Original author: WhiteRunner
In the past few years, large-scale security incidents at exchanges have not been uncommon, and attack entry points have gradually expanded from hot wallets and signature systems to internal permissions and third-party services. As systems become increasingly complex, the boundaries exchanges need to defend are also growing larger.
On September 25, Bitget suffered a security incident, and it was ultimately confirmed that approximately $388 million in assets were affected. CEO Gracy Chen later said in a livestream that this was the first such security incident in the platform's eight years of operation. According to the investigation results published by SlowMist, the earliest malicious activity discovered involved a zero-day vulnerability on a node of a third-party security product. Investigations by both Mandiant and SlowMist pointed the attack path to the compromise of third-party security infrastructure, which ultimately led into Bitget's wallet environment.
After the incident, Bitget announced that the losses would be covered by its user protection fund. At the time of the incident, this fund, established in 2022, held 5,500 BTC, worth more than $464 million. Gracy promised that after being used, the protection fund would be replenished to $300 million within one week, restoring it to the baseline scale set when it was established in 2022. On September 30, this commitment was fulfilled on schedule.
Withdrawals also began to resume according to the previously announced timetable. At 16:00 on September 28, BTC was the first to open for withdrawals. After ETH withdrawals resumed on the 29th, the relevant hot wallets quickly shifted from net outflows to net inflows, and soon the balance was even slightly above the initial level before withdrawals were opened, showing that user trust is returning. As of press time, all currencies have resumed withdrawals.
From nearly $400 million being stolen to withdrawals resuming and funds flowing back in, only a few days passed in between. How exactly did the hacker transfer assets without the private key being leaked? How did a protection fund prepared four years in advance truly come into play? And what did Bitget do that caused the incident to begin to turn around?
One particularly unusual aspect of this attack is that Bitget's private key was not leaked, the cold wallet was not breached, and it was not a smart contract vulnerability either. The breakthrough the hackers found turned out to be a third-party security product used by the platform.

According to the investigation results currently disclosed by Bitget, at around 02:31 Beijing time on September 25, the earliest confirmed related small transfers appeared on-chain, after which larger-scale asset transfers began to occur.
In an interview with The Block, Gracy stated that between 02:58 and 04:09, the attacker conducted 17 large transactions across multiple networks including Ethereum, XRP, Zcash, BNB Chain, Base, Arbitrum, Optimism, and Avalanche. As subsequent statistics were supplemented, Bitget ultimately confirmed that the incident affected approximately $388 million in assets.
At 03:05, about 7 minutes after the first large transfer occurred, Bitget's reconciliation system detected significant fund discrepancies and triggered a platform-wide withdrawal block; at 03:14, the platform activated its highest-level emergency response. Since private key leakage could not yet be ruled out at the time, the wallet team subsequently moved assets to cold wallets and shut down wallet withdrawal and signing services.
Afterward, the security team confirmed the root cause of the incident. According to the currently disclosed attack chain, the hacker exploited a previously unknown zero-day vulnerability in a third-party security product.

A so-called zero-day vulnerability refers to a security flaw that the vendor and users were previously unaware of and for which no ready-made patch was available for advance deployment. In other words, this was a previously unknown attack entry point. What happened next is the key to understanding this loss of nearly $400 million.
By exploiting this vulnerability, the attacker used the flaw in the third-party security product to steal internal network credential permissions, forge withdrawal commands to the wallet system, and deceive the wallet into executing abnormal transfers that bypassed risk checks. Throughout the entire process, private keys were not leaked, and cold wallets were not affected.

