Bitget Suffers $387.5M Security Breach, Plans for IPO Remain Intact
Bitget, a cryptocurrency exchange, has suffered a significant security breach that resulted in the loss of $387.5 million in unauthorized withdrawals. The attack occurred on September 24 at 18:31 UTC and affected hot and warm wallets, but not cold wallets or private keys.
The stolen assets included approximately 103 million XRP (worth about $157 million) as well as ETH and USDT, with additional tokens reportedly affected across several blockchain networks. According to Bitget CEO Gracy Chen, the attackers spoofed transfer data, tricking the exchange's authorization-signing process into approving withdrawals that should never have gone through.
The dollar figure attached to the breach has shifted more than once, initially estimated at $183 million and later revised upward to $387.5 million after additional stolen assets were tracked across the Zcash and TRON networks. Bitget's User Protection Fund holds over $464 million, which will fully cover the losses, leaving about $76 million to spare.
Despite the breach, Chen has reaffirmed plans to take Bitget public within three years, a timeline that now doubles as a test of how well the company recovers from reputational damage. The exchange has brought in Mandiant and SlowMist to investigate the breach and trace the stolen funds across blockchains.