys were not compromised and that its cold wallets were not affected.
The incident occurred on September 24th, with the attacker initiating two relatively small transactions followed by 17 larger transfers involving various assets. Bitget's monitoring systems detected a significant discrepancy at 19:05 UTC, prompting an automatic block of user-initiated withdrawals across the platform.
Chen stated that the attack was 'a sophisticated targeted operation' and that the exchange does not currently believe it was an inside job. The forensic investigation is ongoing, with firms Mandiant and SlowMist supporting the analysis. Bitget has also frozen some assets through industry cooperation and expects to complete its official security report this week.
The exchange has begun a phased restoration of withdrawal services, with BTC withdrawals on the Bitcoin and BSC networks resuming at 08:00 UTC on September 28th. Chen noted that user account balances were not affected, and losses from the incident will be covered by Bitget's User Protection Fund.