Bitget resumes Bitcoin withdrawals in phased restart after $387.5 million hack
Bitget reopened Bitcoin withdrawals following a four-day freeze caused by a $387.5 million exploit, marking the first stage of a phased plan to restore all platform withdrawals by Oct. 2.

Bitget reopened Bitcoin withdrawals on Monday at 08:00 UTC, kicking off a phased recovery after attackers drained an estimated $387.5 million from its hot and warm wallets on Sept. 24. While withdrawals remained suspended for four days during the investigation, trading and deposits stayed active. Bitget CEO Gracy Chen said Bitcoin withdrawals were enabled on both the Bitcoin network and BNB Smart Chain, reporting that the exchange processed 9,585 withdrawal orders totaling 4,098.036 BTC as of 17:00 UTC+8.[3][4][5]
Bitget said the underlying vulnerability has been remediated and no further unauthorized transfers occurred after containment. According to Chen, attackers exploited flaws in third-party products to obtain internal credentials, which were then used to spoof transaction data and trick Bitget's approval mechanisms without stealing private keys. The exchange confirmed that cold wallets were untouched, customer balances remain safe, and its protection fund—holding around $464 million—will cover the shortfall. Blockchain security firms Mandiant and SlowMist are assisting the investigation, while Chen noted the incident bore characteristics linked to North Korean hacking groups.[2][3][4][6]
Bitget is restoring other assets incrementally to ensure infrastructure checks are completed across each network. Ethereum withdrawals across Ethereum, BSC, Arbitrum, Base, and Optimism are scheduled to reopen on Sept. 29, followed by Tether (USDT) across Ethereum, BSC, Solana, and Tron on Sept. 30. The exchange expects withdrawals for all remaining tokens, fiat currencies, and peer-to-peer services to go live on Oct. 2.[1][3][4]
Key facts
- Bitget restarted Bitcoin withdrawals at 08:00 UTC on Sept. 28 after a four-day freeze caused by an estimated $387.5 million hack.
- Bitget processed 9,585 orders totaling 4,098.036 BTC as of 17:00 UTC+8 on Sept. 28, according to CEO Gracy Chen.
- Attackers compromised internal credentials via third-party product vulnerabilities to spoof backend transfer approvals without taking private keys or accessing cold wallets.
- Bitget affirmed that customer balances are unaffected and losses will be covered by its User Protection Fund, which holds around $464 million.
- Under Bitget's phased reopening timetable, ETH resumes Sept. 29, USDT resumes Sept. 30, and all other assets, fiat, and P2P services resume Oct. 2.
- Mandiant and SlowMist are assisting forensics, while stolen funds have been traced through Wasabi mixing services and THORChain cross-chain swaps.
Sources · 5 sources
- CR
CryptoSlateArticle ·
Bitget says Bitcoin withdrawals are open after $387M hack, but ETH and USDT must wait At about 04:20 UTC Monday, Bitget's public feed showed BTC and ETH futures trades taking place after the exchange's Sept. 24 security breach. On Sept. 28, Bitget said it had opened BTC withdrawals on the Bitcoin network, the first stage of its phased plan. The notice says the service is open; it does not document a completed customer withdrawal. Trading activity and the ability to send assets off the exchange face separate tests. Bitget said its security systems detected unauthorized transfers from some hot wallets at 18:31 UTC on Sept. 24. It suspended withdrawals while keeping trading and deposits open. The exchange initially estimated affected assets at about $351.6 million. A Sept. 25 update raised the estimate to approximately $387.5 million after it identified more transactions from the original incident; Bitget said the revision did not reflect additional unauthorized transfers. Related Reading Bitget’s $351.6 million hack pushes September crypto losses to 2026 high Bitget says customer balances remain unaffected and its Protection Fund will cover the incident's financial impact. Those assurances come from the exchange. The practical question for customers is whether they can successfully transfer assets or trading proceeds out of their accounts. The company's phased reopening plan sets 08:00 UTC for each of these dates: Scheduled date Withdrawal service Sept. 28 BTC on Bitcoin Sept. 29 ETH on Ethereum, BSC, Arbitrum, Base and Optimism Sept. 30 USDT on Ethereum, BSC, Solana and Tron Oct. 2 Other tokens, fiat and peer-to-peer services The first scheduled restart was still ahead when the public trading snapshot was taken at 04:20 UTC. Bitget has since said BTC withdrawals on Bitcoin are open. Its service notice does not establish whether individual transfers have completed. A customer with ETH on a network scheduled for Sept. 29, for example, would face a different timetable from a customer withdrawing BTC on Bitcoin. Related Reading Bitget freezes XRP withdrawals as 27M stolen tokens move Bitcoin withdrawals and futures trading are