What happened?
According to Bitget's initial security notice and subsequent incident summary, systems detected unauthorized transfers from part of the exchange's hot and warm wallet infrastructure across multiple chains at about 18:31 UTC on September 24.
Bitget says an attacker compromised a critical backend system, spoofed transaction data and triggered the authorization process. The company says the attack path was identified, the underlying vulnerability remediated and private-key compromise ruled out based on the investigation to date. Mandiant and SlowMist continue to support forensic review and tracing.
Why did the estimate rise from $351.6M to $387.5M?
The initial estimate was about $351.6 million. After further transaction classification, Bitget revised it to about $387.5 million, including Zcash- and TRON-related transfers not captured initially. The company says this was a more complete accounting, not a second drain after containment.
What was and was not affected?
| Area | Published status | Important context |
|---|---|---|
| Exchange hot/warm wallets | Part of the infrastructure had unauthorized transfers | Remediation is reported complete; forensics continue |
| Cold wallets | Bitget says they were unaffected | This remains a company disclosure rather than something users can prove from an account balance |
| User ledger balances | Bitget says they were unaffected | A displayed balance and immediate withdrawal availability are different questions |
| Bitget Wallet | Reported unaffected | It uses separate self-custodial infrastructure |
| Withdrawals | Phased restoration | Availability varies by asset and network |
Withdrawal restoration schedule
Bitget's published schedule lists BTC on September 28 at 08:00 UTC, ETH on supported EVM networks on September 29, USDT on selected networks on September 30, and other tokens, fiat and P2P on October 2. This is a plan, not this site's guarantee. Users should rely on the authenticated withdrawal screen.
Direct impact on users
- Liquidity restriction: trading and displayed balances can remain available while funds cannot leave through a paused network.
- Operational errors: staggered reopening increases the chance of choosing the wrong network or resubmitting delayed requests.
- Phishing: fake compensation, expedited withdrawal and asset-migration messages exploit the event.
- Trust and cost: the market will assess restoration, investigation transparency, fund recovery and the economic cost of using the Protection Fund.
Impact on BGB and the exchange industry
BGB is closely tied to expectations for the Bitget ecosystem, so an exchange security event can raise volatility and cause the market to reprice platform, regulatory and protection-fund risk. Even if users are made whole, remediation, tighter controls and reputation repair can affect the business.
The broader lesson is that cold storage and multisignature controls do not by themselves solve a compromised transaction-construction or backend authorization system. Exchange security must protect the complete route from transaction data and approvals to signing and withdrawal restoration.
Five things to monitor
- Whether each network reopens and real test withdrawals settle normally.
- Whether a full forensic report explains the entry point and failed controls.
- Freezing, tracing, recovery and bounty progress.
- Protection Fund replenishment and updated reserve disclosures.
- Any further unauthorized transfer or service restriction.
Practical next step: the Bitget user safety and withdrawal checklist.