Roobet
google-news-img
spot_img

Bitget Issues Security Update as BTC Withdrawals Resume

Key Insights

  • Bitget attackers exploited vulnerabilities in third-party products to obtain internal credentials and issue fraudulent withdrawal commands, while private keys and cold wallets were not compromised.
  • Bitget says Bitcoin withdrawals are live, with 9,585 orders totaling 4,098.036 BTC processed as of 17:00 UTC+8, while other assets will return in phases.
  • The exchange says all affected funds are 100% covered by its Protection Fund and plans to restore the fund to more than $300 million within the week.

Bitget resumed Bitcoin withdrawals on Sept. 28 after identifying the attack path behind its $387.5 million security incident. The exchange said attackers compromised a third-party security product rather than its private keys or cold wallets.

CEO Gracy Chen said Bitget had processed 9,585 withdrawal orders totaling 4,098.036 BTC by 17:00 UTC+8. Other assets will return through a phased rollout extending to Oct. 2.

Bitget Hack Traced to Third-Party Security Product

Bitget’s latest priority is no longer simply stopping unauthorized transfers. It is restoring normal withdrawals while keeping controls in place.

Bitcoin is the first major asset to return. The 4,098.036 BTC processed across 9,585 orders shows that the restart was already handling substantial withdrawal demand by the time of the update.

Bitget said other cryptocurrencies will be restored in phases.

That approach follows the exchange’s decision to suspend withdrawals after unauthorized transfers were detected on September 24.

Bitget BTC Withdrawals Resume | Source: X
Bitget BTC Withdrawals Resume | Source: X

The Coin Republic previously reported that the affected amount was approximately $351.6 million, with unauthorized transfers detected from some hot wallets at 18:31 UTC. Bitget said deposits and trading remained available during the suspension.

The initial investigation did not establish the attack vector. Bitget had said it would avoid speculation while the review continued.

The latest explanation points toward compromised credentials and fraudulent internal withdrawal commands.

Protection Fund Takes the Financial Hit

The financial response is another central part of the update.

Bitget says all affected user funds are 100% covered by its Protection Fund. The exchange had previously disclosed that the fund held more than $464 million, above the estimated $351.6 million affected by the incident.

Bitget now plans to restore the Protection Fund to more than $300 million within the week.

That does not erase the security incident. It does, however, define how the exchange says it will absorb the reported losses without passing them to affected users.

Bitget has also emphasized that cold wallets were not compromised. The earlier incident was tied to hot and warm wallet infrastructure, while the exchange said its cold-wallet holdings remained secure.

For customers, the operational test is straightforward: withdrawals must continue to function while the investigation and remediation work proceed.

The Crypto Exploit Problem Is Bigger Than One Exchange

The Bitget incident lands during a period of heightened scrutiny around crypto exploits.

The distinction between an exchange breach and other forms of crypto abuse has become increasingly important.

Some attacks target wallets or infrastructure directly. Others exploit smart-contract logic, front-end systems or token-launch mechanisms.

Bitget’s case centers on unauthorized withdrawal commands after attackers obtained internal credentials, according to the exchange.

It is therefore different from the growing number of crypto scams built around token launches and user deception.

A recent Robinhood Chain case illustrates that contrast.

The Coin Republic reported that pseudonymous on-chain analyst Wazz linked at least $18.43 million in extractions to 53 memecoin launches on Robinhood Chain between July 10 and September 21.

The report independently confirmed the mechanics behind 10 of the launches and one of the fund flows used to connect them, but did not independently reproduce the $18.43 million total.

Those alleged extractions involved launch activity rather than a centralized exchange security breach.

The common thread is control. In one case, compromised credentials allegedly enabled unauthorized withdrawals.

In another, connected wallets allegedly accumulated large amounts of newly launched tokens before public trading.

Neither should be treated as the same type of crypto exploit.

Bitcoin Withdrawals Offer the First Real Test

For Bitget, the restart of BTC withdrawals is the most tangible sign that the platform is moving beyond the initial containment stage.

The numbers provide an early operational benchmark. More than 4,000 BTC had already been processed across thousands of orders by 17:00 UTC+8, according to Chen’s update.

The exchange has not said that the broader incident investigation is finished. Instead, the phased reopening suggests that different assets and systems are being brought back under restored controls.

That makes the next stage less about the size of the original breach and more about execution.

Bitget must now demonstrate that withdrawal infrastructure can operate normally after the credential compromise. It must also rebuild the Protection Fund to the level it has targeted.

For the wider market, the episode is another reminder that crypto security risks do not begin and end with private keys.

Exchanges can retain control of their cold wallets and still face losses when operational systems, credentials or transaction authorization processes are compromised.

This article is for informational purposes only. Investigation findings and loss estimates may evolve as forensic analysis and asset recovery continue.

Disclaimer

The contents of this page are intended for general informational purposes and do not constitute financial, investment, or any other form of advice. Investing in or trading crypto assets carries the risk of financial loss. The forecasted data (also called “price prediction”) on this page are subject to change without notice and are not guaranteed to be accurate.

Our Newsletter

Subscribe to our newsletter to get the latest news and promotions.

Arnold Kirimi
Arnold Kirimi
Arnold Kirimi is a crypto and Web3 journalist from Nairobi, Kenya. With a sharp eye for emerging trends and a talent for demystifying blockchain jargon, Kirimi turns complex concepts into compelling narratives. Featured in top outlets like Cointelegraph, DailyCoin and CryptoSlate.