Bitget has updated the financial impact of its recent security incident, raising the estimated loss from an initial $351.6 million to approximately $387.5 million. This revision follows additional on-chain tracing that identified affected transactions involving Zcash and TRON networks. The exchange clarified that the higher figure reflects a more complete accounting of transfers during the original attack rather than new unauthorized movements.
Forensic investigations conducted by Mandiant and blockchain security firm SlowMist revealed that attackers likely exploited a vulnerability in a third-party security product to obtain high-level internal credentials. These credentials were used to send fraudulent withdrawal commands, bypassing existing controls. Bitget stated that private keys remained uncompromised and cold wallets were unaffected. The company has since revoked credentials, restructured access, and begun restoring withdrawals in phases, while maintaining that customer balances are protected by its User Protection Fund.
The upward revision of the loss amount underscores the complexity of tracing assets across multiple blockchain networks, including Ethereum, XRP Ledger, Zcash, and TRON. By engaging independent firms like Mandiant and SlowMist, Bitget aims to provide a transparent account of how the breach occurred, specifically highlighting the role of third-party security vulnerabilities rather than direct key theft. This distinction is critical for understanding the operational risks inherent in centralized exchange infrastructure, where trusted software components can become vectors for compromise if not rigorously audited.
From a market structure perspective, this incident intensifies scrutiny on the supply chain security of cryptocurrency platforms. The reliance on third-party tools for internal credential management introduces systemic risks that traditional perimeter defenses may miss. While Bitget’s use of its User Protection Fund mitigates immediate user harm, the event serves as a cautionary tale for institutional adoption, emphasizing the need for robust anomaly detection and stricter controls over privileged access within hot and warm wallet systems.


