BTC $84,865.19 -2.11%
ETH $2,681.23 -2.42%
BNB $773.92 -0.99%
XRP $1.49 -3.14%
SOL $119.45 -2.58%
TRX $0.3358 +0.33%
DOGE $0.0927 -4.07%
ADA $0.2450 -4.24%
BCH $311.57 -1.32%
LINK $13.88 -3.37%
HYPE $88.42 -2.55%
AAVE $180.93 -1.33%
SUI $1.17 -2.14%
XLM $0.2153 -4.12%
ZEC $1,303.63 -5.69%
AAPL $333.21 +0.69%
AMZN $251.85 +0.29%
GOOGL $343.15 +0.01%
MSFT $517.39 +0.21%
META $728.08 -0.39%
NVDA $234.35 -1.17%
TSLA $370.95 +0.44%
SNDK $1,716.83 -1.20%
INTC $117.99 -4.91%
SPCX $159.11 +1.82%
MU $1,069.59 -1.28%
AMD $632.29 -0.92%
BTC $84,865.19 -2.11%
ETH $2,681.23 -2.42%
BNB $773.92 -0.99%
XRP $1.49 -3.14%
SOL $119.45 -2.58%
TRX $0.3358 +0.33%
DOGE $0.0927 -4.07%
ADA $0.2450 -4.24%
BCH $311.57 -1.32%
LINK $13.88 -3.37%
HYPE $88.42 -2.55%
AAVE $180.93 -1.33%
SUI $1.17 -2.14%
XLM $0.2153 -4.12%
ZEC $1,303.63 -5.69%
AAPL $333.21 +0.69%
AMZN $251.85 +0.29%
GOOGL $343.15 +0.01%
MSFT $517.39 +0.21%
META $728.08 -0.39%
NVDA $234.35 -1.17%
TSLA $370.95 +0.44%
SNDK $1,716.83 -1.20%
INTC $117.99 -4.91%
SPCX $159.11 +1.82%
MU $1,069.59 -1.28%
AMD $632.29 -0.92%

After the withdrawal of funds was restored, the capital not only did not decrease but instead increased. How did Bitget turn the situation around in five days?

Core Viewpoint
Summary: A crisis will not end a platform; responsibility can redefine a platform.
Industry Express
2026-10-03 16:43:36
A crisis will not end a platform; responsibility can redefine a platform.

Author: WhiteRunner

In recent years, it has not been uncommon for exchanges to encounter major security incidents, with attack vectors gradually extending from hot wallets and signature systems to internal permissions and third-party services. As systems become increasingly complex, the boundaries that exchanges need to defend are also expanding.

On September 25, Bitget experienced a security incident, ultimately confirming that approximately $388 million in assets were affected. CEO Gracy Chen subsequently stated in a live broadcast that this was the first such security incident in the platform's eight-year operation. According to the investigation results released by SlowMist, the earliest detected malicious activity involved a zero-day vulnerability on a node of a third-party security product. Investigations by Mandiant and SlowMist both pointed to the attack path leading to the compromise of third-party security infrastructure, which ultimately entered Bitget's wallet environment.

After the incident, Bitget announced that the losses would be covered by the user protection fund. At the time of the incident, this fund, established in 2022, held 5,500 BTC, valued at over $464 million. Gracy promised that the protection fund would be replenished to $300 million within a week after use, restoring it to the benchmark size determined at its establishment in 2022. On September 30, this promise was fulfilled as scheduled.

Withdrawals also began to resume according to the previously announced timetable. On September 28 at 16:00, BTC was the first to reopen for withdrawals, and after ETH resumed withdrawals on the 29th, the related hot wallet quickly shifted from net outflow to net inflow, with balances even slightly exceeding the initial levels before the withdrawal reopening, indicating a return of user trust. As of the time of publication, all cryptocurrencies had resumed withdrawals.

From nearly $400 million being stolen to the resumption of withdrawals and funds flowing back in, only a few days had passed. How did the hackers manage to transfer assets without leaking private keys? How did a protection fund prepared for four years come into play? What did Bitget do to turn the situation around?

