Bitget has begun restoring cryptocurrency withdrawals following a security incident on September 24 that resulted in the theft of approximately $388 million. The exchange clarified that attackers exploited a vulnerability in a third-party security product to obtain high-level internal credentials, allowing them to issue fraudulent withdrawal commands across multiple blockchain networks including Ethereum, XRP Ledger, and Tron. By Monday morning, Bitget had processed 9,585 bitcoin withdrawals totaling 4,098 BTC, with plans to resume other asset withdrawals throughout the week.
The company emphasized that its private keys and cold wallets were never compromised, and customer balances remain intact, supported by a User Protection Fund exceeding $464 million and a comprehensive reserve ratio of 127%. Forensic specialists Mandiant and Slowmist are assisting with the investigation, while some affected assets have been frozen through industry coordination. CEO Gracy Chen noted that the attack methodology appeared consistent with North Korean-linked groups, though the official security report is expected later this week.
This incident highlights a critical shift in the threat landscape for centralized exchanges, where breaches no longer require compromising cryptographic foundations like private keys or cold storage. Instead, attackers are targeting the operational infrastructure and trusted access layers that authorize transactions. The exploitation of a third-party security product demonstrates how supply chain vulnerabilities can bypass traditional perimeter defenses, rendering even robust key management systems ineffective if the authorization logic itself is manipulated. For institutional observers, this underscores the fragility of relying on external vendors for core security functions without rigorous, independent verification of their integration points.
From a market structure perspective, Bitget’s rapid restoration of withdrawals and reliance on its User Protection Fund serves as a stress test for exchange resilience protocols. While the immediate liquidity crunch was mitigated by processing thousands of BTC withdrawals quickly, the broader implication is the need for stricter controls over internal credential issuance and abnormal activity detection. The involvement of forensic firms and the freezing of assets indicate a coordinated industry response, yet the recurrence of such sophisticated attacks suggests that compliance frameworks must evolve beyond static audits to include dynamic monitoring of third-party dependencies. Stakeholders should watch for the final security report to determine if regulatory scrutiny will intensify regarding vendor risk management standards.

