Bitget has reopened Bitcoin and BSC withdrawals as of September 28, following a suspension triggered by a $388 million crypto theft. The incident originated from a zero-day vulnerability in a third-party security product, which allowed the attacker to obtain high-level internal credentials and inject legitimate-looking withdrawal orders. Private keys and cold wallets remained untouched, distinguishing this breach from direct asset storage compromises.

The attack began with two small test transactions (0.184 ETH and 193 TRX) that bypassed risk controls, followed by seventeen large transfers across eight networks, including Ethereum and Zcash. Bitget’s User Protection Fund, valued at over $464 million at the time of the attack, absorbed the loss without impacting user balances. Investigations involving Mandiant and SlowMist are ongoing, while CEO Gracy Chen publicly requested THORChain halt processing of stolen funds, highlighting tensions between centralized recovery efforts and decentralized protocol principles.