Gracy later also revealed that after completing the operation, the attacker deleted some related traces, increasing the difficulty of investigation and reconstructing the attack process.
Bitget subsequently disabled the affected third-party functions and reissued internal credentials, revoked and re-segmented highly sensitive permissions, while also adding independent verification for withdrawals. Mandiant and SlowMist are still participating in independent forensic investigations and fund tracing.
A direct warning this incident leaves for the industry is that the security boundary of an exchange is no longer just private keys and cold wallets. Security software, wallet infrastructure, and other third-party services that can access core systems may themselves also become attack entry points.
After the incident, what truly tests an exchange next is who should bear the losses, and how management faces and reassures users.
Bitget was the first to tap into its protection fund.
This fund was established in 2022 and has long maintained a baseline scale of $300 million. At the time of the incident, the fund held 5,500 BTC, worth over $464 million, enough to cover the final confirmed loss of approximately $388 million.
Bitget subsequently made it clear that the protection fund would bear the financial impact of this incident, and user account balances would not be affected.
Before BTC withdrawals resumed on September 28, on-chain data already showed the protection fund beginning to transfer assets to hot wallets. On-chain analyst Aunt Ai monitored that initially 2,042.28 BTC was transferred from the relevant protection fund address to the Bitget hot wallet (Bitget Protection Fund on-chain monitoring).
This is one of the most industry-referential aspects of Bitget's handling of this incident.
This protection fund was not a compensation plan temporarily announced after the incident, but was established four years earlier. The funds have been reserved for the long term, the wallet addresses are publicly verifiable, and there is a clear baseline scale; after an actual incident occurs, it is actually deployed, and after use, it is replenished according to the original standard.
The protection fund solved the problem of bearing losses. This time, the nearly $400 million loss was ultimately not passed on to users. Gracy stated that Bitget would replenish the protection fund back to at least $300 million within a week, and based on on-chain monitoring, this was fulfilled as scheduled.

Bitget also released its 47th Proof of Reserves (PoR) on September 30, with a total reserve ratio of 131%, covering 19 types of assets. Among them, the reserve ratios for BTC, ETH, USDT, and USDC were 142%, 110%, 107%, and 154%, respectively.

Beyond funds, Bitget's communication approach over these few days is also worth noting.
Gracy responded continuously for about three hours in a live stream for the community, and Xie Jiajin also continued to update progress through social media and the community. The three-hour live stream itself is not the point; more importantly, during the most chaotic days of the incident, management consistently stood at the forefront to respond to questions.

Moreover, several key statements basically provided clear information or next-step plans.
Who would bear the losses was quickly clarified as being covered by the protection fund; after the affected amount was adjusted from $351.6 million to $388 million, the reason for the change in the figure was explained; before the attack entry point was confirmed, there was no rush to draw conclusions about the attacker's identity and method; after progress was made in the investigation, details such as third-party security products, zero-day vulnerabilities, high-privilege credentials, and forged withdrawal instructions were gradually disclosed.
The same was true for the resumption of withdrawals.
This incident involved multiple currencies and multiple networks, and the scope of the investigation was not limited to a single wallet. Bitget did not restore all withdrawals at once, but instead opened them in batches after confirming the relevant wallets, networks, and risk exclusions one by one.
On September 26, the platform announced a specific restoration timetable: BTC would be restored on September 28, ETH and related networks on September 29, USDT and related networks on September 30, and other tokens, fiat currencies, and C2C services were scheduled to be restored on October 2. As of press time, it had been verified that all were restored on schedule.

Considering that this was a large-scale security incident involving multiple currencies, multiple networks, third-party software, and internal permissions, it is commendable that a restoration plan with specific dates and times was provided first and then fulfilled one by one.
The protection fund was prepared four years in advance and only tapped into when a real incident occurred; management continuously engaged with the community; confirmed information was released promptly, while uncertain information was not rushed to conclusions; the recovery plan provided a clear timeline and was executed according to that timeline.
This series of clean and decisive actions led many people to view Bitget more positively.
After ETH withdrawals resumed on September 29, a noteworthy change quickly appeared on-chain.

According to monitoring by on-chain analyst Aunt Ai, the relevant hot wallets Bitget prepared for ETH withdrawals saw their balances return to above 30,000 ETH within half an hour after withdrawals opened, exceeding the initial value.
Data subsequently released by Bitget showed that in the first hour after withdrawals resumed, about 9,674 ETH flowed in and about 9,023 ETH flowed out, for a net inflow of about 651 ETH. Data on September 30 showed that the platform's 24-hour fund inflow reached $231 million, close to the average daily inflow of $245 million in August this year. There was no one-way capital outflow as the market had previously feared; instead, a recovery in market confidence could be seen.
At the same time, in order to repay users' trust, Bitget also began launching multiple incentive campaigns.

