Bitget Reopens Withdrawals After $388M Hack Exploits Third-Party Vulnerability
The cryptocurrency exchange Bitget has restarted Bitcoin withdrawals after hackers exploited a third-party security vulnerability to steal approximately $388 million. According to a statement from CEO Gracy Chen, the attackers obtained high-level internal credentials through a vulnerability in an external security product, allowing them to issue fraudulent withdrawal commands and bypass risk controls.
The compromised infrastructure facilitated unauthorized transfers across multiple blockchain networks, including Ethereum, XRP Ledger, and Tron. Bitget initially pegged the damage at $351.6 million before subsequent reconciliation raised the figure to approximately $388 million.
Customer balances remain unaffected, with the exchange's User Protection Fund exceeding $464 million. The company is reviewing its third-party security dependencies, internal access controls, withdrawal verification, and abnormal activity detection. Forensic specialists Mandiant and Slowmist are assisting with the investigation.