Skip to content

Funds Rose Instead of Fell After Withdrawals Were Resumed: How Did Bitget Turn Things Around in Five Days?

Oct 3, 16:11·Original author: WhiteRunner
Funds Rose Instead of Fell After Withdrawals Were Resumed: How Did Bitget Turn Things Around in Five Days?

In recent years, it has not been uncommon for exchanges to experience major security incidents, with attack vectors gradually expanding from hot wallets and signature systems to internal permissions and third-party services. As systems grow increasingly complex, exchanges face ever-expanding defensive perimeters.

On September 25, Bitget suffered a security incident, ultimately affecting approximately $388 million in assets. CEO Gracy Chen later stated in a livestream that this was the first such security breach in the platform's eight-year history. According to the investigation results published by SlowMist, the earliest detected malicious activity involved a zero-day vulnerability on a node of a third-party security product. Investigations by both Mandiant and SlowMist pointed to the compromise of third-party security infrastructure as the initial attack vector, which eventually led into Bitget's wallet environment.

Following the incident, Bitget announced that the losses would be covered by its user protection fund. At the time of the event, the fund, established in 2022, held 5,500 BTC valued at over $464 million. Gracy committed to replenishing the protection fund to $300 million within one week after use, restoring it to the baseline size established when it was set up in 2022. By September 30, this commitment had been fulfilled as scheduled.

Withdrawals also began to resume according to the previously announced schedule. BTC withdrawals reopened first on September 28 at 16:00. After ETH withdrawals resumed on the 29th, the relevant hot wallets quickly shifted from net outflows to net inflows, with balances soon surpassing their pre-withdrawal-initial levels, indicating a return of user trust. As of press time, withdrawals have been restored for all supported assets.

From nearly $400 million stolen to the resumption of withdrawals and renewed capital inflows, only a few days passed. How exactly did the attackers move the assets without compromising private keys? How did a protection fund prepared for four years finally come into play? What did Bitget do to turn the tide of the incident?

Hackers Exploited a Zero-Day Vulnerability to Breach Third-Party Security Product

A distinctive feature of this attack is that Bitget's private keys were not compromised, cold wallets were not breached, and it was not due to a smart contract vulnerability. Instead, the attackers found an entry point through a third-party security product used by the platform.

image

According to the investigation findings disclosed by Bitget so far, around 02:31 Beijing Time on September 25, the earliest confirmed small-scale related transfers appeared on-chain, followed by larger-scale asset movements.

Speaking to The Block, Gracy stated that between 02:58 and 04:09, the attackers conducted 17 large transactions across multiple networks including Ethereum, XRP, Zcash, BNB Chain, Base, Arbitrum, Optimism, and Avalanche. With subsequent updates to the statistics, Bitget ultimately confirmed that the incident affected approximately $388 million in assets.

At 03:05, roughly seven minutes after the first large transfer occurred, Bitget's reconciliation system detected significant fund discrepancies and triggered a platform-wide withdrawal halt. At 03:14, the platform activated its highest-level emergency response. Since private key compromise could not yet be ruled out, the wallet team subsequently transferred assets to cold storage and disabled wallet withdrawals and signing services.

Subsequently, the security team identified the root cause of the incident. Based on the currently disclosed attack chain, hackers exploited a previously unknown zero-day vulnerability in a third-party security product.

image

A zero-day vulnerability refers to a security flaw that neither the vendor nor the users have previously discovered, leaving no ready-made patches available for deployment beforehand. In other words, it represents a previously unknown attack vector. What happened next is key to understanding this near-$400 million loss.

Leveraging this vulnerability, attackers stole internal network access credentials via the third-party security product, forged withdrawal commands to the wallet system, and tricked the wallet into executing anomalous transfers that bypassed risk verification protocols. Throughout the entire process, private keys remained uncompromised and cold wallets were unaffected.

image

Gracy later revealed that after completing their operations, the attackers deleted certain traces, complicating the investigation and reconstruction of the attack sequence.

Bitget subsequently disabled the affected third-party functionality, reissued internal credentials, revoked and further segmented high-sensitivity permissions, and implemented independent verification checks for withdrawals. Mandiant and SlowMist are currently continuing their independent forensic investigations and fund tracing efforts.

This incident delivers a direct warning to the industry: an exchange's security perimeter is no longer limited to private keys and cold wallets. Security software, wallet infrastructure, and other third-party services with access to core systems can themselves become attack vectors.

Protection Fund Deployed, Withdrawals Resume According to Schedule

After the incident occurs, what truly tests an exchange is who bears the losses and how management confronts and reassures users.

Bitget moved first to deploy its protection fund.

Established in 2022, the fund has long maintained a baseline scale of $300 million. At the time of the incident, it held 5,500 BTC valued at over $464 million, sufficient to cover the final confirmed loss amount of approximately $388 million.

Bitget then explicitly stated that the protection fund would absorb the financial impact of this incident, ensuring that user account balances remain unaffected.

