Technology
Cointelegraph.com News

Bitget ‘gradually back to usual’ as protection fund reaches $309M

Source Entity

Cointelegraph by Turner Wright

October 2, 2026
Bitget ‘gradually back to usual’ as protection fund reaches $309M

Bitget is recovering from a $388 million hack linked to a zero-day exploit identified by SlowMist. While September saw record crypto theft, Bitget is utilizing its $309 million protection fund to restore user operations.

The Bitget Breach: A Deep Dive into the September Crypto Crisis

The Anatomy of an Exploit

The recent $388 million theft from the Bitget cryptocurrency exchange stands as a stark reminder of the systemic vulnerabilities present in the digital asset ecosystem. Security firm SlowMist has traced the origins of this breach back to August 31, identifying a sophisticated attack path that leveraged a zero-day vulnerability. By compromising a third-party security product, the attackers gained unauthorized access to internal databases through a hidden script. This initial foothold allowed them to manipulate wallet application hosts, setting the stage for the massive extraction of funds that occurred on September 24.

The Role of Third-Party Vulnerabilities

A critical aspect of this incident is the reliance on external security products. SlowMist’s investigation highlights how an attacker can bypass traditional perimeter defenses by exploiting vulnerabilities within the software supply chain. By targeting "Product A" and manipulating its database access, the perpetrators demonstrated that even exchanges with robust internal protocols can be compromised if their integrated third-party tools are flawed. This underscores a broader industry trend where the security posture of an exchange is only as strong as its weakest integrated dependency.

Operational Recovery and the Protection Fund

Following the breach, Bitget has moved toward a gradual restoration of services. CEO Gracy Chen confirmed that the exchange’s 'Protection Fund,' established in early 2022, has been instrumental in absorbing the financial impact of the $388 million loss. With the fund currently valued at approximately $309 million, the exchange has begun resuming withdrawals for various tokens, including BTC, ETH, and USDT. This mechanism serves as a crucial case study for how centralized exchanges can maintain liquidity and user trust following catastrophic security failures.

A Record-Breaking Month for Cybercrime

The Bitget incident was not an isolated event but rather the centerpiece of a record-breaking month for illicit activity. September 2026 saw total crypto-related losses estimated between $766 million and $768 million, according to data from security firms PeckShield and CertiK. The month saw 55 to 97 major incidents, including the $320 million Liquid Network hack. While a significant portion of the Liquid Network funds were eventually returned, the sheer scale of the Bitget breach solidified September as the most damaging month of the year for the sector.

Future Trends and Security Implications

Looking forward, the industry is likely to face increased scrutiny regarding the vetting of third-party software vendors. The success of the Bitget attack, which relied on pre-existing vulnerabilities, suggests that exchanges must adopt more rigorous auditing processes for any external integration. As the total value locked in decentralized and centralized finance continues to grow, the sophistication of these zero-day exploits will likely accelerate, necessitating a shift toward more resilient, decentralized security architectures that do not rely on single points of failure.

Multiple Citing Sources

Verification Required?

Read the full report from the primary source

Go to Cointelegraph.com News