// 1 ZERO-DAY · 6 CVE · 4 EXPLOIT IN THE LAST 24H→
Bitget resumed Bitcoin withdrawals on September 28, 2026, four days after unauthorized transfers hit its hot and warm wallets for roughly $387.5 million. The breach exploited a vulnerability in a third-party security product to obtain high-level internal credentials, bypassing risk controls without compromising private keys or cold storage.

Bitget resumed Bitcoin withdrawals on September 28, 2026, four days after unauthorized transfers hit its hot and warm wallets for roughly $387.5 million. The breach, detected on September 24 at 18:31 UTC according to CryptoDaily, exposed a critical flaw in the industry's custodial security model: the attack path did not run through compromised keys or breached cold storage, but through the very product meant to protect the infrastructure. The incident raises questions about how centralized exchanges manage supply-chain risks in the intermediate layers between operational liquidity and asset protection.

Key Takeaways
  • Bitget detected unauthorized transfers on September 24, 2026 at 18:31 UTC; cold wallets were not compromised and user balances remained intact.
  • The attacker exploited a vulnerability in a third-party security product to obtain high-level internal credentials, bypassing risk controls.
  • The loss estimate was revised from $351.6 million to roughly $387.5 million after reclassification of additional Zcash and TRON transactions.
  • Bitcoin withdrawals resumed on September 28 at 08:00 UTC, with 9,585 operations totaling roughly 4,098 BTC processed within an hour according to Bitcoin.com News.

The Attack Path: When the Security Product Becomes the Vulnerability

According to the cited order, the investigation identified the compromise's origin in a vulnerability within a third-party security product. This flaw allowed the attacker to obtain high-level internal credentials, which were then used to send fraudulent withdrawal commands that bypassed existing risk controls. Private key compromise was explicitly ruled out by the inquiry.

The distinction is both technical and substantive. Cold wallets, offline storage designed to isolate funds from the network, were untouched. The attack struck the intermediate layers: hot and warm wallets, where exchanges keep operational liquidity to process withdrawals and deposits in real time. This architecture is functionally necessary for a centralized exchange (CEX), but it creates an attack surface that does not depend solely on the cryptographic robustness of keys.

The brief does not specify the name of the vulnerable third-party security product, nor does it provide technical details on the nature of the flaw. No CVE identifier has been declared in the available sources. Mandiant and SlowMist are supporting the forensic investigation and fund tracing, but as of the sources they had not released independent accessible reports.

The Restoration Timeline and First-Day Numbers

The restoration calendar published by Bitget followed a phased sequence: Bitcoin on September 28, Ethereum slated for September 29, USDT for September 30, other tokens and fiat/P2P services for October 2. By 09:00 UTC on September 28, the platform had processed 9,585 Bitcoin withdrawals totaling roughly 4,098 BTC, according to data provided to Bitcoin.com News. The source does not specify the dollar value of these withdrawals at the prevailing exchange rate.

The damage estimate rose from $351.6 million at detection to roughly $387.5 million, a revision driven by the reclassification of Zcash and TRON transactions initially omitted from early tallies. CryptoRank.io confirmed this figure, simultaneously reporting the identification of 2,377 attacker addresses via a tracker published by the platform.

Bitget's Protection Fund, valued at over $464 million at the time of the incident, is expected to cover the declared losses. Bitget has also launched a bounty program for fund recovery, noting that some assets have already been frozen without quantifying the amount.

"The September 24 incident is the first time in eight years that an attack of this nature has breached Bitget Exchange's infrastructure"

THORChain and the Limits of Selective Freezing

A distinctive element emerges from the CryptoBreaking source, the only one in the corpus to report details on this aspect. CEO Gracy Chen asked THORChain to deny service to addresses linked to the attacker. THORChain's response, quoted verbatim, was that "the mechanism is not a selective freeze of specific funds or an individual swap." The protocol implemented a general network halt, not a selective one.

The CryptoBreaking source also reports that the attacker allegedly used THORChain as a laundering channel, citing Lookonchain and Arkham data. No other source in the dossier independently confirms this specific path. The same source 2 operates under an affiliate marketing disclaimer and maintains a commercial relationship with Bitget, as documented by the platform's partner program. These limitations must be kept in mind when evaluating the claim.

The contrast highlights a structural tension in the sector. Centralized exchanges can halt withdrawals, identify addresses, and cooperate with investigations. DeFi protocols like THORChain, designed for censorship resistance, offer limited halt mechanisms by design. The attacker apparently exploited this operational asymmetry.

What to Do Now

Bitget users with Bitcoin withdrawals pending since September 24 should verify that their requests were processed by September 28 at 09:00 UTC, when the platform completed the first cycle of 9,585 operations. Those holding ETH, USDT, or other tokens must wait for the respective restoration windows on September 29, September 30, and October 2, without attempting repeated transactions that could overload systems.

Security operators at other exchanges should verify whether they use the same third-party security product identified in the Bitget flaw, even though the name has not been made public. The demand for independent audits on the risk controls that precede withdrawal execution is the most concrete measure derivable from this case.

For fund tracing, the tracker of 2,377 addresses published by Bitget provides an operational reference. Companies running nodes or compliance services can integrate these addresses into their monitoring systems, with the awareness that attacker attribution remains independently unverified.

Bitget's bounty program for fund recovery is active; anyone with relevant information can report it through the platform's official channels. The Protection Fund of over $464 million is the declared guarantee for loss coverage, but the dossier does not document automatic reimbursement procedures or timelines for potential claims.

The North Korea Hypothesis and the Limits of Attribution

CEO Gracy Chen suggested the methodology is "highly consistent with North Korean-linked groups," according to the quote reported by Bitcoin.com News. The dossier does not, however, contain independent investigative confirmations on this threat profile. Sources citing North Korean activity in the general threat landscape (Infosecurity Magazine on WaterPlum) do not establish direct links to the Bitget incident.

At present, attribution remains a hypothesis declared by the interested party, not a consolidated investigative fact. The attacker's identity, precise motive, and operational geography do not emerge with certainty from the available sources. This limit is relevant for risk assessment: without verified attribution, the community cannot correlate the attack with known infrastructure, prior compromise indicators, or documented operational models.

Why It Matters

The Bitget case ranks in 2026 as the sector's second billion-dollar breach after Bybit. For centralized exchange users, it represents a test of declared solvency and operational capacity to manage liquidity crises without contagion to balances. For companies relying on third-party security products, it highlights the supply-chain risk in which the protection tool itself becomes the compromise vector.

The event does not resolve the trade-off between operational speed and custodial protection: hot wallets are necessary for service, cold wallets are protective but illiquid, and the intermediate layers remain the most complex surface to defend. The dossier offers no indications on how Bitget or the sector intend to reduce this specific exposure.

Information is based on the cited source and current as of publication.

Sources


Sources and references
  1. infosecurity-magazine.com
  2. cryptobreaking.com
  3. news.bitcoin.com
  4. cryptorank.io
  5. openpr.com
  6. cryptodaily.co.uk
  7. bitget.com
  8. partner.bitget.com
  9. coinstats.app