Cryptocurrency

Bitget Begins Phased Withdrawals After $388 Million Exploit

0

SINGAPORE — Cryptocurrency exchange Bitget has started a phased withdrawal restart following the September 24 security incident that resulted in roughly $387.5 million in assets being transferred to attacker controlled addresses. The exchange says the vulnerability has been identified and remediated, while its User Protection Fund will cover the financial impact of the incident.

Bitcoin withdrawals resumed on September 28 at 08:00 UTC, with Ethereum scheduled to follow on September 29. USDT withdrawals are planned for September 30, while remaining supported assets, fiat withdrawals and peer to peer services are scheduled to return on October 2.

How the Bitget exploit unfolded

Bitget initially estimated that approximately $351.6 million had been transferred during the incident. The exchange later revised the figure to $387.5 million after identifying additional transfers involving assets on the Zcash and TRON networks. Bitget said the higher figure represents a more complete accounting of the original incident rather than a second attack.

The affected assets included XRP, Ether, USDT, USDC, Zcash, TRON, BNB, Avalanche and Tether Gold. The unauthorized transfers were detected on September 24, after which Bitget suspended withdrawals while its security teams investigated the activity.

The exchange has said that customer account balances were not affected and that its cold wallets remained secure. Its separately operated self custody Bitget Wallet product was also reported as unaffected.

The attack targeted transaction infrastructure

Early analysis indicates that the incident was not a straightforward theft of private keys.

According to an independent analysis from blockchain security firm GoPlus Security, attackers appear to have compromised part of Bitget’s wallet backend and manipulated transaction instructions before they reached the signing process. The analysis suggests that the attackers were able to make unauthorized transactions appear legitimate to the system responsible for approving and signing transfers.

The analysis is based on Bitget’s public statements and onchain transaction data rather than a final Bitget postmortem, so the precise initial entry point remains under investigation.

The distinction is important for the wider crypto industry. Modern exchanges rely on multiple layers of automated controls between a customer withdrawal request and the final blockchain transaction. A compromise of those intermediate systems can potentially create a path to large asset movements without directly stealing the underlying private keys.

Stolen XRP adds another recovery challenge

XRP represented a significant portion of the assets involved in the incident. CoinDesk reported that approximately $83 million worth of stolen XRP had subsequently been moved from several wallets associated with the attack. Around $75 million remained in wallets that cannot be directly frozen under the XRP Ledger’s rules.

This highlights an important distinction between native blockchain assets and issuer controlled tokens.

Ripple does not have a built in mechanism to freeze native XRP held by an attacker. By contrast, stablecoin issuers such as Circle and Tether have controls that allow them to freeze certain issuer issued tokens. CoinDesk reported that approximately $320,000 in USDC and USDT linked to the incident had been frozen.

As stolen assets move between wallets and blockchain networks, recovery can therefore depend on cooperation from exchanges, token issuers and other infrastructure providers.

Bitget prepares for a phased return

Bitget has said the vulnerability behind the incident has been fixed and that no further unauthorized transfers are possible. The exchange has also brought in independent cybersecurity firms Mandiant and SlowMist to assist with the investigation and additional security checks.

The phased withdrawal schedule is designed to allow the exchange to validate each network and withdrawal route before restoring access. Bitget said trading and deposits remain operational during the process.

The exchange also maintains a User Protection Fund containing 5,500 BTC, which it says will fully cover the financial impact of the breach.

The incident nevertheless puts renewed attention on the security architecture behind centralized crypto exchanges. Protecting private keys remains important, but the Bitget case shows that transaction approval systems, backend infrastructure and automated authorization controls can also become critical points of failure.

As Bitget works toward restoring all withdrawal services, the ongoing investigation is expected to provide more information about how the attackers gained access and how the exchange’s transaction controls were bypassed.

Nvidia Launches Open Agent Safety Platform to Secure Autonomous AI Systems

Previous article

You may also like

Comments

Comments are closed.