On September 24, Bitget was forced to press the "emergency stop button" during a security incident involving multiple non-EVM chains and 10 cryptocurrencies, leading to a complete halt of platform withdrawals. The official statement emphasized that this was a safety measure implemented to prevent risk spread, not a signal that assets were no longer available, and clearly stated that user account balances were unaffected. To ease tensions both internally and externally, Bitget presented two key signals: firstly, the protection fund would cover the financial consequences of this security incident across the entire platform, meaning losses would be borne by the platform rather than users; secondly, withdrawals would not be resumed only after all issues were resolved, but instead a phased recovery approach would be taken. Starting from September 28, 8:00 (UTC), withdrawals for Bitcoin network would be reopened first, pulling the most core main channel back from a "locked" status to a "usable" status after completing preliminary safety verifications of the infrastructure. Through this series of statements, Bitget aimed to find a time and pace arrangement acceptable to the market while managing technical risks and restoring user trust.
Multi-chain Hit: Difficulty in Investigating Non-EVM and Ten Cryptocurrencies
According to Bitget's official statement, this security incident focused on multiple non-EVM chains and 10 cryptocurrencies, essentially triggering multi-chain infrastructure risks at the exchange level, rather than a single contract being compromised. For any centralized platform, this scenario means that the common EVM handling template of "finding the problematic contract, replacing the key, and partial restarting" cannot be applied. Instead, it requires returning to the very base layer of the linkage and asset mapping, verifying withdrawal paths, signature logic, and risk control thresholds chain by chain and currency by currency.
In practice, this directly raised the cost of coordination between technology and operations: the security team needed to verify the node environment and wallet systems for each non-EVM chain separately, while the operations team had to explain why Bitget chose to suspend all withdrawals without fully clarifying the risks, instead of only locking the chains or currencies that had confirmed anomalies. The official statement later stated that additional verification and security checks had been conducted on the withdrawal infrastructure, but until the investigation was completed, the withdrawal pace had to first come to an overall "emergency stop," followed by a phased recovery by network. This left some users' assets still stagnant in their platform accounts, temporarily losing the ability for cross-chain scheduling.
Phased Withdrawal Recovery: Why Prioritize BTC Network
On September 28 at 8:00 (UTC), Bitget chose to individually restart Bitcoin network withdrawals without releasing recovery timelines for other networks and cryptocurrencies. This left the first "unfreezing point" for the market's most recognized mainstream asset. Previously, the official had repeatedly stressed that the suspension of withdrawals was a safety measure unrelated to user asset availability, but when the incident was described as "involving multiple non-EVM chains and 10 cryptocurrencies," and details of the attack remained undisclosed, it was naturally interpreted that the priority unfreezing of BTC signified that its on-chain withdrawal path had undergone more thorough infrastructure validation. However, this judgment still rested at the level of risk assessment, rather than based on confirmed technical conclusions.
From the perspective of network characteristics, the UTXO model of the Bitcoin mainnet and its relatively simple on-chain protocol stack are generally seen as easier to delineate risk boundaries during audits, and allow for precise closure of certain withdrawal channels if necessary, without affecting the overall account system. This provided a technical rationale for the phased strategy of "first BTC, then others." The management team, including Xie Jiayin and CEO Gracy Chen, personally participated in the recovery arrangements—on one hand, by setting clear time points to respond to user anxieties about withdrawal certainty, and on the other hand, by only opening the BTC network, allowing resources for investigation to continue focusing on other affected links and currencies. This maintained a comprehensible compromise between user expectation management and risk control: enabling some funds to regain an on-chain exit, while retaining the ability to continue "closing gates" against still unclear attack surfaces.
Distinction in Theft Methods: Bitget vs. Bybit
Xie Jiayin deliberately recalled last year's Bybit security incident during external communications, yet emphasized that the method of theft for Bitget was different. This "difference" effectively delineated the industry's handling paths. He pointed out that precisely because the methods of attack differed, Bitget deliberately adopted a rhythm and plan that were different from Bybit in handling and recovering withdrawals: instead of replicating the commonly seen "one-time full restart" template, only Bitcoin network withdrawals were restored starting from September 28, while other links and currencies remained locked in the investigation phase, prioritizing thorough risk elimination over speed and scope.
