The perpetrator behind the $388 million exploit of Bitget executed a pair of minor test transactions thirty minutes prior to emptying the platform, as stated by Chief Executive Officer Gracy Chen.
During a discussion with Gareth Jenkinson of The Block, Chen explained that the initial illicit transactions took place at 6:31 p.m. UTC on September 24, consisting of 0.184 ETH originating from an Ethereum hot wallet alongside 193 TRX from a Tron hot wallet. Both amounts remained underneath the platform’s automated risk-management limits, generating zero system warnings.
Roughly half an hour later, the hacker initiated substantial transfers. Chen noted that 17 distinct transactions spanning Ethereum, XRP, Zcash, BNB Chain, Base, Arbitrum, Optimism, and Avalanche executed between 6:58 p.m. and 8:09 p.m. amassed approximately $361 million worth of digital assets.
Bitget’s auditing mechanism identified a major imbalance just seven minutes after the initial large movement, specifically at 7:05 p.m., prompting the security architecture to halt user-facing withdrawals across the entire exchange, according to the chief executive.
How the attacker gained access
Nevertheless, the culprit had already secured entry to an administrative backend by leveraging an unpatched zero-day vulnerability residing in an external security software, Chen pointed out. This vulnerability enabled them to inject unauthorized withdrawal instructions straight into wallet-associated backend infrastructure, leading the system to process them as authentic.
The hacker subsequently erased the logs generated by the malicious instructions, Chen explained, making it more difficult for Bitget to reconstruct the timeline of events.
“It’s also, in my opinion, the trickiest part,” Chen remarked, commenting on the removal of audit logs.
Bitget has confirmed that private keys and cold storage devices remained untouched. The trading platform is collaborating with Mandiant and SlowMist regarding the ongoing inquiry and anticipates releasing an official post-mortem document within the week.
Regarding the identity of the perpetrators, Chen stated: “It’s still the same group of people that we suspect,” withholding specific names pending the official release of the incident report.
Bitget’s user protection reserve, valued at $465 million as of September 25, will cover the entire deficit. Chen indicated that the pool will be restored to no less than $300 million within seven days utilizing corporate funds, which totaled upwards of $1.4 billion according to an August 31 audit.
“An incident like this scale is very serious,” Chen mentioned. “But serious doesn’t mean existential.”
In the interim, Bitcoin withdrawals recommenced on Monday, successfully clearing over 3,000 BTC during the initial sixty minutes. Ethereum withdrawals are scheduled to launch on September 29.
Originally published at https://www.theblock.co/news/regulation/2026-09-28-bitget-attacker-tested-risk-controls-small-transfers-388-million-theft-ceo-says-417045.