Before BTC withdrawals resumed on September 28, on-chain activity already showed the protection fund beginning to allocate assets to hot wallets. On-chain analyst Ai Yi monitored that initially, 2,042.28 BTC was transferred from the relevant protection fund address to Bitget's hot wallets (Bitget Protection Fund On-Chain Monitoring).

This is one of the most instructive aspects of Bitget's handling of this incident for the industry.

This protection fund was not a makeshift compensation plan announced after the incident; it had been built four years prior. Funds were accumulated over the long term, wallet addresses were publicly verifiable, and there was a clear baseline scale. It was actually deployed upon the occurrence of a real incident, and once used, it was replenished according to the original standards.

The protection fund resolved the issue of loss absorption. This time, the nearly $400 million loss was ultimately not passed on to users. Gracy stated that Bitget would replenish the protection fund to at least $300 million within a week, which has been fulfilled as scheduled according to on-chain monitoring.

image

Bitget also released its 47th Proof of Reserves (PoR) report on September 30, showing a total reserve ratio of 131% covering 19 asset types. Among them, the reserve ratios for BTC, ETH, USDT, and USDC stood at 142%, 110%, 107%, and 154%, respectively.

image

Beyond liquidity, Bitget's communication strategy over these days also warrants attention.

Gracy addressed the community directly in a continuous three-hour livestream, while Xie Jiayin consistently updated progress via social media and community channels. The three-hour duration itself was not the main point; more importantly, throughout the most chaotic days of the incident, management remained at the forefront fielding questions.

image

Moreover, each of several key communications largely delivered clear information or outlined next steps.

It was quickly clarified that losses would be covered by the protection fund; after adjusting the impacted amount from $351.6 million to $388 million, the reason for the numerical change was explained; before confirming the attack vector, management refrained from prematurely concluding the attackers' identities or methods; once the investigation made progress, details regarding the third-party security product, zero-day vulnerability, high-level credentials, and forged withdrawal instructions were disclosed sequentially.

The same principle applied to the restoration of withdrawals.

This incident involved multiple assets and various networks, meaning the scope of investigation was not confined to a single wallet. Bitget did not restore all withdrawals at once; instead, they were opened in batches after verifying relevant wallets, networks, and eliminating risks one by one.

On September 26, the platform published a specific restoration timeline: BTC on September 28, ETH and related networks on September 29, USDT and related networks on September 30, with other tokens, fiat services, and C2C functions scheduled for October 2. All have been verified as restored on schedule prior to publication.

image

Considering this was a major security breach involving multiple assets, various networks, third-party software, and internal permissions, providing a precise date-and-time restoration plan upfront and then fulfilling it item by item is certainly commendable.

The protection fund was prepared four years in advance and deployed when absolutely necessary; management continuously engaged with the community; confirmed information was published promptly, while unconfirmed details saw no rushed conclusions; the restoration plan offered explicit timelines, which were then executed accordingly.

This series of crisp, decisive actions have prompted many to view Bitget more favorably.

Turning Point Emerges as Capital Returns to Net Inflows

After ETH withdrawals resumed on September 29, a noteworthy change quickly emerged on-chain.

image

According to on-chain analyst Ai Yi, Bitget's relevant hot wallets prepared for ETH withdrawals saw their balances rebound to above 30,000 ETH—exceeding initial levels—within half an hour of the reopening.

Data subsequently released by Bitget showed that in the first hour after withdrawals resumed, approximately 9,674 ETH flowed in while about 9,023 ETH flowed out, resulting in a net inflow of roughly 651 ETH. Data from September 30 indicated that 24-hour platform fund inflows reached $231 million, closely approaching the daily average inflow of $245 million recorded in August this year. Rather than experiencing the one-way capital exodus previously feared by the market, signs of recovering confidence were evident.

Meanwhile, to reward user trust, Bitget also launched a series of incentive campaigns.

image

The ETH PoolX campaign offers a 500,000 USDT prize pool, where participants can earn allocations simply by staking ETH. Early promotional materials projected an estimated APR of around 37.11%, which dynamically decreased as participating capital increased.

The BTC PoolX campaign subsequently went live, offering a 100,000 BGB prize pool with additional bonuses based on users' BTC holdings over the preceding 15 days.

For stablecoins, Bitget simultaneously rolled out flexible savings campaigns for USDT and USDGO, supporting instant deposits and withdrawals, with limited-time APYs reaching 10% and 12%, respectively. The "Peer Plan" allocates 30% of eligible trading fee revenue during the campaign period into a user prize pool, distributed with 60% weighted by trading volume and 40% by asset holding. On October 2, official Bitget data showed that the first wave of rewards had been disbursed, totaling 1,907,455 USDT distributed to 763,543 users.

The intent behind these campaigns is not difficult to understand. Restoring withdrawals addressed the question of whether users "could leave," while the subsequent series of initiatives aimed to restart trading, yield farming, and capital accumulation.

Soon, many users voted with their capital, demonstrating confidence in Bitget and enthusiasm for the campaigns.

image

A few days ago, the market's primary concern was still "when will funds be withdrawable"; now that withdrawals have resumed, the conversation has shifted to "which campaign yields a higher APR."

