Bitget Hack Exposes Weakness in Withdrawal Controls
Crypto exchange Bitget suffered a security breach on September 24, 2026, after an attacker exploited a vulnerability in a third-party security product and gained unauthorized access to critical systems within the exchange's wallet infrastructure.
The incident resulted in approximately $388 million in unauthorized crypto transfers across multiple blockchains. The attacker obtained high-level internal credentials and used them to issue fraudulent withdrawal commands that bypassed existing risk controls.
Affected infrastructure involved portions of the exchange's hot and warm wallets, while private keys and cold wallets were not compromised. Bitget temporarily suspended withdrawals, engaged Mandiant and SlowMist for independent forensic investigations, and activated its User Protection Fund to cover the financial impact.