Loading market data...

Bitget CEO Details $388 Million Security Breach, Says BTC Withdrawals Have Resumed

Bitget CEO Details $388 Million Security Breach, Says BTC Withdrawals Have Resumed

Bitget CEO Gracy Chen has provided a detailed account of a security incident that unfolded on Sept. 24, revealing that an attacker obtained internal credentials and initiated approximately $388 million in unauthorized transfers. In a statement, Chen confirmed that BTC withdrawals have since resumed as the exchange moves to contain the fallout.

How the breach happened

According to Chen's account, the attacker gained access to internal credentials — the kind of login details that are supposed to stay behind layers of security. With those credentials in hand, the attacker initiated a series of unauthorized transfers totaling roughly $388 million. The exact method used to obtain the credentials hasn't been disclosed, and it's not clear whether the breach came through a phishing campaign, an insider, or a compromised system.

What is clear is the scale: $388 million is a significant sum even by the standards of crypto exchange incidents, which have grown larger and more frequent in recent years.

Withdrawals resume after brief halt

BTC withdrawals have resumed following the incident, according to Chen's update. That's a key operational marker — when an exchange halts withdrawals, it usually means the security team is assessing the damage and patching whatever hole allowed the breach. Resuming BTC withdrawals suggests Bitget has regained enough confidence in its systems to let users move their funds again, at least for bitcoin.

Chen did not say whether other assets were affected or whether withdrawal limits remain in place. The exchange hasn't publicly detailed how much of the $388 million has been recovered, if any.

What we still don't know

Several critical questions remain unanswered. The facts provided don't specify whether the unauthorized transfers were fully executed or partially blocked, nor whether any customer funds were ultimately lost. The identity of the attacker — or attackers — hasn't been revealed. And there's no word on whether law enforcement or regulators have been brought in.

Bitget also hasn't said whether it plans to reimburse users for any losses, or what specific security changes it's making in the wake of the breach. Chen's account was detailed on the timing and the dollar figure, but it left the operational and legal next steps vague.

The broader context

Exchange breaches have become a recurring feature of the crypto landscape, with attackers increasingly targeting internal credentials rather than trying to break through technical defenses. The Bitget case fits that pattern — no sophisticated smart contract exploit, just stolen login details used to move a large sum quickly.

For Bitget users, the immediate question is whether their funds are safe and whether withdrawals will remain open. The resumption of BTC withdrawals is a positive signal, but it doesn't answer whether other assets are similarly accessible or whether the exchange has fully closed the security gap.

Bitget hasn't announced a timeline for a full post-mortem or said when it might release more details. Until then, the $388 million figure and the resumption of BTC withdrawals are the main facts on the table — and users are left watching for the next update.