Bitget Resumes BTC Withdrawals After Security Incident on September 24
Bitget has resumed BTC withdrawals after a security incident on September 24. The exchange experienced its first-ever security breach in eight years, where an attacker exploited vulnerabilities in a third-party security product to obtain high-level internal credentials.
The attacker then used these credentials to send fraudulent withdrawal commands directly to the wallet system, likely bypassing risk controls and triggering abnormal transfers. Private keys were not compromised, and cold wallets were not affected.
Bitget isolated the affected systems, remediated the vulnerability, revoked and reissued internal credentials, and restructured access to highly sensitive systems. The exchange has also published the identified attacker addresses publicly to support broader industry collaboration and asset recovery.
The frozen amount represents a small fraction of the total stolen assets. Bitget has requested THORChain to refuse service to the identified attacker addresses. Every user balance is fully covered by the Bitget Protection Fund, which will be topped back up to over $300 million with the firm's own capital within the week.