Cryptocurrency investors rushed to withdraw more than 4,000 bitcoins—worth over $334 million at current market prices—within a single hour after centralized exchange Bitget officially resumed customer withdrawals following a major security breach.
The frantic rush of outflows occurred immediately after the platform opened its doors back up to user transactions, according to statements made by company leadership. Bitget CEO Gracy Chen detailed the timeline of the post-hack panic during an interview with Bloomberg Television on Tuesday, noting that while the initial hour saw heavy outflows, withdrawal activity has since stabilized significantly across the platform.
The resumption of services follows a devastating cyberattack last week that saw hackers make away with approximately $388 million in digital assets after successfully compromising the Victoria, Seychelles-based exchange’s hot wallets. The breach immediately triggered a freeze on all customer funds as blockchain analytics firms and security researchers flagged unusual outflows leaving the platform.
"The withdrawals actually stabilized a lot today," Chen told Bloomberg Television, addressing the immediate wave of user redemptions. "Those hundreds of millions [in bitcoin withdrawals] actually most of them happen on the first hour of the withdrawal restart."
In a public statement shared on the social media platform X on Monday, Chen provided a more granular breakdown of the initial market reaction, revealing that the platform processed 9,585 distinct withdrawal orders totaling 4,098 bitcoins during the initial reopening phase. To manage liquidity and safeguard remaining assets while restoring full operational capacity, the exchange has implemented a phased approach, allowing customers to withdraw their funds progressively rather than all at once.
The security incident came to light after on-chain investigators noticed suspicious transaction patterns leaving Bitget’s infrastructure. In the wake of the discovery, the exchange swiftly halted all customer withdrawals to contain the damage and launched an internal investigation alongside external cybersecurity experts.
Following preliminary forensics, Bitget publicly stated that the methodology employed in the cyberattack was "highly consistent with known patterns of North Korean hacker organizations." State-sponsored cybercrime syndicates linked to Pyongyang have developed a notorious reputation within the global financial and cryptocurrency sectors, frequently targeting digital asset exchanges, decentralized finance protocols, and blockchain infrastructure projects to fund state operations. These groups are widely recognized by cybersecurity professionals as some of the most sophisticated and persistent threat actors operating in the digital landscape today.
Detailing the exact vector of the breach, Chen clarified that the exchange’s secure offline reserves remained entirely untouched and secure. The attackers did not manage to breach cold storage facilities, which typically hold the vast majority of an exchange’s user funds offline and away from internet connectivity. Instead, Chen explained that the threat actors "exploited vulnerabilities from third-party products to steal internal credentials, then used those credentials to send fraudulent withdrawal commands that bypassed our risk controls."
The breach inevitably took a heavy toll on the exchange’s financial safety reserves. Chen confirmed that the company is actively utilizing its own corporate capital to top up its dedicated protection fund after the pool experienced a sharp decline in size following the incident. According to Bloomberg reports, the protection fund plummeted to below $200 million in the wake of the attack, a steep drop from its pre-hack standing of $464 million.
Despite the severity of the breach and the subsequent financial impact, Bitget leadership emphasized that the platform has maintained an otherwise unblemished security record for nearly a decade. The company noted in official communications that this incident was the first "security incident of this nature in eight years" of commercial operations.
"The incident remains contained, and no further unauthorized transfers are possible," the exchange reiterated in a formal support advisory published on its direct portal.
Bitget stands as a major player in the global cryptocurrency derivatives and spot trading markets. According to data tracked by CoinGecko, the platform currently ranks as the sixth-largest cryptocurrency exchange by trading volume, having processed approximately $811 million in transactions over a recent 24-hour period. The exchange maintains a substantial user base, with the vast majority of its customers primarily located across Asian markets.
As the exchange works to restore complete normalcy to its operations, rebuild its security reserves, and process the remaining phased withdrawal requests, the incident serves as another stark reminder of the persistent cybersecurity vulnerabilities facing centralized financial platforms and the evolving sophistication of state-backed hacking syndicates operating within the digital asset ecosystem.
Leave a Reply