Bitget has reopened Bitcoin and BSC withdrawals as of September 28, following a suspension triggered by a $388 million crypto theft. The incident originated from a zero-day vulnerability in a third-party security product, which allowed the attacker to obtain high-level internal credentials and inject legitimate-looking withdrawal orders. Private keys and cold wallets remained untouched, distinguishing this breach from direct asset storage compromises.
The attack began with two small test transactions (0.184 ETH and 193 TRX) that bypassed risk controls, followed by seventeen large transfers across eight networks, including Ethereum and Zcash. Bitget’s User Protection Fund, valued at over $464 million at the time of the attack, absorbed the loss without impacting user balances. Investigations involving Mandiant and SlowMist are ongoing, while CEO Gracy Chen publicly requested THORChain halt processing of stolen funds, highlighting tensions between centralized recovery efforts and decentralized protocol principles.
This incident underscores a critical shift in exchange security risks, moving beyond traditional key management failures to vulnerabilities within the operational infrastructure and third-party dependencies. By exploiting a security product rather than the wallet architecture itself, the attacker demonstrated how supply chain weaknesses can compromise even well-segregated cold storage systems. The rapid detection and blocking of withdrawals suggest robust real-time monitoring capabilities, yet the initial bypass of risk thresholds via small transactions reveals gaps in anomaly detection logic for low-value activities.
From a market structure perspective, the reliance on a substantial User Protection Fund mitigated immediate customer panic, but it does not resolve the underlying systemic fragility. The public dispute with THORChain illustrates the friction between centralized entities seeking restitution and decentralized protocols adhering to permissionless design principles. As exchanges increasingly integrate complex third-party tools, the definition of the defense perimeter must expand to include vendor software integrity, making comprehensive security audits of external providers a non-negotiable standard for institutional adoption.


