Bitget Details $388 Million Security Incident as BTC Withdrawals Resume

Ledger
Coinmama


Bitget CEO Gracy Chen has provided further details about the security incident that affected the exchange on Sept. 24, saying the attacker exploited a vulnerability in a third-party security product to obtain high-level internal credentials.

During a public livestream on X, Chen said the attacker subsequently used those credentials to send fraudulent withdrawal commands to Bitget’s wallet system. The commands triggered abnormal transfers that bypassed existing risk controls.

“Our investigation has found that the attacker exploited a vulnerability in a third-party security product to obtain the high-level internal credentials,” Chen said. “And then the attacker used these credentials to send fraudulent withdrawal commands to the wallet system, causing it to execute abnormal transfers that bypassed risk controls.?


XRP Headlines Altcoins Ahead of Busy Macro Week, Binance’s New Listing Live with SpaceX Campaign: Main Crypto News This Morning


XRP, Gram (GRAM), Near Protocol (NEAR) and Bitcoin (BTC) Price Analysis for September 28: Outstanders Stay Relevant

Bitget said its private keys were not compromised and that its cold wallets were not affected. The exchange has identified the attack path, remediated the vulnerability and contained the incident. It said no further unauthorized transfers had been identified after containment.

Binance

What happened 

The initial unauthorized transfers began at about 18:31 UTC on Sept. 24, according to Chen. The attacker first made two relatively small transactions, transferring 0.84 ETH from an Ethereum hot wallet and 93 TRX from a Tron hot wallet. Bitget said both transactions fell below its risk-control threshold and did not trigger an alert.

Between 18:58 and 20:09 UTC, the attacker initiated 17 larger transfers involving Ethereum, XRP, Zcash, BNB Smart Chain, Base, Arbitrum, Optimism and Avalanche. Their combined estimated value was about $361 million.

Bitget’s monitoring systems detected a significant discrepancy at 19:05 UTC, seven minutes after the first large transfer. The exchange then automatically blocked user-initiated withdrawals across the platform.

Bitget activated its highest-level P0 emergency response at 19:14 UTC, while its technical team began containment measures at 19:40 UTC. At about 20:40 UTC, the wallet team began moving funds into cold storage as a precaution while it assessed whether private keys had been compromised.

The attacker then initiated another seven transfers between 20:55 and 21:23 UTC involving Avalanche, XRP, Ethereum, Zcash, Algorand, TIA and Cosmos. Bitget estimated the value of this second wave at about $30 million.

At approximately 21:44 UTC, Bitget shut down wallet withdrawal services, including its signing service, and isolated withdrawal-related inbound and outbound access.

The exchange said its security team identified the root cause within several hours and subsequently reported the incident to law enforcement in the jurisdiction where its relevant entity is based.

Bitget has confirmed that approximately $388 million in assets were transferred during the incident. The exchange said the figure reflects its latest reconciliation and classification of transactions associated with the attack.

According to Chen, the incident was the first security event of this nature to affect Bitget Exchange during its eight years of operation.

Forensic investigation continues 

Chen described the attack as a targeted operation in which the attacker used legitimate credentials and attempted to remove evidence of the activity.

“Along the way, they used legitimate credentials. They disguised their activity as routine administrative operations while removing traces of their actions,” Chen said. “This is a sophisticated targeted attack.”

According to Bitget, the attacker gained access to an internal management system through the third-party vulnerability, used the compromised credentials to insert fraudulent withdrawal commands into wallet-related backend services and subsequently deleted traces of those commands.

Chen said Bitget does not currently believe the incident was an inside job, but added that the company would not speculate about the attacker’s identity before the investigation reaches a confirmed conclusion.

Forensic firms Mandiant and SlowMist are supporting the investigation, including analysis of the attack vectors, validation of containment and remediation measures, and on-chain asset tracing.

Bitget is also working with law enforcement, other exchanges, blockchain projects, on-chain security specialists and other industry participants to trace and recover the affected assets. The exchange said some assets have already been frozen through these efforts and has published identified attacker addresses and relevant tracing data to support industry cooperation.

Bitget expects to complete its official security report this week and said additional findings will be disclosed as they are verified.

Withdrawals resume

Meanwhile, the exchange has begun a phased restoration of withdrawal services. BTC withdrawals on the Bitcoin and BSC networks resumed at 08:00 UTC on Sept. 28.

As of 09:00 UTC, Bitget said users had initiated 9,585 BTC withdrawals, totaling 4,098.03574 BTC. The exchange reported that the withdrawal service was operating normally at that time.

ETH withdrawals are scheduled to resume on Sept. 29, followed by USDT withdrawals on Sept. 30. Other supported tokens, fiat withdrawals and P2P services are scheduled to resume on Oct. 2. Availability will be shown directly on the Bitget platform.

Chen said BTC was prioritized because its withdrawal pipeline had completed the necessary security checks and the Bitcoin network itself was not affected by the incident. Other networks and assets will be restored after completing their respective security reviews.

Bitget said users will not need to take additional steps once individual services are restored. Existing minimum withdrawal amounts and 24-hour maximum limits will remain in place.

Chen also said the temporary withdrawal suspension was a security measure rather than an indication of insufficient user assets.

“The temporary pause is just a security measure. It’s not related to the sufficiency of users’ assets because the assets are fully recovered or fully covered by the Bitget Protection Fund,” she said.

Bitget said user account balances were not affected and that losses from the incident would be covered by its User Protection Fund. The fund currently exceeds $464 million, according to the exchange.

Chen said Bitget established the fund in 2022 and would use it to cover the losses before replenishing it with company capital. She said the fund would be restored to more than $300 million in USDT or equivalent assets within a week of being used.

The exchange also reported a comprehensive Proof of Reserves ratio of 127%. Bitget said the reserve ratio and User Protection Fund are separate measures, with the former representing its reported reserves relative to covered user liabilities.

Following the incident, Bitget said it has strengthened its assessment and deployment standards for third-party security products, as well as internal access controls, withdrawal verification and abnormal-activity monitoring. The company also plans to introduce stronger independent verification for withdrawals.

Alongside the withdrawal restoration, Bitget has launched two limited-time programs. The Bitget Alliance Program for eligible users runs from Sept. 28 at 08:00 UTC through Oct. 26 at 08:00 UTC and allows participants to share in transaction fees generated through eligible trading activity.

Project Stand Together targets eligible PRO clients and market makers, offering special project fee discounts and extended PRO-level protection. 

Preferential rates are scheduled to run from Sept. 28 at 10:00 UTC through Oct. 30 at 09:00 UTC, while the extended PRO-level protection will remain in place through Nov. 30 at 09:00 UTC.

Chen said Bitget would continue publishing information about the investigation, remediation measures, withdrawal restoration and asset recovery as the relevant findings are verified.

“This incident is obviously a very serious test for Bitget. We will face it directly,” Chen said. “We want to learn from it and we will not let it define us.”

She added that the exchange intends to make its response available for scrutiny by users and the wider industry, including through further disclosures about what happened and the changes implemented afterward.



Source link

Bybit

Be the first to comment

Leave a Reply

Your email address will not be published.


*