Bitget Traces Sept. 25 Attack to Third-Party Security Tool
The exchange said attackers used stolen internal credentials to forge withdrawal commands, while private keys and cold wallets remained unaffected.

Bitget said its Sept. 25 attack was traced to a vulnerability in a third-party security product, with attackers using stolen internal credentials to forge withdrawal commands and bypass transaction controls.
CEO Gracy Chen said the incident did not expose private keys and did not affect cold wallets. Bitget also said its internal review found no evidence of insider involvement, while a formal security report will provide additional technical details.
The exchange said it isolated affected servers, invalidated and reissued internal credentials, tightened access to sensitive permissions and added multiple-approval requirements for critical operations. Withdrawals must also pass independent checks before being processed.
Bitget said its $464 million user protection fund covers the reported losses and that user assets remain secure. Bitcoin (BTC) withdrawals began reopening in batches on Sept. 28, with other chains and assets to follow after separate verification. The company said the staged process reflects the need to complete checks across the affected networks.