In this comparative relationship, the method of theft was elevated as an upstream variable in decision-making, reflecting the exchange's different understanding of its own responsibility boundaries. Bitget, by actively mentioning Bybit, acknowledged that there was already a "reference" within the industry, while at the same time, with the phased recovery and the specific arrangement of only opening BTC, it explained to users that the current priority was to ensure all affected networks and withdrawal infrastructure completed additional verification and third-party security checks, rather than providing an open timeline that seemed favorable but might contain hidden dangers. Different attack paths ultimately reflect different communication languages used with users—whether to first state "everyone can withdraw" or "check thoroughly before withdrawing," also made this incident a clear example of the differentiation in security narratives among exchanges.
Involvement of Security Companies: Mandiant and SlowMist's Endorsement Competition
To enhance the credibility of "check thoroughly before withdrawing," Bitget, in addition to the internal investigation, opened a security investigation to two third parties with vastly different styles—Google's Mandiant, and SlowMist Technology. The former represents the traditional internet security system and large company endorsement, while the latter has long focused on on-chain scenarios, giving it a closer image of "on-chain native security" in the minds of crypto industry users. Bitget, on one hand, publicly emphasized that this event was a security incident for the entire platform and not an isolated incident for a specific business line, while on the other hand, it involved external institutions in the extra verification and security checks of withdrawal infrastructure, essentially submitting two "proofs" to different user tiers: reassuring those who value compliance and traditional security that the investigation possesses sufficient technical depth, while also allowing users accustomed to the on-chain context to see familiar security brands appear on the list.
In industry narratives, this collaborative investigation model has gradually become the default path after security incidents involving exchanges. A platform giving a sole conclusion of "risk eliminated" is difficult to convince all users when attack details remain undisclosed and affected addresses are not public. However, when the conclusion is endorsed by both the internal team and a third-party security company, its credibility and accountability are relatively enhanced. By simultaneously introducing Mandiant and SlowMist and packaging the verification process of withdrawal infrastructure into explicable steps to the outside, this incident, which essentially involved the exploitation of a security vulnerability at the exchange level, at least created a more transparent, externally verifiable investigation framework in terms of communication.
Rebuilding User Trust and New Normal of Exchange Security
From the complete suspension of withdrawals, to setting 8:00 (UTC) on September 28 as the initial reopening for Bitcoin network, and then involving Mandiant and SlowMist for investigation and verification, Bitget has deconstructed an exchange-level security vulnerability incident into a complete set of actions: "stem the bleeding—investigate—phased recovery." The officials continually reiterated two key signals: user account balances were unaffected, and the current withdrawal restrictions were due to safety considerations rather than asset unavailability; they also promised that the protection fund would cover the financial consequences of this event, and that the management team would jointly establish recovery arrangements with security companies. All of these point towards a new industry norm that emphasizes post-event compensation mechanisms and third-party audit endorsements. For broader multi-chain risk management, this incident is likely to reinforce platforms' emphasis on cross-chain asset paths, non-EVM network risk management, and independent security assessments. However, with the amounts stolen, the complete list of affected cryptocurrencies, and technical details still undisclosed, the only actions the outside can truly verify include: whether Bitget will provide more detailed technical and process information after the investigation concludes, whether there will be a clear and executable timeline for the recovery rhythm of non-BTC networks and other cryptocurrencies, and whether the user communication mechanism can evolve from post-event reassurance to a standardized and predictable response procedure for anomalies.
Join our community to discuss and become stronger together!
AiCoin Exclusive Hyperliquid Benefits: https://app.hyperliquid.xyz/join/AICOIN88
AiCoin Exclusive Aster Benefits: https://www.asterdex.com/zh-CN/referral/9C50e2
On-chain Telegram Community: https://t.me/AiCoinWhaleData
On-chain Community: https://www.aicoin.com/link/chat?cid=N6OVMor5g
AiCoin On-chain Twitter: https://x.com/aicoinwhaledata
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。



