Bitget Says Third-Party Vulnerability Caused First Security Incident in Eight Years
The exchange said losses fall within its user protection fund, while private keys and cold wallets were not affected.

Bitget said a vulnerability in a third-party security product caused its first security incident in eight years, with losses covered by the exchange’s user protection fund.
Bitget CEO Gracy said attackers obtained internal access credentials through the vulnerability and used them to send fabricated withdrawal commands to the wallet system. The commands bypassed risk checks and triggered abnormal transfers.
Private keys were not exposed, and cold wallets were unaffected, Gracy said. Bitget said the verified losses remain within the protection fund’s coverage and that user funds are safe.
The exchange said it has more than $1.4 billion in its own funds, including about $464 million in the user protection fund. It plans to replenish the fund to more than $300 million within a week.
Bitget said a detailed security report will provide additional technical information.


