Bitget Sees $463M Net Outflow in Single Day After $388M Hack
nashnova research
Crypto exchange Bitget recorded a $463 million single-day net outflow on Tuesday — the largest in four years of DefiLlama tracking — after hackers stole $388 million last week; its protection fund has dropped below $200 million, and user trust now hinges on how fast the exchange can rebuild it.
What does a $463 million single-day outflow mean?
Bitget saw roughly $463 million in net outflows on Tuesday — the largest single-day figure in four years of DefiLlama's proof-of-reserves tracking.
The exchange currently holds about $5.7 billion in reserves; this outflow exceeds 10% of that total.
This means → the hack has triggered a clear trust crisis — users are voting with their feet, pulling funds at speed.
How did the hackers get in?
Attackers exploited a vulnerability in a third-party security product to obtain internal credentials, then sent fraudulent withdrawal instructions to Bitget's wallet system.
Those instructions bypassed existing risk controls and caused abnormal transfers totaling roughly $388 million.
In plain terms = the hackers did not brute-force Bitget's own system — they found a "key" at an outside vendor and used it to impersonate legitimate operations.
Only parts of the hot-wallet (online) and warm-wallet (semi-online) infrastructure were affected. Private keys and cold storage (offline) were not compromised.
Is the protection fund still adequate?
Bitget's user protection fund was previously reported at $464 million; it has now fallen below $200 million — it is absorbing the financial impact of the breach.
CEO Gracy Chen has pledged to replenish the fund with the company's own capital, targeting above $300 million within one week.
This means → the fund has been more than half depleted by this single incident; how quickly it is rebuilt will directly shape whether users choose to stay.
When will full withdrawals resume?
Bitget is restoring withdrawals in phases: Bitcoin first on Monday, then Ethereum and USDT.
Other tokens, fiat, and peer-to-peer services are scheduled to resume on October 2.
The company says the phased approach is a security measure and "unrelated to the sufficiency or availability of user assets."
Was North Korea behind the attack?
Bitget is working with Google's cybersecurity unit Mandiant and blockchain security firm SlowMist on the ongoing investigation.
CEO Chen previously cited preliminary indicators of North Korean involvement; external researchers reached similar conclusions.
But she remains cautious on final attribution: "These indicators are still being evaluated and should not be treated as definitive attribution."
This reflects a broader reality — tracing large-scale crypto security incidents often takes weeks or months, and it is too early to draw firm conclusions.
市场有风险,内容仅供研究参考,不构成投资建议。
