Skip to the article
Crypto Docket

Crypto news and comparative analysis

Bitget breach exposes risk beyond stolen private keys

Bitget says attackers stole $387.5 million from hot and warm wallets through forged withdrawals; phased services have resumed, but the breach reached beyond private keys.

By Crypto Docket Newsroom#3266973 min read

Abstract cover artwork

Bitget says attackers stole $387.5 million from its hot and warm wallets on September 24, using forged withdrawal instructions rather than stealing private keys. The loss was revised up from $351.6 million after the exchange identified additional assets, and the breach reached infrastructure that could issue withdrawals even while the cold wallets holding most platform assets remained untouched. In its incident timeline, Bitget’s official account says 12 wallet addresses were involved and that the private keys were not compromised.

The distinction matters for a custodial exchange: keeping most assets in cold storage limits exposure to online wallet theft, but it does not by itself prevent a compromised internal system from authorizing transfers out of operational wallets. Bitget’s case therefore differs from a direct theft of cold-wallet keys, while still showing that operational controls can become a route to customer-facing losses.

How did attackers bypass Bitget’s withdrawal checks?

Bitget’s investigation found that attackers exploited a vulnerability in a third-party security product to steal internal network credentials, then used forged commands to make its wallet system process unauthorized withdrawals. BleepingComputer’s report, citing findings from investigators Mandiant and SlowMist, describes access to two security appliances, followed by movement to a production wallet server and deployment of malicious tools.

That account points to a compromise of the path into the wallet system, rather than a theft of the cryptographic keys themselves. Bitget says the attackers’ instructions passed through the authorization process and bypassed risk checks. It has said the relevant vulnerability was remediated, internal credentials were reset and withdrawal verification was strengthened. The exchange has also said the full technical report is still to come.

What was affected, and what has resumed?

The stolen assets came from exchange hot and warm wallets across multiple networks; Bitget says its cold wallets and separate self-custodial Bitget Wallet product were unaffected. The revised $387.5 million estimate reflects further on-chain tracing, not a second theft. Bitget’s incident page rounds the final amount to about $388 million and lists 12 affected wallet addresses.

Bitget suspended withdrawals while it checked the infrastructure, but deposits and trading remained available, according to the exchange. It then restarted withdrawals in stages: Bitcoin first on September 28, followed by Ether, USDT, and other cryptocurrencies, fiat withdrawals and peer-to-peer services. Its latest incident update says all categories had resumed by October 2. The phased approach limited immediate withdrawal access while checks proceeded; the trade-off was that customers could not freely move some assets during the review.

What should users watch after withdrawals return?

The exchange has said the financial impact would be covered by its Protection Fund, and its latest update reports the fund had been replenished to more than $300 million, holding 3,705 BTC. That reported balance is below the $387.5 million breach estimate, so the figures do not by themselves establish how much of the loss has ultimately been offset. Bitget says users’ account balances were unaffected; the fund balance and any recoveries remain relevant measures of how the exchange absorbs the incident.

The next signals are the promised technical report, updates on assets frozen or recovered, and clear disclosures of the fund’s balance and reserve position. With withdrawals restored, the immediate test shifts from service availability to whether Bitget can show how the credential compromise was contained and how its new controls stop forged instructions from reaching the wallet system again.

Sources and documents