ETH PoolX offered a prize pool of 500,000 USDT. Users could participate in the distribution simply by locking ETH. In the early stage of the campaign, the estimated APR on the page once reached about 37.11%, and then dynamically declined as participating funds increased.
BTC PoolX was subsequently launched, offering a prize pool of 100,000 BGB and giving additional bonuses based on users' BTC holdings over the previous 15 days.
On the stablecoin front, Bitget simultaneously launched flexible savings campaigns for USDT and USDGO, supporting deposit and withdrawal at any time, with limited-time APRs reaching 10% and 12% respectively. The "Peer Program" included 30% of the eligible trading fee revenue during the campaign period into a user reward pool, of which 60% was distributed based on trading volume and 40% based on asset volume. On October 2, Bitget's official data showed that the first batch of rewards had been distributed, with a cumulative 1,907,455 USDT issued to 763,543 users.
The intent behind these campaigns is not difficult to understand. The restoration of withdrawals solved the question of whether users "could leave," and the series of campaigns subsequently launched were about restarting trading, wealth management, and capital retention.
Soon, many users voted with their funds, demonstrating confidence in Bitget and enthusiasm for the campaigns.

A few days ago, the market's biggest concern was still "when can the money be withdrawn"; with withdrawals restored, the question began to shift to "which campaign to join to earn a higher APR."
The signal of a turning point in the incident.
For an exchange, the most direct proof of user confidence recovery is that users are still willing to keep their money there when they can freely deposit and withdraw.
After this incident at Bitget, it received support from almost "half the industry."
The most noteworthy among them is Bybit.
In February 2025, Bybit suffered a security incident of about $1.4 billion. About 5 hours after the attack occurred, Bitget provided Bybit with 40,000 ETH, then worth more than $100 million. These 40,000 ETH carried no interest, no collateral, and no fixed repayment deadline. Bybit subsequently repaid them in full within three days.
More than a year later, the two sides' positions were reversed. After Bitget's incident, Bybit CEO Ben Zhou quickly publicly expressed willingness to help, and specifically mentioned: "When we suffered a hacker attack, Bitget once helped us." Bybit then included the relevant stolen funds in the LazarusBounty system for tracking.
Those who stepped forward were far from only Bybit. CZ publicly voiced support after the incident, and the Binance security team subsequently cooperated with Bitget, including sharing threat intelligence, tracking stolen funds, and supporting asset recovery; MEXC CEO Vugar Usi also proactively contacted Bitget to express support. Beyond exchanges, Mandiant and SlowMist participated in investigation and forensics, while Circle and Tether participated in freezing the relevant assets.

When I saw this news, I did feel a surge of excitement.
The crypto industry has never lacked competition. Exchanges compete for users, for liquidity, for market share, but when a security crisis involving hundreds of millions of dollars actually hits, peers will still band together for warmth.
And whether Bitget as a platform has truly won trust and respect in the industry is most directly shown in moments of crisis.
But if this matter stops at "a friend in need is a friend indeed," then its significance is underestimated.
The crypto industry does not have a unified institution to backstop it, but protection funds, peer collaboration, security agencies, and on-chain tracking are forming their own risk-handling network. At the same time, from hot wallets, signing systems to third-party software and internal permissions, the boundaries exchanges need to defend are also growing larger and larger: attacks are becoming more and more complex, and the industry needs to respond hand in hand.
And establishing protection funds, maintaining public transparency and honoring commitments afterward, as well as industry cooperation, are now already an excellent paradigm for responding to crises, and Bitget has now seriously demonstrated it once.

Over the past two years, the crypto industry has been talking about Mass Adoption. ETFs, stablecoins, RWA, and tokenized securities have brought more traditional financial capital in, and the U.S. regulatory framework is also gradually being established. Having reached this point, what the industry needs to prove is no longer just innovation and growth, but also the ability to handle risk.
This time, Bitget used 400 million dollars to test a platform's sense of responsibility in the face of crisis. A crisis will not end a platform, but accountability can redefine a platform.
For the crypto industry that is moving toward mainstream finance, this is likewise an exam it must go through. No financial system can be built on the assumption that "nothing will ever go wrong." When something really does go wrong, whether it can pay, explain clearly, and recover tests responsibility and bottom lines.
How the financial world ultimately views the crypto industry may depend on how it correctly responds to a bad day.
Welcome to join the official BlockBeats community:
Telegram Subscription Group: https://t.me/theblockbeats
Telegram Discussion Group: https://t.me/BlockBeats_App
Official Twitter Account: https://twitter.com/BlockBeatsAsia