1. Hackers Exploit Zero-Day Vulnerability in Third-Party Security Product

One unique aspect of this attack is that Bitget's private keys were not leaked, cold wallets were not compromised, and there were no smart contract vulnerabilities. The breakthrough the hackers found was in a third-party security product used by the platform.

After the withdrawal of funds was restored, the capital not only did not decrease but instead increased. How did Bitget turn the situation around in five days?

According to the investigation results currently disclosed by Bitget, around 02:31 Beijing time on September 25, the earliest confirmed small transactions appeared on-chain, followed by larger asset transfers.

Gracy stated in an interview with The Block that between 02:58 and 04:09, the attackers conducted 17 large transactions across multiple networks including Ethereum, XRP, Zcash, BNB Chain, Base, Arbitrum, Optimism, and Avalanche. With subsequent statistical updates, Bitget ultimately confirmed that the incident affected approximately $388 million in assets.

At 03:05, about seven minutes after the first large transfer occurred, Bitget's reconciliation system detected significant discrepancies in funds and triggered a platform-wide withdrawal block; at 03:14, the platform initiated the highest level of emergency response. Since private key leakage could not be ruled out at that time, the wallet team subsequently transferred assets to cold wallets and shut down wallet withdrawals and signature services.

The security team then confirmed the root cause of the incident. According to the currently disclosed attack chain, the hackers exploited a previously unknown zero-day vulnerability in a third-party security product.

After the withdrawal of funds was restored, the capital not only did not decrease but instead increased. How did Bitget turn the situation around in five days?

A zero-day vulnerability refers to a security flaw that the vendor and users have not yet identified, and for which there are no existing patches that can be deployed in advance. In other words, this is a previously unknown attack vector. What happened next is key to understanding the nearly $400 million loss.

Exploiting this vulnerability, the attackers stole internal network credential permissions through the third-party security product's flaw, forged withdrawal commands to the wallet system, and deceived the wallet into executing abnormal transfers that bypassed risk checks. Throughout the process, private keys were not leaked, and cold wallets were unaffected.

After the withdrawal of funds was restored, the capital not only did not decrease but instead increased. How did Bitget turn the situation around in five days?

Gracy later revealed that after completing their operations, the attackers deleted some relevant traces, increasing the difficulty of investigating and restoring the attack process.

Bitget subsequently disabled the affected third-party functions, reissued internal credentials, reclaimed and re-split high-sensitivity permissions, and added independent verification for withdrawals. Mandiant and SlowMist are still participating in independent forensic investigations and fund tracking.

One direct warning this incident leaves for the industry is that the security boundaries of exchanges are no longer just private keys and cold wallets. Security software, wallet infrastructure, and other third-party services that can access core systems may also become attack vectors.

2. Protection Fund Activated, Withdrawals Resuming as Scheduled

After the incident, what truly tests an exchange is how it addresses the losses and how management faces and reassures users.

Bitget first activated the protection fund.

This fund was established in 2022 and has long maintained a benchmark size of $300 million. At the time of the incident, the fund held 5,500 BTC, valued at over $464 million, sufficient to cover the confirmed loss of approximately $388 million.

Bitget subsequently clarified that the financial impact of this incident would be borne by the protection fund, and user account balances would not be affected.

Before BTC resumed withdrawals on September 28, on-chain data showed that the protection fund began allocating assets to hot wallets. On-chain analyst Ai monitored that initially, 2,042.28 BTC was transferred from the relevant protection fund address to Bitget's hot wallet (Bitget Protection Fund On-Chain Monitoring).

This is one of the most noteworthy aspects of Bitget's handling of the situation for the industry to reference.

This protection fund was not a compensation plan announced after the incident but was established four years ago. The funds are kept in long-term reserves, wallet addresses are publicly verifiable, and there is a clear benchmark size; when an incident occurs, it is actually utilized and replenished according to the original standard afterward.

The protection fund resolved the issue of who bears the losses. This time, the nearly $400 million loss was ultimately not passed on to users. Gracy stated that Bitget would replenish the protection fund to at least $300 million within a week, and on-chain monitoring indicates that this has been fulfilled as promised.

After the withdrawal of funds was restored, the capital not only did not decrease but instead increased. How did Bitget turn the situation around in five days?