separate tests Bitget's public trade feed returned 100 BTCUSDT futures fills between 04:20:25 and 04:20:49 UTC on Sept. 28. It returned 100 ETHUSDT fills between 04:20:34 and 04:20:52 UTC. Those records show that the two USDT-margined contracts matched trades during those seconds. The records cover those two contracts and those seconds; other markets and customer-specific execution prices remain outside their scope. Related Reading Swiss bank shields Bitget institutions while retail funds freeze A separate snapshot around 04:21 UTC showed $22.14 million of displayed BTC futures buy and sell orders and $10.29 million of ETH orders within 0.05% of each contract's midpoint. That band counts orders priced no more than 0.05% away from the middle of the best buy and sell quotes. The BTC quoted spread was about 0.012 basis points and the ETH spread about 0.038 basis points. A hypothetical $500,000 sell against the displayed buy orders would have averaged 0.0095% below the BTC midpoint and 0.0183% below the ETH midpoint, before fees. The calculation models a static book; no customer order produced those prices. Orders can be canceled, replenished or changed while a trade is placed. The snapshot captures one moment during the withdrawal suspension. A TokenInsight study provides the historical comparison. Sampling nine venues every 30 minutes from Aug. 16 through Sept. 14, it put Bitget first for combined BTC and ETH futures depth within the wider 0.05% band, at a $41.60 million median. At the tighter 0.03% band, Bitget ranked third at $15.25 million, behind MEXC and Hyperliquid. The study ended before the breach. Their different windows and methods preclude a measured before-and-after change or a current peer ranking. A futures book measures displayed interest in a derivative. Withdrawal access requires separate evidence about conversion and transfers across the intended network. The public fills establish trading in two contracts at a particular time; Bitget's timetable and its BTC reopening notice describe the phased return of off-platform transfers. The next observable test is whether Bitcoin withdrawals complete in practice, followed by each asset and network in the plan. The post Bitget says Bitcoin withdrawals are open after $387M hack, but ETH and USDT must wait appeared first on CryptoSlate .
Open source - CB
Crypto BriefingArticle ·
Bitget reveals attack path behind $387.5M breach as Bitcoin withdrawals restart Bitget resumed Bitcoin withdrawals after its $387.5M hack as CEO Gracy Chen revealed attackers stole internal credentials through a third-party flaw. The post Bitget reveals attack path behind $387.5M breach as Bitcoin withdrawals restart appeared first on Crypto Briefing .
Open source - UN
UnchainedArticle ·
Bitget Reopens Bitcoin Withdrawals, Starting Phased Restart After $388 Million Hack Bitget reopened bitcoin withdrawals on Monday, the first step in bringing back a service the exchange has kept frozen since attackers took about $388 million from its hot and warm wallets on Sept. 24. Withdrawals of BTC on the Bitcoin network began at 8:00 UTC “as scheduled,” Bitget said on X . The exchange said the flaw the attackers used “has been remediated” and that there were “no further unauthorized transfers identified following containment.” Get Unchained’s crypto news in your inbox with the free Unchained Daily newsletter . One Asset Group a Day The rest of the platform comes back in stages, under a timetable Bitget published on its support site on Sept. 26. ETH withdrawals on Ethereum, BSC, Arbitrum, Base and Optimism are set for 8:00 UTC on Tuesday. USDT on Ethereum, BSC, Solana and Tron follows at the same hour on Wednesday. Every other token, along with fiat and P2P withdrawals, is slated for Oct. 2 . Bitget’s notice said the order “applies consistently across users without preference.” Trading and deposits have stayed open, and users don’t need to do anything before their assets unlock, according to the exchange. CEO Gracy Chen hosted a live AMA on X at 7:30 UTC on Monday to take questions on the incident and what comes next. What Happened The attackers did not need Bitget’s private keys. Chen said on X early on Sept. 25 that “the attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out.” Mandiant and SlowMist are helping with the investigation. The exchange raised its loss count on Sept. 25 to roughly $387.5 million , up from a first estimate of $351.6 million, after adding transfers on Zcash and TRON. Chen has said the attack matched techniques used by North Korea-linked hacking groups. Bitget says its User Protection Fund, which holds about $464 million, will cover the losses in full. It is also offering a bounty of 5% of any stolen funds frozen or recovered through voluntary efforts. Related Listen: Inside the Coldcard Hack That Drained Over $100 Million in Bitcoin: Uneasy Money The post Bitget Reopens Bitcoin Withdrawals, Starting Phased Restart After $388 Million Hack appeared first on Unchained .
