Bitget has updated its initial loss estimate from the September 24 security incident to $387.5 million in affected assets. The revision reflects a more complete reconciliation of transactions linked to the attack, specifically including crypto assets on Zcash and TRON that were omitted from the first report. The increase of $35.9 million does not indicate additional theft but rather a broader accounting of funds transferred to attacker-controlled addresses during the breach.
The exchange confirmed that user balances remained unaffected and cold wallet private keys were not compromised. The attack targeted withdrawal systems by exploiting a vulnerability in a third-party security product to obtain high-level internal credentials, which bypassed risk controls. Bitget is working with Mandiant and SlowMist for forensic analysis and has launched a recovery bounty program. Withdrawal services are being restored sequentially, with BTC reopening on September 28, ETH on September 29, and USDT on September 30, ahead of further token and fiat service restorations planned for October 2.
The upward revision of the loss figure highlights the complexity of post-incident reconciliation across multiple blockchain networks. By including assets on privacy-focused chains like Zcash and high-throughput networks like TRON, Bitget provides a more accurate scope of the financial impact. This transparency is critical for maintaining trust, as it distinguishes between new losses and previously unaccounted transfers. The incident underscores the risks associated with third-party security integrations, where vulnerabilities in external products can compromise internal credential management and bypass traditional risk controls.


