Cryptelio

Bitget CEO Reveals Details of $388 Million Hack and Withdrawal Resumption Plans

Cryptelio Editorial Published 28 Sep 2026 · 23:00 UTC
Bitget CEO Reveals Details of $388 Million Hack and Withdrawal Resumption Plans

Bitget's CEO, Gracy Chen, disclosed that the recent hack, which resulted in the theft of approximately $388 million in cryptocurrency, was facilitated by exploiting vulnerabilities in third-party products. The hacker managed to steal internal credentials, allowing them to issue fraudulent withdrawal commands that bypassed the exchange's risk controls.

Chen emphasized that the hack did not compromise any private keys or cold wallets, and the situation has been contained. Affected systems have been isolated, and the vulnerability has been addressed. Internal credentials have been revoked and reissued, and access to sensitive systems has been restructured. The exchange has also notified the relevant third-party vendor and disabled the affected functionality while a fix is developed.

In response to the incident, Bitget temporarily halted withdrawals but has since begun a phased resumption. As of September 28, the exchange processed over 9,500 withdrawal orders, primarily for Bitcoin, with Ethereum and USDT withdrawals set to resume shortly thereafter. Chen reassured users that 100% of their funds are covered by the Bitget Protection Fund, which currently holds 5,500 Bitcoin in publicly visible wallets.

Following the hack, nearly 5,000 Bitcoin has left Bitget's reserves, indicating users' reactions to the security breach. The exchange's Bitcoin balance dropped significantly, reflecting both customer withdrawals and potential wallet movements. Blockchain security firms, including Mandiant and SlowMist, are assisting with forensic investigations and asset tracing efforts.

As the situation develops, the focus remains on recovering the stolen funds, which are reportedly being laundered through various channels, complicating the recovery process.

FAQ

What caused the $388 million hack on Bitget?

The hack was facilitated by exploiting vulnerabilities in third-party products, allowing the hacker to steal internal credentials and issue fraudulent withdrawal commands that bypassed the exchange's risk controls.

Were any private keys or cold wallets compromised during the hack?

No, the hack did not compromise any private keys or cold wallets, and the situation has been contained.

What measures has Bitget taken in response to the hack?

Bitget has isolated affected systems, revoked and reissued internal credentials, restructured access to sensitive systems, and notified the relevant third-party vendor while disabling the affected functionality.

What is the status of withdrawals on Bitget after the hack?

Bitget temporarily halted withdrawals but has begun a phased resumption. As of September 28, they processed over 9,500 withdrawal orders, primarily for Bitcoin, with Ethereum and USDT withdrawals set to resume shortly thereafter.

How does Bitget ensure the safety of user funds after the hack?

Bitget reassured users that 100% of their funds are covered by the Bitget Protection Fund, which currently holds 5,500 Bitcoin in publicly visible wallets.

Related

Comments

Comments are moderated before publish.

No comments yet — be the first.

Comment as guest

Captcha