Bitget Attacker Tested Systems with Small Transfers Before $388M Theft

Bitget Attacker Tested Systems with Small Transfers Before $388M Theft

Exchange suffers major breach after security probe

Crypto exchange Bitget lost approximately $388 million in a cyberattack that began on September 24. The attacker first sent small test transactions to check the system's defenses before draining funds from hot wallets.

CEO Gracy Chen stated that the exchange's user protection fund will cover the entire loss. The fund is expected to be restored to at least $300 million within a week using corporate reserves.

How the breach unfolded

  • The attack started with two small transfers: 0.184 Ethereum and 193 Tron, both below the alert threshold.
  • Thirty minutes later, the attacker executed 17 larger transactions across multiple blockchains totaling $361 million.
  • Bitget's internal system detected the discrepancy within seven minutes and blocked all user withdrawals.
  • The total stolen amount was reported as $388 million.

Details from CEO Gracy Chen

In an interview, Chen explained that the attacker exploited a zero-day vulnerability in a third-party security product. This flaw allowed them to gain access to an internal management system and insert fake withdrawal commands that appeared legitimate.

After injecting these commands, the attacker deleted the digital traces left behind. Chen noted this made it difficult to determine exactly what happened during the incident.

Bitget confirmed that private keys and cold wallets were not compromised. The company is working with cybersecurity firms Mandiant and SlowMist and plans to release a formal report soon.

Fund recovery and withdrawal status

As of September 25, Bitget's user protection fund held $465 million. The company stated that corporate reserves, audited at over $1.4 billion as of August 31, will replenish the fund.

Withdrawals have begun to resume. Bitcoin withdrawals restarted on Monday, processing over 3,000 BTC in the first hour. Ethereum withdrawals are scheduled to reopen on September 29.

Attribution remains under investigation

Chen mentioned that the exchange suspects the same group responsible for previous incidents but declined to name them publicly. A formal incident report is expected later this week to provide more details on the attribution.

Source

Newisty Editorial Team
Written by

Newisty Editorial Team

Technology · Crypto · Digital Economy
View all posts

Newisty Editorial Team covers technology, cryptocurrency, digital products, online platforms, developer tools and the wider digital economy. Our content is researched from official sources, company announcements, public documentation, market data and other primary or reputable sources. Articles are reviewed and edited before publication for clarity, accuracy and useful context.

Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!