Bitget Recovers After $388 Million Security Incident
Bitget confirmed that a security incident on 25 September affected about $388 million in assets. Investigations by SlowMist and Mandiant linked the attack to a zero-day vulnerability in a third-party security product, rather than a leaked private key, compromised cold wallet or smart-contract exploit. The attacker reportedly obtained internal credentials, forged withdrawal commands and bypassed wallet risk controls across several blockchain networks.
Bitget halted withdrawals after detecting abnormal fund movements and launched its highest-level emergency response. The exchange said its user protection fund would cover the losses. The fund held 5,500 BTC, valued at more than $464 million at the time, and was restored to at least its $300 million benchmark within a week. Bitget also published a proof-of-reserves report showing a total reserve ratio of 131%.
Withdrawals resumed in stages, beginning with BTC on 28 September and ETH on 29 September. By 30 September, all currencies had reportedly resumed withdrawals. On-chain data showed ETH inflows exceeded outflows after services reopened, while daily platform inflows reached about $231 million, close to the August average. Bitget also launched incentive programmes involving ETH, BTC, USDT and USDGO to rebuild user activity.
The incident highlights expanding exchange security risks, including third-party software, privileged credentials and internal infrastructure. For traders, the rapid restoration of withdrawals, protection-fund coverage and transparent communication may reduce contagion concerns, although third-party risk and exchange counterparty risk remain important factors.
Neutral
The market impact is best classified as neutral. The incident was severe, with approximately $388 million in affected assets, and could initially have triggered withdrawals, exchange-token selling and broader concerns about counterparty risk. However, the reported damage was contained at the platform level. Bitget stated that its protection fund would cover user losses, restored the fund to its benchmark, published a 131% reserve ratio and reopened withdrawals in stages according to a disclosed schedule.
Short-term trading sentiment may remain cautious. Traders are likely to monitor wallet balances, reserve disclosures, fund flows and any evidence that the attacker can liquidate assets. The return of net ETH inflows and daily platform inflows close to historical averages suggests that the event did not produce sustained panic or sector-wide contagion. This differs from past exchange failures where frozen withdrawals, unclear liabilities or insufficient reserves caused prolonged outflows and sharp repricing.
Longer term, the incident is a reminder that exchange risk extends beyond private keys and cold wallets. Third-party security products, privileged credentials and wallet-operating infrastructure can become attack vectors. Bitget’s response may improve confidence in platforms with transparent reserves and pre-funded protection mechanisms, but it does not eliminate operational risk. The overall effect is therefore mixed: confidence in Bitget may recover, while the wider market receives a bearish security warning without a clear directional catalyst for major cryptocurrencies.