Bitget restored Bitcoin withdrawal functionality on September 28 following a security breach that resulted in unauthorized transfers totaling approximately $387.5 million. CEO Gracy Chen reported that the exchange processed 9,585 withdrawal orders for 4,098.036 BTC by 17:00 UTC+8. The investigation determined that attackers compromised a third-party security product rather than accessing private keys or cold wallets. Other assets are scheduled to return through a phased rollout extending to October 2.
The incident originated from fraudulent internal withdrawal commands enabled by compromised credentials, distinct from direct wallet breaches. Bitget stated that all affected user funds were covered by its Protection Fund, which previously held more than $464 million. The exchange plans to restore the fund to over $300 million within the week. Deposits and trading remained available during the suspension period that began on September 24.
This development highlights a critical vulnerability in centralized exchange infrastructure where operational security failures can bypass traditional key management safeguards. By attributing the breach to a compromised third-party security product and fraudulent internal commands, Bitget underscores that cold wallet isolation is insufficient if transaction authorization processes are weak. The rapid resumption of withdrawals serves as an immediate test of the platform's ability to maintain control while restoring normal operations, signaling to users that containment measures have stabilized the specific vector exploited by attackers.
From a market structure perspective, this incident reinforces the growing distinction between technical exploits targeting infrastructure and social engineering attacks on token launches. While the financial impact was absorbed by the Protection Fund, the event may prompt institutional clients to scrutinize vendor risk management and internal credential controls more rigorously. Observers should watch whether the phased restoration of other assets proceeds without further incidents, as any recurrence would challenge the credibility of the remediation efforts and potentially trigger broader regulatory attention regarding exchange custody protocols.


