Bitget said it restarted Bitcoin withdrawals on September 28 after a breach that moved about $387.5 million from parts of its hot and warm wallet infrastructure. The exchange said its investigation with Mandiant and SlowMist traced the incident to a flaw in a third-party security product, not to private-key theft, and that cold wallets and user balances were unaffected.
Bitget said the supplier-side flaw handed attackers high-level internal credentials, which they used to send withdrawal commands that its risk controls treated as legitimate. In plain terms, the break was in the trust path that authorizes withdrawals, so controls aimed at protecting wallet keys did not stop the transaction flow.
For exchanges and custody platforms, the lasting lesson is that a hot-wallet incident can originate in a third-party control plane and still end up at the withdrawal layer. If a supplier can mint credentials your systems trust, the exposure can survive even when the key store itself is untouched.