Open source - CR
CryptoSlateArticle ·
Nearly 5,000 BTC leaves Bitget as hackers begin laundering $387 million haul Nearly 5,000 Bitcoin has left Bitget’s tracked reserves after the crypto exchange reopened withdrawals following its $387.5 million hack. On Sept. 28, Bitget Chief Executive Officer Gracy Chen said the exchange had processed 9,585 withdrawal orders totaling 4,098.036 BTC as of 17:00 UTC+8, shortly after it resumed Bitcoin withdrawals. Separate DeFiLlama data showed Bitget’s tracked Bitcoin balance falling to about 30,770 BTC from 35,412 BTC, a decline of roughly 4,642 BTC. At prevailing prices, the drop represents about $391 million of Bitcoin. Bitget’s tracked Bitcoin balance hovered near 30,000 BTC before briefly rising above 35,000 and then declining. Source: DeFiLlama The reserve decline is larger than the amount Chen said Bitget had processed through customer withdrawal orders. DeFiLlama tracks assets held in wallets attributed to exchanges, meaning changes can also reflect wallet movements or differences in address coverage rather than customer withdrawals alone. Still, the rapid outflow provides the first indication of how users are responding after Bitget froze withdrawals for four days while investigating the largest security incident in its eight-year history. Bitget restored Bitcoin withdrawals at 08:00 UTC on Sept. 28 after completing additional checks on its withdrawal infrastructure. Ethereum withdrawals are scheduled to follow on Sept. 29, USDT on Sept. 30, and remaining tokens, fiat, and peer-to-peer services on Oct. 2. The restart comes as Bitget attempts to reassure customers that the attack did not compromise its private keys or cold-wallet reserves. Chen said a completed internal trace found that attackers exploited vulnerabilities in third-party products to obtain internal credentials. Those credentials were then used to submit fraudulent withdrawal instructions that bypassed Bitget’s risk controls. The exchange has isolated affected systems, revoked and reissued internal credentials, and restructured access to sensitive infrastructure, Chen said. Bitget also disabled the affected third-party functionality while the vendor works on a fix. Blockchain security firms, including Mandiant and SlowMist, continue to assist with forensic analysis and attempts to trace the stolen assets. Bitget previously said the incident involved a critical backend system in its wallet infrastructure and that it had remediated the vulnerability before withdrawals began returning. Bitget has said customers will bear no losses from the incident and that its Protection Fund will cover the shortfall. Chen said the company plans to replenish the fund with its own capital to more than $300 million within a week. Related Reading Bitget’s hack just got $36 million bigger, and now there’s a bounty on the stolen crypto Stolen funds move as THORChain resists calls to intervene Meanwhile, recovering the stolen Bitget funds is becoming more difficult as the assets are fragmented across bridges, cross-chain protocols and privacy services. Blockchain investigator ZachXBT said Chinese illicit actors were laundering proceeds from the exploit on behalf of hackers he described as allegedly linked to North Korea . He said the funds were being chain-hopped and deposited into mixing services including Wasabi. A TRM and ZachXBT flow map traces Bitget exploit funds through multiple intermediary wallets, including transfers toward THORChain. Source: ZachXBT ZachXBT also linked one participant in the laundering network to movements following the $292 million Kelp DAO exploit earlier this year, saying he had seen similar behavior after several attacks attributed to the TraderTraitor campaign. The laundering action has put THORChain at the center of a growing dispute over whether permissionless infrastructure should intervene when stolen assets pass through its systems. THORChain says it would not selectively block wallets or swaps, arguing that its role is comparable to censorship-resistant networks such as Bitcoin and Ethereum. However, blockchain security firm GoPlus challenged that comparison, saying THORChain's architecture gives its node operators powers that base-layer validators do not have. GoPlus pointed to THORChain's threshold-signature vaults, where active nodes jointly authorize outbound transfers, and said releasing assets from those vaults requires an affirmative signing action. It also cited per-chain signing halts, network-wide