Bitget pins $388M exploit on third-party security product as BTC withdrawals resume
By Crypto Wire
September 28, 2026
Bitget put a fresh method statement on the wire the same morning phase-one BTC withdrawals were due. In remarks shared with The Block and published about 08:31 UTC September 28, the exchange said it has started processing BTC withdrawals on the Bitcoin network at 08:00 UTC Monday as scheduled—and, for the first time in this desk’s watchlist chapters, named how the September 24 drain allegedly got through: a vulnerability in a third-party security product that yielded high-level internal credentials, then fraudulent withdrawal commands that bypassed risk controls. This UPDATE links the live reopen beat (9902) rather than silent-editing that URL.
What The Block piece adds beyond the schedule. Bitget told the outlet that at about 18:31 UTC September 24, unauthorized transfers of certain assets ran across multiple networks from hot and warm wallet infrastructure. The attacker, per Bitget’s wording relayed by The Block, targeted a vulnerability in a third-party security product used by the exchange “to obtain high-level internal credentials,” then “used these credentials to send fraudulent withdrawal commands to the wallet system, causing it to execute abnormal transfers that bypassed risk controls.” Bitget still says private keys were not compromised and that user balances and cold wallets were not affected—company claims attributed through The Block, not an independent key audit.
Containment and cover math, as stated. The exchange said it has patched the vulnerability, contained the incident, and seen no further unauthorized transfers, while confirming about $388 million in stolen assets—the figure The Block frames as the largest reported crypto theft so far this year versus other 2026 incidents it names. Losses, Bitget said, will be fully covered by the Bitget User Protection Fund, which holds 5,500 BTC. A 5% bounty remains for parties whose actions directly freeze or recover attacker funds. Bitget also said it will review how it assesses and deploys third-party security products, with Mandiant and SlowMist assisting the investigation. On attribution, The Block notes Bitget will not speculate until the probe is firm, while describing attackers as “sophisticated” and “state-backed”; earlier media briefings citing a North Korea suspicion stay labeled as prior company speculation, not a new forensic conclusion in this statement.
Why this is a Rug Room UPDATE, not a rehash of 9902. Chapter 9902 established the operational toggle: Bitget’s published 08:00 UTC BTC Bitcoin-network slot plus route monitors showing native BTC withdrawals Open. The Block chapter’s new fact is the credential-path method—third-party security product → internal credentials → fraudulent withdrawal commands—plus the same-morning company confirmation that BTC processing had started on schedule and that the ~$388 million total stands with Protection Fund cover claimed. Asset mix in the latest statement was not re-listed; The Block points back to its earlier reporting that ether, USDT, USDC, AVAX, and BNB were among transfers. Do not invent vendor names Bitget did not publish.
Calendar unchanged after the method dump. Bitget told The Block each chain must pass security checks before reopen, which is why restoration stays staged. After Monday’s BTC step: ETH on Ethereum, BSC, Arbitrum, Base, and Optimism at 08:00 UTC September 29; USDT on Ethereum, BSC, Solana, and Tron the next day at the same clock; remaining assets, fiat, and P2P on October 2. NFT and collector desks still care because Bitget is a major fiat/crypto on-ramp for traders who also bid floors—operational risk on withdrawal rails is Rug Room beat, not side gossip. Trail hops (THORChain / Wasabi and related freezes) stay on the sibling THORChain / Wasabi tracker; this chapter is method + BTC-phase confirmation only.
What not to invent: that Bitget named the third-party vendor in this statement; that private-key compromise is proven (Bitget denies it); that every account can withdraw without queue or KYC friction; that ETH or USDT already reopened; that the 5,500 BTC Protection Fund balance has been independently audited for this desk; or that “state-backed” equals a closed attribution. Stick to The Block’s September 28 write-up of Bitget’s statement, the scheduled BTC processing claim, the third-party credential path quote, the ~$388 million confirm, and the remaining Sep 29 / Sep 30 / Oct 2 rungs. Solana Alpenglow still lacks a confirmed mainnet-live primary for tracker 9852 on this tick, so the desk takes the Bitget method UPDATE that printed inside the window.
Bottom line: Bitget’s statement to The Block confirms phase-one BTC withdrawals are processing as scheduled and newly frames the ~$388 million September 24 drain as a third-party security-product credential attack that bypassed risk controls—Rug Room UPDATE on the Bitget hack & withdrawals tracker after 9902.
Disclaimer: This article is provided for informational and educational purposes only. It does not constitute financial, investment, legal, or trading advice. The NFT market is highly volatile, and past performance is not indicative of future results. Readers should conduct their own research and consult qualified professionals before making any decisions related to digital assets. The cover image for this article may have been created using artificial intelligence (AI).