On September 30, Bitget also released the 47th proof of reserves (PoR), with a total reserve ratio of 131%, covering 19 asset categories. Among them, the reserve ratios for BTC, ETH, USDT, and USDC were 142%, 110%, 107%, and 154%, respectively.

After the withdrawal of funds was restored, the capital not only did not decrease but instead increased. How did Bitget turn the situation around in five days?

Beyond the funds, Bitget's communication approach during these days is also noteworthy.

Gracy responded continuously for about three hours in a community live broadcast, and Xie Jiayin also kept updating progress through social media and community channels. The three-hour live broadcast itself is not the focus; more importantly, during the most chaotic days of the incident, management consistently stood at the forefront to address questions.

After the withdrawal of funds was restored, the capital not only did not decrease but instead increased. How did Bitget turn the situation around in five days?

Moreover, several key statements provided clear information or next steps.

It was quickly clarified that the losses would be covered by the protection fund; the affected amount was adjusted from $351.6 million to $388 million, with explanations for the numerical changes; no rush to conclude the identity and method of the attackers before confirming the attack vector; and after progress in the investigation, details about the third-party security product, zero-day vulnerabilities, high-privilege credentials, and forged withdrawal instructions were gradually disclosed.

The resumption of withdrawals was similar.

This incident involved multiple cryptocurrencies and networks, and the scope of investigation was not limited to a single wallet. Bitget did not restore all withdrawals at once but opened them in batches after confirming relevant wallets, networks, and risk exclusions.

On September 26, the platform announced a specific recovery timetable: BTC would resume on September 28, ETH and related networks on September 29, USDT and related networks on September 30, and other tokens, fiat currencies, and C2C services would resume on October 2. Before publication, it was confirmed that everything resumed as scheduled.

After the withdrawal of funds was restored, the capital not only did not decrease but instead increased. How did Bitget turn the situation around in five days?

Considering this was a large-scale security incident involving multiple cryptocurrencies, networks, third-party software, and internal permissions, providing a detailed recovery plan with specific dates and times, and then fulfilling it item by item, is commendable.

The protection fund was prepared four years in advance and was actually utilized after the incident occurred; management continuously faced the community; confirmed information was promptly disclosed, while uncertain information was not rushed to conclusions; and a clear recovery plan was provided with specific timelines, which were then executed accordingly.

This series of clean and decisive actions has led many to view Bitget more positively.

3. Turning Point in the Incident, Funds Flowing Back In

After ETH resumed withdrawals on September 29, an interesting change quickly appeared on-chain.

After the withdrawal of funds was restored, the capital not only did not decrease but instead increased. How did Bitget turn the situation around in five days?

According to on-chain analyst Ai, the relevant hot wallets prepared by Bitget for ETH withdrawals saw their balances return to over 30,000 ETH, exceeding the initial value within half an hour after the withdrawals reopened.

Data released by Bitget subsequently showed that in the first hour after the resumption of withdrawals, approximately 9,674 ETH flowed in and about 9,023 ETH flowed out, resulting in a net inflow of approximately 651 ETH. Data from September 30 indicated that the platform's fund inflow reached $231 million within 24 hours, close to the average daily inflow of $245 million in August this year, with no signs of the one-way capital outflow that the market had previously worried about, but rather a recovery of market confidence.

At the same time, to reward users' trust, Bitget also began launching multiple incentive activities.

After the withdrawal of funds was restored, the capital not only did not decrease but instead increased. How did Bitget turn the situation around in five days?

ETH PoolX offers a prize pool of 500,000 USDT, allowing users to lock up ETH to participate in the distribution. The estimated APR on the early activity page once reached about 37.11%, but then dynamically decreased as participation funds increased.

BTC PoolX was subsequently launched, providing a prize pool of 100,000 BGB, with additional bonuses based on users' BTC holdings over the previous 15 days.

In terms of stablecoins, Bitget launched USDT and USDGO savings activities simultaneously, supporting flexible deposits and withdrawals, with limited-time APRs reaching 10% and 12%, respectively. The "Peer Program" includes 30% of the trading fee income from eligible transactions during the activity period into the user prize pool, with 60% distributed based on trading volume and 40% based on asset amount. On October 2, Bitget's official data showed that the first batch of rewards had been distributed, totaling 1,907,455 USDT to 763,543 users.

