Bitget Bounces Back: From $388M Exploit to Net Inflows in Five Days
TREE NEWS reports: On September 25, Bitget suffered a security breach that resulted in approximately $388 million in assets being affected. The attack exploited a zero-day vulnerability in a third-party security product, allowing hackers to forge withdrawal commands without compromising private keys or cold wallets. Within days, the exchange restored withdrawals, replenished its user protection fund, and saw net inflows return—a remarkable turnaround that offers lessons for the entire crypto industry.
The Attack: A New Frontier in Exchange Security
The breach was not a typical private key leak or smart contract exploit. Instead, attackers infiltrated a third-party security product, stole internal credentials, and bypassed risk checks to execute unauthorized transfers across multiple chains including Ethereum, BNB Chain, and Arbitrum. The exchange’s reconciliation system detected anomalies within minutes, triggering an immediate halt of withdrawals and a highest-level emergency response. Investigations by Mandiant and SlowMist confirmed the root cause: a previously unknown zero-day vulnerability in the third-party infrastructure.
This incident underscores a critical shift: exchanges must now defend not only their hot and cold wallets but also every third-party service that touches their core systems. The attack surface has expanded, and traditional security perimeters are no longer sufficient.
The Response: A Pre-Positioned Safety Net
Bitget’s handling of the crisis was anchored by its User Protection Fund, established in 2022 with a baseline of $300 million. At the time of the hack, the fund held 5,500 BTC worth over $464 million—more than enough to cover the losses. The exchange immediately committed to covering all affected assets, ensuring no user balances were impacted. By September 30, the fund was replenished to its $300 million baseline, as promised.
Withdrawals resumed on a staggered schedule: BTC on September 28, ETH on September 29, and USDT by September 30. Notably, after ETH withdrawals reopened, the relevant hot wallet saw net inflows within 30 minutes, with balances exceeding pre-incident levels. The first hour after ETH withdrawal resumption saw 9,674 ETH inflow versus 9,023 ETH outflow—a net positive of 651 ETH. By September 30, 24-hour platform inflows reached $231 million, close to the August daily average of $245 million, signaling restored confidence.
Industry Implications: Collaboration Over Competition
The crypto industry’s response was equally noteworthy. Bybit, which suffered a $1.4 billion hack in February 2025, offered support, recalling Bitget’s own $100 million ETH loan during that crisis. Binance shared threat intelligence, Circle and Tether assisted with asset freezing, and security firms Mandiant and SlowMist conducted forensic investigations. This collective action highlights a maturing risk-response network that transcends competition.
Bitget also launched a series of incentive campaigns—ETH and BTC PoolX staking, stablecoin yield products with up to 12% APR, and a fee-sharing program—to encourage users to keep funds on the platform. The first batch of rewards distributed 1.9 million USDT to over 763,000 users.
Forward-Looking: Redefining Crisis Management
Bitget’s recovery demonstrates that a well-prepared protection fund, transparent communication, and industry collaboration can turn a potential catastrophe into a trust-building event. As crypto moves toward mass adoption, the ability to handle bad days will be as important as innovation. The exchange’s five-day turnaround sets a new benchmark for crisis response—one that other platforms would be wise to study.




