Bitget is gradually restoring normal operations after hackers stole about $388 million from its hot wallets on Sept. 24. Blockchain security firm SlowMist traced the attack to malicious activity dating back to Aug. 31 and said attackers exploited vulnerabilities involving third-party security products and a wallet application host.
The attackers obtained high-level internal credentials and used a customised tool to manipulate the exchange’s withdrawal process. Bitget CEO Gracy Chen said private keys and cold wallets were not compromised. The exchange has restored access to BTC, ETH and USDT, while its Protection Fund has reached $309 million.
-Bitget Protection Fund back to >$300M as we promised. https://t.co/iWjc4O51f4
-PoR is 131% per yesterday’s update https://t.co/NnAWhZnLXj
-Withdrawal resumed for BTC, ETH, and USDT already, will open up everything else on Friday.The business is gradually back to usual. Thank… pic.twitter.com/eTbYO0MyvJ
— Gracy Chen @Bitget (@GracyBitget) September 30, 2026
According to SlowMist’s latest progress report, the attackers’ activity began well before the actual theft of funds. The security firm said it traced suspicious activity to Aug. 31, when a zero-day vulnerability was apparently exploited.
@bitget has engaged SlowMist’s security team to investigate the September 25 hot wallet asset theft.
As of September 29, our investigation has identified malicious activity involving certain third-party security products and a wallet application host, as well as a highly… pic.twitter.com/JQ3zoAH5Yi
— SlowMist (@SlowMist_Team) September 30, 2026
The attacker reportedly used a hidden script to access the database of a third-party security product, referred to as “Product A” by SlowMist. The password was obtained from an environment variable. Similar suspicious activity was later detected on other nodes on Sept. 23 and Sept. 25.
On Sept. 25, the attacker also gained access to the management platform of another security product, called “Product B”. SlowMist said the attacker used the identity of an internal employee and attempted to inject system commands, change server configurations and upload malicious files.
The investigation is still underway, with SlowMist examining how the attacker moved between the different systems.
One of the more significant findings was the recovery of a deleted and highly customised tool. SlowMist said the tool was designed to interfere with the wallet system’s withdrawal process. It could forge risk-control parameters, create fraudulent withdrawal requests and trigger the withdrawal process.
The attacker also tried to directly alter withdrawal records in the wallet database and initiate additional Bitcoin withdrawals. Two fabricated Bitcoin withdrawal orders entered the processing stage but failed because of errors. The attacker then checked system logs and order status before making further attempts.
SlowMist’s on-chain investigation found the earliest transfer identified so far at 2:31 am UTC+8 on Sept. 25. An attacker-controlled address first received 93 TRX and, 11 seconds later, 0.84 ETH. Transfers continued across several blockchains for about two hours and 52 minutes.
Bitget had earlier reported that about $387.5 million worth of assets were transferred to addresses controlled by the attackers. Chen later described the incident as a breach involving a vulnerability in a third-party security product that allowed attackers to obtain high-level internal credentials and issue fraudulent withdrawal commands. According to Chen, Bitget’s private keys and cold wallets were not compromised.
The exchange is now working to restore normal services. Chen said withdrawals for all tokens were expected to resume on Friday, while users had already regained access to Bitcoin, Ether and USDt.
Bitget Protection Fund Update 📢
Bitget has replenished its User Protection Fund, restoring it to over $300 million.
The Protection Fund is an additional safeguard for user assets, funded by Bitget’s own capital. pic.twitter.com/RNVi5NjaGv
— Bitget (@bitget) September 30, 2026
Bitget’s Protection Fund has also grown to about $309 million. The fund was established in January 2022 with 5,500 BTC and was designed to cover certain user losses that were not caused by user misconduct. Chen said the fund was created for situations such as the current incident and had absorbed the financial impact of the attack.
Bitget is continuing efforts to recover the stolen funds, but Chen has acknowledged that recovering the entire amount may be difficult. The exchange has not ruled out different possibilities regarding the identity of the attackers, including an insider attack or involvement by North Korean hackers.
Bitget has also launched a bounty programme, offering rewards linked to frozen and recovered funds. Meanwhile, blockchain investigator ZachXBT reported that wallets associated with the Bitget hack had moved about $3.8 million worth of Zcash (ZEC) into the network’s Ironwood pool. The amount represented around 14% of the 18,917 ZEC reportedly stolen in the attack.
The latest findings highlight how a compromise involving third-party security infrastructure can eventually affect an exchange’s internal systems and withdrawal controls, even when its core private keys and cold wallets remain protected.
Stay informed with the latest trends in Web3, blockchain innovation, and cybersecurity updates at 3verseTV
You need to login in order to Like










Leave a comment