Bitget CEO Gracy Chen stated that attackers made two small test transfers at 18:31 UTC on September 24, including 0.184 ETH and 193 TRX. These transfers were below the exchange's risk control threshold and did not trigger system alerts. Approximately 30 minutes later, the attackers began large-scale transfers, executing 17 transactions across eight blockchains, including Ethereum, XRP, and Zcash, between 18:58 and 20:09, totaling approximately $361 million. Bitget detected the anomaly within seven minutes of the first large transfer and blocked user withdrawals. The attackers gained access to the internal management system by exploiting a zero-day vulnerability in a third-party security product, directly inserting fraudulent withdrawal instructions and deleting their traces. Bitget's User Protection Fund will cover the losses and plans to replenish it to at least $300 million from company reserves within a week. Bitcoin withdrawals resumed on Monday, and Ethereum withdrawals will open on September 29.