Bitget Resumes Withdrawals in Phases After $388 Million Hack
Withdrawals restart after major security breach
Crypto exchange Bitget has begun allowing users to withdraw funds again, starting with Bitcoin. This move follows a security incident on September 24 that resulted in the loss of approximately $388 million.
The exchange stated that it has fixed the security flaw that allowed the attack. Bitget confirmed that all losses will be paid out from its User Protection Fund, ensuring customers do not lose their money.
Step-by-step return of access
- Bitcoin (BTC) withdrawals resumed on the Bitcoin network at 8 a.m. UTC on Monday.
- Ether (ETH) and tokens on chains like Ethereum, BSC, Arbitrum, Base, and Optimism will open on September 29 at 8 a.m. UTC.
- USDT withdrawals on Ethereum, BSC, Solana, and Tron are scheduled for September 30 at the same time.
- All other assets, fiat currency withdrawals, and peer-to-peer (P2P) transactions will be restored on October 2.
The exchange explained that this staged approach is necessary because each blockchain network must pass specific security checks before withdrawals can safely resume.
How the attack occurred
The unauthorized transfers began around 6:31 p.m. UTC on September 24. Attackers exploited a weakness in a third-party security tool used by Bitget. This allowed them to gain high-level internal credentials.
Using these credentials, the attackers sent fake withdrawal commands to the wallet system. These commands bypassed standard risk controls. Bitget clarified that its private keys were not stolen and that user balances held in cold wallets (offline storage) remained safe.
While the exact list of stolen assets was not detailed in the latest update, previous reports indicated that ether, USDT, USDC, AVAX, and BNB were among the affected tokens. Security firms Mandiant and SlowMist are helping investigate the incident.
Largest theft of the year so far
The $388 million loss is currently the largest reported crypto theft this year, surpassing incidents involving KelpDAO and Drift Protocol. To help recover the funds, Bitget has launched a bounty program offering 5% of any successfully frozen or recovered attacker funds to those who assist.
Suspects remain unconfirmed
Bitget described the attackers as "sophisticated" and potentially "state-backed," noting their ability to hide stolen funds. While the exchange previously told media outlets it suspects North Korea, it stated it will not confirm the identity of the attackers until the investigation concludes.
Next steps for the platform
Bitget plans to review how it assesses and deploys third-party security products to prevent future issues. The exchange confirmed that no further unauthorized transfers have occurred since the initial breach was contained.