Bitget has now put a clearer attack path on the record for the September 24 breach that moved about $388 million out of part of its hot and warm wallet stack. In its own incident explainer and in CEO Gracy Chen's Monday livestream remarks reported by U.Today and The Hacker News, the exchange says the attacker used a vulnerability in a third-party security product to grab high-level internal credentials, then fed fraudulent withdrawal commands into wallet backends that treated them as legitimate. Cold wallets were not hit, and Bitget says private keys were not compromised.
That detail matters if you trade or custody on Bitget this week. BTC withdrawals already reopened at 08:00 UTC on September 28. ETH is on the September 29 slot across Ethereum, BSC, Arbitrum, Base, and Optimism, with USDT on September 30 and other tokens plus fiat and P2P on October 2, per Bitget's published schedule.

How the $388M moved, in one clock
Bitget's academy timeline and Chen's U.Today-reported breakdown line up on the same sequence. We collapsed the public timestamps into one table:
| UTC time (Sep 24–29) | What Bitget says happened |
|---|---|
| Sep 24, 18:31 | Two small test transfers: 0.84 ETH and 93 TRX, under the risk-control threshold |
| 18:58–20:09 | 17 larger transfers across ETH, XRP, ZEC, BSC, Base, Arbitrum, Optimism, Avalanche (~$361M) |
| 19:05 | Reconciliation flags a discrepancy; platform withdrawals auto-blocked |
| 19:14 / 19:40 | P0 emergency response; containment begins |
| 20:40 | Funds moved toward cold wallets while private-key compromise was still possible |
| 20:55–21:23 | Second wave of seven transfers (~$30M) |
| 21:44 | Withdrawal and signing services shut down |
| Sep 25 | Root cause identified; law enforcement notified |
| Sep 28, 08:00 | BTC withdrawals reopen (Bitcoin and BSC) |
| Sep 29, 08:00 | ETH withdrawals scheduled to reopen |
Own math on the published waves: $361M + $30M = $391M, which sits next to Bitget's reconciled ~$388M estimate across 12 hot/warm addresses and 11 chains. The detection lag from the first large transfer (18:58) to the auto-block (19:05) is seven minutes. From the first test transfer to full signing shutdown is 18:31 to 21:44, or 3 hours and 13 minutes. Those are Bitget's clocks, not an outside forensic firm's.

The Hacker News summary adds the operational shape: the flaw opened an internal management system, then fake withdrawal commands rode the normal approval path. Chen, quoted via U.Today, said the attackers used legitimate credentials and tried to erase traces while looking like routine admin work. Bitget has not named the third-party product. Mandiant and SlowMist are on the forensic and tracing work, and Bitget says a formal security report is due this week.
Coverage math and what users should do
Bitget says customer account balances were not reduced by the theft and that its User Protection Fund will cover the loss. U.Today reports Chen putting the fund above $464 million. Against a ~$388 million hit, that is about $76 million of headroom before replenishment ($464M − $388M = $76M), and Chen said the fund would be restored above $300 million in USDT or equivalent within a week of being used. Bitget also cites a Proof of Reserves ratio around 127%, which it treats as separate from the Protection Fund.
On the recovery side, Bitget published attacker addresses, offered a 5% bounty on frozen or recovered funds under program rules, and says some assets are already frozen through industry partners. The Hacker News notes TRM Labs saw wallet overlaps consistent with prior North Korea-linked laundering patterns, while Bitget itself is not locking a public attribution until the formal report.
Geeknewz's view: if you hold funds on Bitget, the practical checklist is narrow. Confirm your asset is on the reopen calendar before you need an urgent withdrawal. Do not chase unofficial "support" DMs during a breach week. Treat the Protection Fund claim as the exchange's commitment, then watch whether the formal Mandiant/SlowMist report and the replenishment to $300M+ both show up on the promised clock. The lesson for the wider market is uglier than a stolen key: a vendor flaw plus trusted internal credentials was enough to walk hot and warm rails while cold storage stayed intact.
Sources: Bitget security incident explainer; The Hacker News; U.Today (Chen livestream details).
