Bitget said attackers stole about $388 million from its wallet environment on Sept. 25 after exploiting a previously unknown flaw in a third-party security product, using compromised internal credentials to issue unauthorized withdrawal instructions. The exchange said private keys were not exposed and its cold wallets were not breached, placing the incident among the largest reported exchange security failures of 2026 despite the containment of its offline reserves.
The attack targeted the systems surrounding wallet operations rather than the cryptographic keys controlling the exchange’s main cold-storage holdings. According to Bitget’s incident account, the compromised third-party product node gave the attackers access to internal network credentials. Those credentials were then used to forge withdrawal commands that bypassed normal risk checks and sent assets out through several blockchain networks.
Bitget said Mandiant and blockchain-security firm SlowMist joined the forensic investigation and fund-tracing effort. The exchange also said it disabled the affected third-party function, reissued internal credentials, revoked and restructured high-sensitivity permissions, and introduced separate validation checks for withdrawals.
Large transfers began shortly before the shutdown
On-chain activity showed small transfers beginning around 02:31 Beijing time, followed by 17 larger transactions between 02:58 and 04:09, according to the timeline released by Bitget. The funds moved across Ethereum, XRP, Zcash, BNB Chain, Base, Arbitrum, Optimism and Avalanche.
The exchange said its reconciliation system detected a significant mismatch at 03:05, roughly seven minutes after the first large transfer. It then imposed a platform-wide block on withdrawals. By 03:14, Bitget said it had raised its response to the highest emergency level, transferred assets toward cold storage, and suspended wallet withdrawal and signing services.
That response sequence offers a narrow but consequential measure of the attack’s operational window. The exchange halted withdrawals shortly after the larger transfers began, yet the attacker had already pushed funds through multiple networks, complicating recovery efforts. Bitget executive Chen said some traces were deleted after the transactions were executed.
Cross-chain dispersal can make stolen assets harder to immobilize quickly because each network may require separate monitoring, cooperation from stablecoin issuers, or action by service providers receiving the funds. Bitget named Binance’s security team, MEXC, Circle, Tether, Mandiant and SlowMist among entities involved in intelligence sharing, tracing, and potential freezing efforts.
Only about $1.1 million of the approximately $388 million stolen had been frozen, according to the information provided on the incident. That leaves the recovery of most of the stolen assets uncertain.
Protection fund covered the reported loss
Bitget said it used its user protection fund to cover the losses. The reserve was established in 2022 with a stated long-term baseline of $300 million. At the time of the breach, Bitget said the fund held 5,500 BTC worth more than $464 million, exceeding the reported amount lost in the attack.
Blockchain analyst Ai Yi tracked an initial movement of 2,042.28 BTC from an address linked to the protection fund to a Bitget hot wallet before Bitcoin withdrawals reopened. The transaction provided an on-chain indication that the exchange was mobilizing reserve assets to support resumed operations.
Chen said Bitget would restore the protection fund to at least $300 million within a week. The exchange said that target was met on Sept. 30, the same day it released its 47th proof-of-reserves report.
The report listed an aggregate reserve ratio of 131% across 19 asset categories, with BTC reserves at 142%, ETH at 110%, USDT at 107%, and USDC at 154%. Proof-of-reserves reports can show wallet balances against reported customer liabilities, although their usefulness depends on the completeness of the liabilities disclosed and the timing of the snapshot.
Withdrawals resumed in phases
Bitget reopened withdrawals on a staged timetable, beginning with Bitcoin at 16:00 on Sept. 28. Ethereum withdrawals resumed on Sept. 29, followed by USDT on Sept. 30. The exchange scheduled other tokens, fiat services and C2C functions for Oct. 2, later stating that withdrawals for all assets had returned to normal status.
The reopening placed immediate pressure on Bitget’s liquidity management, since users could test the exchange’s ability to process withdrawals after several days of halted access. The exchange said ETH wallet flows turned positive within about 30 minutes of Ethereum withdrawals resuming, with hot-wallet balances rising above 30,000 ETH.
Bitget reported 9,674 ETH in deposits and 9,023 ETH in withdrawals during the first hour of resumed ETH transfers, leaving a net inflow of about 651 ETH. It also said total platform inflows reached $231 million in the first 24 hours after withdrawals were restored, compared with an average daily inflow of $245 million in August.
Those figures come from Bitget and cannot independently establish customer confidence or the exchange’s overall liquidity position. The company also rolled out deposit and trading incentive programs after services resumed, including campaigns offering rewards tied to ETH, BTC and stablecoin deposits. Such promotions can affect short-term inflow data by rewarding users for moving assets onto the platform.
Third-party access becomes the central security issue
The reported entry point adds to scrutiny of third-party software and service providers with access to exchange infrastructure. A vulnerability in a connected security product can create a path into systems that manage permissions, transaction approvals and operational credentials, even without exposing the private keys held in cold storage.
Bitget said the attackers had maintained access inside internal nodes from Aug. 31 before executing the theft weeks later. If confirmed through the ongoing investigation, that timeline would indicate a patient intrusion focused on operational control systems rather than a rapid exploit-and-withdrawal attack.
The incident also follows February 2025’s approximately $1.4 billion Bybit breach. Bitget transferred 40,000 ETH to Bybit about five hours after that earlier attack, according to the supplied account, and Bybit later repaid the amount. Bybit said it would use its LazarusBounty system to assist in tracing funds linked to the Bitget theft.
For exchanges, the immediate lesson is less about reserve size than the controls surrounding the systems that can instruct wallets to move funds. Segmented permissions, independent transaction validation, continuous credential monitoring, and strict limits on third-party access determine whether an intrusion can reach the point where unauthorized withdrawals are approved.
Worried about exchange hacks? Learn essential protection steps in how to protect your crypto account today.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
