Bitget Hit by $388M Crypto Theft: Attack Exploited Vulnerability in Security Product
Bitget reported that it was hit by an attack on September 24th, resulting in approximately $387.5 million being transferred from its hot and warm wallet infrastructure. The unauthorized transfers began at around 6:31 p.m. ET (22:31 UTC) and continued until containment measures were taken.
The company stated that the attacker obtained high-level internal credentials, inserted fraudulent withdrawal commands, and bypassed existing risk controls to carry out the theft. Bitget's preliminary investigation revealed that this vulnerability was exploited in its hot and warm wallet infrastructure.
Initially, Bitget estimated losses at $351.6 million but later revised this figure upwards after reclassifying additional Zcash and TRON transfers. The updated total loss is approximately $388 million, which only accounts for the initial unauthorized transfers before containment measures were implemented.
Bitget has taken steps to isolate affected systems, reset credentials, and remediate the suspected vulnerability. Its Protection Fund will cover the financial impact of the theft, and a recovery program offering 5% of frozen or recovered funds is being launched for eligible participants.