A clear signal that the incident has reached its turning point.

For an exchange, the most direct proof of restored user confidence is seeing individuals choose to keep their funds even when they can freely withdraw at any time.

What This Security Incident Left for the Exchange Industry

Following the Bitget incident, it received almost half of the industry's support.

The most noteworthy aspect of this involves Bybit.

In February 2025, Bybit suffered a security incident involving approximately $1.4 billion. Roughly five hours after the attack, Bitget provided Bybit with 40,000 ETH, worth over $100 million at the time. The 40,000 ETH carried no interest, required no collateral, and had no fixed repayment deadline. Bybit subsequently repaid the full amount within three days.

Over a year later, the roles have reversed. Following Bitget's incident, Bybit CEO Ben Zhou quickly and publicly expressed willingness to offer assistance, specifically noting: "When we were hacked, Bitget helped us." Subsequently, Bybit integrated the relevant stolen funds into the LazarusBounty system for tracking.

The list of supporters extends far beyond Bybit. CZ publicly voiced solidarity following the incident, and the Binance security team subsequently partnered with Bitget, including sharing threat intelligence, tracking stolen funds, and supporting asset recovery. MEXC CEO Vugar Usi also proactively contacted Bitget to express support. Beyond exchanges, Mandiant and SlowMist participated in the investigation and forensics, while Circle and Tether assisted in freezing relevant assets.

image

Reading these news items truly stirred my passion.

The cryptocurrency industry has never lacked competition. Exchanges battle for users, liquidity, and market share, but when facing a multi-hundred-million-dollar security crisis, peers inevitably band together for mutual support.

Whether a platform like Bitget has genuinely earned trust and respect within the industry becomes most apparent during moments of crisis.

Yet if this situation only remains at the level of "adversity reveals true loyalty," it undersells its significance.

The crypto industry lacks a centralized backstop institution, but protection funds, peer collaboration, security firms, and on-chain tracing are coalescing into their own risk management network. Meanwhile, as defensive perimeters expand from hot wallets and signature systems to third-party software and internal permissions, attacks grow increasingly complex, requiring industry-wide cooperation to counter them.

Establishing protection funds, maintaining post-incident transparency and honoring commitments, and fostering industry cooperation have now emerged as best practices for crisis management, which Bitget has diligently demonstrated.

image

Over the past two years, the crypto industry has constantly talked about Mass Adoption. ETFs, stablecoins, RWAs, and tokenized securities have drawn more traditional financial capital into the space, while the U.S. regulatory framework continues to take shape. Having reached this stage, the industry must prove not only its innovation and growth, but also its capacity to manage risk.

Bitget used this $400 million incident to test a platform's sense of responsibility in the face of a crisis. Crises may not destroy a platform, but accountability can redefine one.

For a crypto industry transitioning toward mainstream finance, this too is an examination that must be passed. No financial system can be built on the assumption that "nothing will ever go wrong." When a real crisis hits, whether one can afford to compensate, explain clearly, and recover effectively tests one's responsibility and bottom lines.

How the broader financial world ultimately views the cryptocurrency industry may very well depend on how correctly it handles a bad day.

Join the official Coincamps community:

X: https://x.com/coincamps

Telegram: https://t.me/coin_camps

Recommended

Hyperliquid will use $15 million USDC revenue for HYPE buybacks; buybacks will no longer rely solely on trading fees.

Oct 3, 18:27
Hyperliquid will use $15 million USDC revenue for HYPE buybacks; buybacks will no longer rely solely on trading fees.

Grayscale Zcash Spot ETF Sees $93.56M in Single-Week Redemptions: Honeymoon Period Turns Sharp, Once Held Nearly 3.5% of Supply

Oct 3, 16:41
Grayscale Zcash Spot ETF Sees $93.56M in Single-Week Redemptions: Honeymoon Period Turns Sharp, Once Held Nearly 3.5% of Supply

After resuming withdrawals, funds did not fall but rose instead. How did Bitget turn the situation around in five days?

Oct 3, 16:32
After resuming withdrawals, funds did not fall but rose instead. How did Bitget turn the situation around in five days?

SEC Clears 3x Leveraged Bitcoin and Ethereum ETPs: Listing Rules Approved, Trading Still Pending Activation

Oct 3, 16:22
SEC Clears 3x Leveraged Bitcoin and Ethereum ETPs: Listing Rules Approved, Trading Still Pending Activation

CryptoPunks Trading Volume Surges Nearly 12X in a Week: Rare Variants Sell for Millions Again, Market Rally Decoupled from ETH

Oct 3, 13:36
CryptoPunks Trading Volume Surges Nearly 12X in a Week: Rare Variants Sell for Millions Again, Market Rally Decoupled from ETH

From Xiaomi to Zhipu: The Q3 2026 Profitability Landscape for Chinese AI Model Vendors

Oct 3, 12:55
From Xiaomi to Zhipu: The Q3 2026 Profitability Landscape for Chinese AI Model Vendors