Bitget's CEO has publicly detailed the cause of a significant security incident that resulted in a large loss of funds. The executive said the breach stemmed from a vulnerability tied to third-party security products rather than a flaw in Bitget's own core infrastructure.
Reported figures for the theft vary slightly by source, with some placing the loss at $380 million and others at $388 million. Both figures point to the same incident, and the discrepancy likely reflects differences in how the loss was calculated or valued at the time of reporting.
According to details shared by the CEO, the attacker did not move directly to a large-scale withdrawal. Instead, the person or group behind the exploit reportedly tested the exchange's risk controls first. Small transfers were made before the larger theft occurred, according to the account given by Bitget's leadership.
This pattern suggests a degree of reconnaissance on the part of the attacker. Testing withdrawal limits and monitoring systems with smaller amounts is a technique sometimes used to probe for gaps in automated fraud detection before attempting a larger extraction of funds.
Bitget has since resumed Bitcoin withdrawals, according to reporting on the incident. The restoration of withdrawal services suggests the exchange has taken steps to address the identified vulnerability and stabilize its systems following the breach.
The incident adds to a long list of security failures tied to third-party integrations across the cryptocurrency industry. Exchanges routinely rely on external vendors for wallet infrastructure, risk monitoring, and other security-adjacent services. When those third-party systems contain flaws, the exposure can extend well beyond the vendor itself and directly affect user funds held on the platform.
Bitget has not been named in prior reports as facing a breach of this scale, making this incident notable both for its size and for the specific attack pattern described by the CEO. The exchange's public disclosure of technical details, including the alleged testing behavior by the attacker, is intended to provide transparency to users and the broader market following the loss.
Market Impact
A theft of this magnitude at a major exchange typically raises questions among users and institutional partners about custody practices and reliance on third-party security vendors. The resumption of Bitcoin withdrawals may ease some immediate concerns among Bitget users, though the broader financial and reputational impact of the incident will likely take longer to assess.
The disclosure also reinforces ongoing scrutiny across the exchange sector regarding third-party risk. Other platforms may face renewed pressure to audit vendor relationships and internal risk controls in light of the attack pattern described, particularly the use of small test transfers to probe system defenses before a larger exploit.
Bitget's disclosure offers a clearer picture of how the breach unfolded, even as reported dollar figures for the theft continue to vary slightly across accounts. Further details may emerge as the exchange and outside investigators continue reviewing the incident.
Frequently Asked Questions
How much was stolen in the Bitget hack?
Reports differ slightly, with figures ranging from $380 million to $388 million describing the same incident.
What caused the Bitget security breach?
Bitget's CEO said the theft resulted from a vulnerability tied to third-party security products used by the exchange, rather than a flaw in its own core systems.
Did the attacker attempt anything before the large theft?
According to Bitget's CEO, the attacker made small test transfers to probe the exchange's risk controls before carrying out the larger theft.
Are Bitget withdrawals working again?
Yes, reporting indicates Bitget has resumed Bitcoin withdrawals following the security incident.