Bitget Reopens Withdrawals in Phases After September 24 Security Incident

Paxful
fiverr


  • Bitget resumed BTC withdrawals, with 9,585 orders and 4,098.036 BTC already processed.
  • ETH, USDT, and other assets will resume in phases through October 2 across multiple networks.

Bitget has begun the phased resumption of withdrawals following the security incident identified on September 24. The first of its kind in the eight years of operation of the exchange. BTC withdrawals on the Bitcoin and BSC networks went live at 08:00 UTC on September 28, with 9,585 orders. 4,098.036 BTC were already processed as of 17:00 UTC+8. 

The schedule for the remaining networks is as follows: ETH withdrawals across Ethereum, BSC, Arbitrum, Base, and Optimism open on September 29. USDT withdrawals on Ethereum, BSC, Solana, and Tron resume September 30. In addition, all other tokens, fiat, and P2P follow on October 2.

What Actually Happened

The full trace-back is complete. The attacker exploited vulnerabilities in a third-party security product used by Bitget to obtain high-level internal credentials. Those credentials were then used to send fraudulent withdrawal commands directly to the wallet system. This likely bypassed risk controls and triggered abnormal transfers. Private keys were not compromised. Cold wallets were not affected.

Bitget isolated the affected systems, remediated the vulnerability, revoked and reissued internal credentials, and restructured access to highly sensitive systems. The security team notified the third-party vendor and disabled the affected functionality.

coinbase

Moreover, Mandiant and SlowMist are continuing to support the independent forensic investigation and on-chain tracing efforts. Bitget has published the identified attacker addresses publicly to support broader industry collaboration and asset recovery.

The Freeze and What It Recovered

Circle blacklisted an address labelled “Bitget Exploiter 8” at 05:00 UTC on September 25, freezing 218,023 USDT and 99,990 USDC, approximately $318,000 combined. Also, Tether subsequently blacklisted the same address, as confirmed by MistTrack.

The frozen amount represents a small fraction of the total stolen assets. On the other hand, MistTrack data shows attacker-linked addresses still hold more than 63,000 ETH. Significantly, the funds that issuers cannot freeze. Bitget has requested THORChain to refuse service to the identified attacker addresses.

Every user balance is fully covered by the Bitget Protection Fund, which will be topped back up to over $300 million with the firm’s own capital within the week. The incident caused zero user impact. Security teams will complete an internal report this week and publish confirmed details shortly after.

Furthermore, Bitget is launching Project Stand Together, a package of trading-fee rewards and additional protections for retail, VIP, and professional users.

Crypto Market Highlights

China’s MSS Warns Crypto Users: Blockchain Transactions Leave a Permanent Trail





Source link

Bybit

Be the first to comment

Leave a Reply

Your email address will not be published.


*