Bitget says the attacker behind last week’s $388 million crypto theft gained access by exploiting vulnerabilities in third-party products rather than by breaching the exchange’s private keys or cold-wallet infrastructure.
In an update on the incident, Chief Executive Gracy Chen said the exploiter stole internal credentials and used them to issue fraudulent withdrawal commands that bypassed Bitget’s risk controls. The company says the incident has been contained and that withdrawals are returning in stages.
How Bitget says the attack happened
According to Chen, the attacker’s entry point was a vulnerability linked to third-party products used by the exchange. After obtaining internal credentials, the hacker was able to send withdrawal instructions that appeared valid enough to evade Bitget’s normal safeguards.
The company’s account of the breach focuses on compromised internal access rather than a failure of wallet custody. Chen said no private keys were exposed and no cold wallets were affected during the exploit.
Containment and investigation
Bitget said the affected systems were isolated and the vulnerability has been remediated. Relevant servers were also separated from the rest of the environment, which the company said was intended both to prevent additional compromise and to preserve forensic evidence.
Chen said internal credentials tied to sensitive systems were revoked and reissued, and that access to highly sensitive systems has been restructured. Bitget also said it notified the relevant third-party vendor, shared details of the flaw and disabled the affected functionality until a fix is available.
The exchange said Mandiant and SlowMist are continuing to support an independent forensic investigation as well as asset-tracing efforts linked to the stolen funds.
User-fund assurance after the theft
Bitget said user balances are fully covered through its Bitget Protection Fund. Chen described the reserve as a self-funded pool holding 5,500 Bitcoin in publicly visible wallets.
The statement is aimed at addressing customer concerns that followed the loss and the subsequent halt in withdrawals. The company did not announce additional figures beyond the previously cited $388 million stolen in the attack.
Withdrawals are resuming in phases
After the exploit last week, Bitget temporarily suspended withdrawals. The exchange has started restoring access on a staggered schedule rather than reopening all services at once.
Bitcoin withdrawals were set to resume on Monday, with Ethereum scheduled for Tuesday and USDT for Wednesday. Other token withdrawals, fiat currencies and peer-to-peer trading are due to return on Friday, according to the timetable shared by the company.
For now, the next confirmed steps are the completion of that phased reopening and the continuation of the independent forensic review and asset-tracing process already underway.
Source: dailyhodl.com