Bitget has resumed Bitcoin withdrawals on the mainnet and BNB Smart Chain following a $387.5 million security breach. CEO Gracy Chen disclosed that attackers exploited vulnerabilities in third-party products to steal internal credentials, allowing them to issue fraudulent withdrawal commands that bypassed risk controls. As of Monday at 17:00 UTC+8, the exchange processed 9,585 orders totaling 4,098.036 BTC. Ether, USDT, and other assets are scheduled to return in phases through October 2.
The incident began on September 24 when unauthorized transfers were detected, initially estimated at $351.6 million before rising to $387.5 million after identifying additional Zcash and TRON movements. Chen stated that private keys and cold wallets remained secure. Bitget isolated affected systems, revoked credentials, and notified the involved vendor. Mandiant and SlowMist continue forensic investigations. The exchange’s Protection Fund, which held over $464 million at disclosure, will be replenished with company capital to exceed $300 million within a week, ensuring user balances remain unaffected.
The restoration of withdrawals signals operational recovery but highlights critical dependencies on third-party infrastructure within centralized exchanges. By attributing the breach to external product vulnerabilities rather than core key management failures, Bitget attempts to delineate the attack surface while maintaining confidence in its primary custody architecture. This distinction is vital for institutional clients who assess counterparty risk based on both technical resilience and supply chain security protocols.
From an Institutional Adoption perspective, the rapid deployment of the Protection Fund and transparent communication regarding credential revocation demonstrate a mature crisis response framework. However, the reliance on external vendors for access control introduces systemic risks that may prompt regulators and partners to demand stricter isolation of sensitive infrastructure. Stakeholders should monitor the final forensic reports from Mandiant and SlowMist to understand the full scope of the third-party compromise and any potential lingering vulnerabilities in the broader ecosystem.

