Bitget Resumes Withdrawals Amid $388M Security Breach Probe
Bitget has begun a phased resumption of withdrawals following a massive security breach that drained approximately $388 million from its hot and warm wallet infrastructure on September 24. The exchange confirmed that user balances and cold wallets remained intact, but the attacker exploited a vulnerability in a third-party security product to obtain high-level internal credentials.
The stolen funds include ETH, USDT, USDC, AVAX, and BNB, which were sent through anomalous transfers that bypassed risk controls. Bitget stated that no unauthorized transfers have occurred since the vulnerability was patched. The exchange has launched a bounty program offering 5% of the frozen or recovered funds to those who directly contribute to their recovery.
The Bitget User Protection Fund, holding 5,500 BTC, will fully cover the losses from the incident. Bitget suspects that the attackers are 'sophisticated' and have state backing, but has not drawn definitive conclusions until further investigation. The exchange expects to publish an official security report by the end of the week.
Withdrawals will be enabled in stages, with BTC on Bitcoin and BSC networks being the first to resume at 8 a.m. UTC today. ETH withdrawals on various networks will become available on September 29, followed by USDT withdrawals on October 1. Remaining assets, fiat withdrawals, and P2P transactions are expected to be operational by October 2.