Particle.news

Bitget Reopens Bitcoin Withdrawals After $387.5 Million Hack

An exploit of a third‑party security product that spoofed wallet authorizations has led Bitget to say its protection fund will cover customer losses.

Overview

  • Bitget resumed Bitcoin withdrawals at 08:00 UTC on Monday after suspending all withdrawals on September 24 following detection of unauthorized transfers.
  • On‑chain tracing shows about USD 387.5 million moved into attacker‑controlled addresses during the breach.
  • The company says attackers abused a flaw in a third‑party security product to obtain high‑level internal credentials and send forged withdrawal commands that bypassed risk controls.
  • Bitget published a phased restoration timetable with ETH withdrawals set for September 29, USDT for September 30, other tokens and fiat returning October 2, and it launched a 5% recovery bounty while Mandiant and SlowMist assist investigations.
  • Bitget says cold wallets and private keys were not compromised, customer balances remain protected by its User Protection Fund, and recovery is complicated by cross‑chain transfers and mixer services while attribution to North Korea‑linked actors remains the company’s assessment.