pauses, and Mimir governance as evidence that node operators can coordinate intervention when they choose. That makes the argument less about whether THORChain has emergency controls than about when its operators are willing to use them. GoPlus also pointed to THORChain's response to its own $10.7 million exploit in May, when the network was halted as part of the containment effort. The security firm argued that the same emergency framework could be used against addresses linked to the Bitget attackers. THORChain disputes that conclusion, saying a network halt is meant to protect the protocol itself and differs from selectively censoring a particular user, wallet, or swap. It also said attacker addresses were not blacklisted during the May incident, maintaining that the protocol should remain neutral even when known stolen funds move through it. GoPlus has accused THORChain of benefiting financially from that stance. It estimated that about 101.5 BTC, worth roughly $8.5 million, had already exited through the protocol from the Bitget exploit, while another 27.63 million XRP, valued at about $43 million, was being converted into Bitcoin. The firm also cited THORChain's role in laundering proceeds from the 2025 Bybit hack, when the attacker moved hundreds of thousands of ETH through the protocol and generated millions of dollars in fees. GoPlus argued that the fee income creates an incentive conflict when node operators decline to interfere with illicit flows. THORChain has not accepted that characterization, and its position leaves the industry with a question of whether decentralized protocols that retain emergency controls should remain transaction-neutral when those same systems are used to launder funds from major hacks. For Bitget, that debate has immediate consequences. As Ethereum, USDT, and other withdrawals reopen, investigators are racing to recover assets that are already being broken up across chains and routed through infrastructure whose operators may refuse to stop them. The post Nearly 5,000 BTC leaves Bitget as hackers begin laundering $387 million haul appeared first on CryptoSlate .
Open source - CB
Crypto Briefing@Crypto_BriefingPost on X ·
🚨NEW: Bitget begins restoring withdrawals following its $387.5M security breach, with Bitcoin withdrawals now live on the Bitcoin network and BNB Smart Chain. CEO Gracy Chen confirmed the breach stemmed from third-party vulnerabilities that exposed internal credentials. https://t.co/QtEPsUgPVu
Open source - CP
Crypto Patel@CryptoPatelPost on X ·
BITGET $387.5M HACK: WITHDRAWALS REOPEN TODAY AS THORCHAIN WAR HEATS UP The biggest crypto hack of 2026 👇 🔰 WHAT HAPPENED: On September 24, attackers drained $387.5M from Bitget's hot and warm wallets. They didn't steal private keys. They spoofed backend transfer data and tricked Bitget's own approval system. ✅ Cold wallets untouched ✅ User balances unchanged ✅ Deposits and trading never stopped ❌ Withdrawals frozen since September 24 Bitget's CEO @GracyBitget points to a suspected North Korea link. There is no official government attribution yet. 🔰 ARE FUNDS SAFE? @Bitget says its $464M+ User Protection Fund covers the full loss. Still with the Attacker: ➡️ 63,000 ETH ($183M) ➡️ 102M XRP ($157M) ➡️ Only ~$318K frozen So Far Nothing meaningful has been recovered yet. 🔰 WITHDRAWAL SCHEDULE (08:00 UTC / 1:30 PM IST) 🟠 Sept 28: $BTC 🔵 Sept 29: $ETH 🟢 Sept 30: $USDT ⚪ Oct 2: Other tokens, fiat, P2P Bounty: 5% for frozen funds and 5% for recovered funds. It's not a "10% bounty." 🔰 THORCHAIN WAR: The stolen funds are being swapped into BTC through THORChain, the same route used after the Bybit hack. Bitget asked THORChain to block the attacker addresses, and THORChain refused, saying it is "permissionless like Bitcoin." But in May 2026, @THORChain halted its entire network within hours after losing $10.7M of its own funds, and stayed offline for over five weeks. So the brake exists. The question is who it's used for. 🔰 DOG DELISTING: Hours after the hack, with withdrawals frozen, Bitget announced the DOG/USDT delisting for September 30. Holders were trapped and the price decoupled. Bitget calls it a routine review, but the timing hurt users. 🔰 CRYPTOPATEL TAKEAWAYS: ✅ Never keep more on an exchange than you actively trade ✅ Judge Bitget by today's withdrawals, not by statements ✅ Watch RUNE, since pressure on THORChain is rising Should THORChain block hacker addresses? Comment 👇 #BitgetHack #THORChain #CryptoHack
Open source