The intention behind these activities is not hard to understand. The resumption of withdrawals addresses the user's question of "can I withdraw," while the subsequent series of activities aims to restart trading, financial management, and capital accumulation.

Soon, many users voted with their funds, demonstrating confidence in Bitget and enthusiasm for the activities.

After the withdrawal of funds was restored, the capital not only did not decrease but instead increased. How did Bitget turn the situation around in five days?

A few days ago, the market's main concern was still "when can I withdraw my money"; with the resumption of withdrawals, the question began to shift to "which activity can yield a higher APR."

This signaled a turning point in the event.

For exchanges, the most direct proof of restored user confidence is when users are willing to leave their money in the platform even when they can freely enter and exit.

IV. What a Security Incident Left for the Exchange Industry

After the incident at Bitget, it almost received support from "half of the industry."

The most notable among them is Bybit.

In February 2025, Bybit encountered a security incident involving approximately $1.4 billion. About five hours after the attack, Bitget provided 40,000 ETH to Bybit, worth over $100 million at the time. This 40,000 ETH was provided without interest, collateral, or a fixed repayment deadline. Bybit subsequently repaid the full amount within three days.

More than a year later, the positions of both parties had reversed. After Bitget's incident, Bybit CEO Ben Zhou quickly publicly expressed a willingness to help and specifically mentioned, "When we were attacked, Bitget helped us." Subsequently, Bybit included the relevant stolen funds in the LazarusBounty system for tracking.

It wasn't just Bybit that stepped up. CZ publicly voiced support after the incident, and Binance's security team subsequently collaborated with Bitget, including sharing threat intelligence, tracking stolen funds, and supporting asset recovery; MEXC CEO Vugar Usi also proactively contacted Bitget to express support. Outside of exchanges, Mandiant and SlowMist participated in the investigation and evidence collection, while Circle and Tether were involved in freezing related assets.

After the withdrawal of funds was restored, the capital not only did not decrease but instead increased. How did Bitget turn the situation around in five days?

When I saw these news reports, I indeed felt a surge of excitement.

The crypto industry has never lacked competition. Exchanges compete for users, liquidity, and market share, but when faced with a security crisis involving hundreds of millions of dollars, peers come together for support.

Whether Bitget has truly earned trust and respect in the industry as a platform is most evident in times of crisis.

However, if this matter only remains at "true feelings are revealed in times of adversity," it underestimates its significance.

The crypto industry does not have a unified institution to fall back on, but a risk management network is forming through protection funds, peer collaboration, security institutions, and on-chain tracking. Meanwhile, from hot wallets and signature systems to third-party software and internal permissions, the boundaries that exchanges need to defend are also expanding: attacks are becoming increasingly complex, and the industry needs to respond together.

Establishing protection funds, maintaining transparency and adhering to commitments post-incident, and industry collaboration have now become excellent paradigms for crisis response, and Bitget has now demonstrated this seriously.

After the withdrawal of funds was restored, the capital not only did not decrease but instead increased. How did Bitget turn the situation around in five days?

Over the past two years, the crypto industry has been discussing Mass Adoption. ETFs, stablecoins, RWA, and tokenized securities are bringing more traditional financial capital into the space, and the regulatory framework in the United States is gradually being established. At this stage, the industry needs to prove not only innovation and growth but also the ability to manage risks.

Bitget has tested a platform's sense of responsibility in the face of crisis with $400 million. A crisis will not end a platform; responsibility can redefine a platform.

For the crypto industry moving towards mainstream finance, this is also an exam that must be faced. No financial system can be built on the assumption of "never having issues." When issues do arise, the ability to compensate, clarify, and recover tests responsibility and bottom lines.

How the financial world ultimately views the crypto industry may depend on how it correctly responds to a bad day.

Join ChainCatcher Official
Telegram Feed: @chaincatcher
X (Twitter): @ChainCatcher_
warnning Risk warning
app_icon
ChainCatcher Building the Web3 world with innovations.