Bitget Restores Withdrawals After $388 Million Security Breach
Bitget began a phased restoration of user withdrawals following a $388 million theft attributed to sophisticated, potentially state-backed attackers.
Bitget began a phased restoration of user withdrawals on September 28 after a security breach on September 24 resulted in the theft of approximately $388 million. The attackers exploited a third-party security product to obtain internal credentials and bypass risk controls. Bitcoin withdrawals resumed first, followed by Ethereum on September 29 and USDT on September 30, with all other services expected to return by October 2.
CEO Gracy Chen requested that the decentralized protocol THORChain freeze attacker addresses, but the protocol refused, stating its mechanisms are not designed to selectively freeze individual funds. Following this refusal, a hacker wallet used THORChain to swap 2,390 ETH for 75.2 BTC. While stablecoin issuers Tether and Circle froze roughly $318,013 and NEAR Intents blocked over $50 million, Chen expressed skepticism about full recovery, citing a previous Bybit hack where only 3.5% of funds were recovered after a year.
Bitget characterized the attackers as sophisticated and state-backed, with preliminary investigations into VPN IP addresses suggesting North Korean involvement, though the exchange has not ruled out an inside job. The company stated that losses will be covered by its User Protection Fund and has launched a bounty program offering 5% for recovered funds.