Bitget Reopens Withdrawals After $388 Million Crypto Hack
Four days after suspending its withdrawals, Bitget starts allowing bitcoins to go out again. Meanwhile, the exchange had to endure a $388 million theft. No private key was broken, no cold wallet emptied: the attacker accessed a security product provided by an external company. Two small transfers first allowed testing the defenses. Then the large movements followed. Today, clients can recover their funds. But the story is far from over.

In Brief
- Bitget gradually reopens withdrawals four days after an attack causing nearly $388 million loss.
- The attacker allegedly exploited a zero-day flaw in a third-party provider to gain internal access and bypass controls.
- Two small transactions served as tests before seventeen massive transfers across eight different blockchain networks.
- Stolen funds passed notably through THORChain, which refuses to block addresses despite public Bitget requests.
- The Protection Fund exceeds $464 million while Bitget promises to fully preserve users’ balances.
The breach wasn’t in Bitget’s code
On September 24, at 6:31 PM UTC, two transactions go almost unnoticed. 0.184 ETH on one side, 193 TRX on the other. Nothing that looks like a $388 million heist. That’s exactly the point.
These two movements remained below Bitget’s risk control thresholds. No alerts were triggered. About thirty minutes later, the attacker moved on. Seventeen transactions were sent across eight networks, including Ethereum, XRP Ledger, Zcash, BNB Chain, Base, Arbitrum, Optimism, and Avalanche. About $361 million then transferred to addresses controlled by the attacker.
The reconciliation system eventually detected an anomaly. Seven minutes after the first big transfer, Bitget began blocking withdrawals.
The most surprising thing lies elsewhere. Private keys were not compromised and cold wallets were untouched. The attacker supposedly exploited a zero-day vulnerability in a third-party security product to gain high-level internal credentials. With these accesses, they could inject withdrawal orders into the wallets backend. The system treated them as legitimate requests.
In other words, no safe was forced. Someone found a way to talk to the guard.
The investigation established that the attacker exploited a vulnerability in a third-party security product to obtain high-level internal credentials. Private keys were not compromised and cold wallets were untouched. — Bitget, September 28, 2026
30 minutes, eight blockchains, $361 million
The 0.184 ETH and 193 TRX take on a different meaning when looking at the full timeline. They were probably not funds meant to be stolen. They serve to see if anyone is watching.
The attacker then waited about thirty minutes before launching main operations. Between 6:58 PM and 8:09 PM UTC, seventeen transactions were executed across multiple blockchains. The amount originally estimated at $351.6 million was later raised to about $388 million after analyzing movements on Zcash and Tron.
Bitget quickly realized something was happening. But the internal access used to trigger withdrawals also allowed the attacker to delete some traces of their commands. This obviously complicated the investigation teams’ efforts to reconstruct the events.
Gracy Chen, Bitget’s CEO, acknowledged it in an interview with The Block: “It’s also, in my opinion, the most delicate part“.
Mandiant and SlowMist are now involved in the investigation. Bitget says it has identified the vulnerability, fixed the issue, and strengthened its controls. The North Korean theory is also being examined but remains a hypothesis until the full report is published.
The difference with many recent crypto hacks is therefore quite clear. This time, the problem did not come directly from the mechanism protecting the assets. It came from the accesses that allow moving them.
THORChain refuses to block the funds after Bitget delisted RUNE
Once out of Bitget, the assets obviously did not remain still. Investigators followed some of the movements across different networks. Some sums notably passed through THORChain before being converted to Bitcoin.
Bitget publicly asked the protocol to stop processing addresses linked to the theft. Gracy Chen made the request directly on X, with a phrase that did not leave users indifferent:
Decentralization is a design principle, not a shield to facilitate clearly stolen funds. The industry is watching.
Gracy Chen, X, September 26, 2026
The problem is that THORChain is not designed to act like a bank that blocks an account on demand. Users immediately reminded this in replies to Bitget’s CEO. Some even mentioned an embarrassing episode for the exchange: Bitget had delisted RUNE from its platform a few days earlier.
The scene is quite revealing of the crypto world. Bitget wants to recover funds whose movements are publicly visible. THORChain defends its permissionless operation. The two parties can therefore see exactly the same transactions and reach very different conclusions about what should be done.
Meanwhile, the funds keep moving.
$464 million to cover $388 million: a $76 million cushion
Bitget at least had a card to play: its User Protection Fund. The fund exceeded $464 million at the time of the attack. It is thus large enough to absorb the roughly $388 million missing without asking customers to cover the difference.
The platform also states that user balances were not affected. It has also begun to gradually reopen withdrawals. Bitcoin was back on September 28 at 8 AM UTC on Bitcoin and BSC. Ethereum is scheduled for September 29, followed by other assets and services in the coming days.
The restart was fast. At 9 AM UTC, Bitget indicated it had already processed 9,585 withdrawals representing about 4,098 BTC.
But the $464 million figure also shows the fragility of the setup. There is still a difference between having a protection fund and preventing a new incident. The first absorbs the shock. The second requires understanding how the attacker obtained their access.
Bitget plans to publish its security report this week. The exchange has also launched a recovery program: 5% of frozen funds and 5% of recovered sums can be paid as bounties to people or organizations whose intervention directly enabled recovery.
The biggest work thus starts now. It is no longer just counting what was stolen, but understanding why the system allowed the first transaction.
Key Figures
- $388 million disappeared during the September 24 attack.
- $464 million was available in the User Protection Fund.
- 9,585 Bitcoin withdrawals were processed during the first hour.
- 17 major transactions were executed across eight different networks.
- 4,098 BTC were withdrawn after the gradual reopening of withdrawals.
The Bitget case adds to an already particularly heavy year for crypto security. Ethereum accounts for 53% of losses recorded in 2026, while Solana also ranks among the prime targets for attackers. The attack mainly reminds us of one thing: protecting keys is no longer enough. In a crypto exchange, accesses, providers, and intermediate systems are now part of the defense perimeter.
Maximize your Cointribune experience with our "Read to Earn" program! For every article you read, earn points and access exclusive rewards. Sign up now and start earning benefits.
La révolution blockchain et crypto est en marche ! Et le jour où les impacts se feront ressentir sur l’économie la plus vulnérable de ce Monde, contre toute espérance, je dirai que j’y étais pour quelque chose
The views, thoughts, and opinions expressed in this article belong solely to the author, and should not be taken as investment advice. Do your own research before taking any investment decisions.