Bitget CEO Gracy Chen stated that an attacker used two small test transfers to evade the exchange's risk controls prior to executing a massive theft. The initial unauthorized transactions, consisting of 0.184 ETH and 193 TRX, occurred at 6:31 p.m. UTC on September 24 and fell below Bitget's undisclosed alert threshold. Approximately 30 minutes later, the attacker initiated larger withdrawals totaling about $361 million across multiple blockchains, with the final revised loss reaching $387.5 million.

The breach exploited a zero-day vulnerability in a third-party security product, allowing fraudulent commands to be inserted directly into wallet backend systems. While Bitget’s reconciliation system detected a significant discrepancy seven minutes after the first large transfer and blocked further withdrawals, it could not reverse the completed transactions. The exchange reported that hot and warm wallets were compromised, but cold storage remained secure. Bitget has since resumed withdrawals, prioritizing Bitcoin, and plans to replenish its user protection fund from corporate reserves.