Bitget Resumes BTC Withdrawals After $388M Attack
Bitget has resumed Bitcoin withdrawals after an attacker exploited high-level internal credentials to steal approximately $388 million in assets. The incident occurred on September 24, when the attacker used legitimate-looking credentials to insert fraudulent withdrawal commands that bypassed risk controls.
The exchange's CEO, Gracy Chen, explained during a public livestream that the attacker had reached internal credentials through a vulnerability in a third-party security product. Chen stated that private keys and cold wallets were not compromised and that the exchange has taken steps to fix the vulnerabilities.
Bitget's User Protection Fund exceeds $464 million, which will cover any losses from the incident. The exchange reported a comprehensive Proof of Reserves ratio of 127%, indicating that it has sufficient funds to cover user assets.