Bitget Reopens Withdrawals After $387.5M Breach
Bitget has restored BTC withdrawals after attackers exploited a vulnerability in a third-party security product to steal approximately $387.5 million from the exchange's hot and warm wallet infrastructure.
The breach occurred when attackers obtained internal access credentials, which they used to submit forged withdrawal commands directly to Bitget's wallet systems, bypassing existing risk checks.
Private keys were not compromised, and Bitget's cold wallets remained unaffected. The exchange has designated its Protection Fund to absorb the financial impact of the breach, which currently stands at more than $464 million.
The fund exceeds the identified loss, leaving user account balances unchanged. Efforts to restrict the stolen funds have created a dispute over permissionless cross-chain infrastructure, with THORChain rejecting Bitget's request to block identified exploiter addresses.
Bitget has ruled out private-key compromise and isolated the affected systems, while strengthening controls around third-party security products, internal access, withdrawal verification, and abnormal-activity monitoring.