How Is Bitget Restoring Withdrawals?
Bitget has begun restoring withdrawals after a Sept. 24 security breach transferred about $387.5 million in crypto assets to attacker-controlled addresses, starting a staged return of services while forensic and recovery work continues.
The exchange reopened BTC withdrawals on the Bitcoin network at 8 a.m. UTC on Monday after completing additional security checks. ETH withdrawals are scheduled to resume on Sept. 29 across Ethereum, BSC, Arbitrum, Base and Optimism, followed by USDT withdrawals on Ethereum, BSC, Solana and Tron on Sept. 30.
Bitget expects withdrawals for remaining tokens, along with fiat withdrawals and peer-to-peer transactions, to return on Oct. 2. Trading and deposits have remained available during the withdrawal suspension.
The phased approach reflects the exchange’s decision to validate individual withdrawal systems before reopening them rather than restoring every network at once. Bitget said the vulnerability has been remediated and that no additional unauthorized transfers have been identified since the incident was contained.
The confirmed loss is higher than the initial $351.6 million estimate disclosed after the breach. Subsequent transaction classification added assets on networks including Zcash and Tron, taking the total to approximately $387.5 million.
What Did The Attackers Compromise?
The attack began at about 18:31 UTC on Sept. 24 and affected portions of Bitget’s hot and warm wallet infrastructure across several blockchains.
Bitget’s investigation found that attackers compromised a critical backend component within its wallet infrastructure and were able to manipulate transaction information before it reached the authorization process. That allowed unauthorized withdrawals to receive valid approvals while bypassing existing controls.
The exchange said its private keys were not compromised and its cold wallets were unaffected. User account balances also remained intact.
The distinction is important because the breach was not a conventional private-key theft. Security researchers have instead focused on how the attacker manipulated the systems responsible for determining what the exchange’s signing infrastructure should authorize. A technical analysis by GoPlus described the attack as a compromise of the transaction-signing trust chain.
Mandiant and SlowMist are assisting Bitget with forensic investigation, validation of the remediation measures and tracing of the stolen assets. Bitget has also said it will review how security tools and critical infrastructure are assessed before deployment.
Investor Takeaway
Restarting withdrawals removes the most immediate operational concern for customers, but the bigger security issue is how fraudulent transactions passed through an authorized signing process without the attackers stealing private keys.
Can Bitget Absorb A $387.5 Million Loss?
Bitget said the financial impact of the incident will be covered by its User Protection Fund, which holds 5,500 BTC and is maintained separately from the exchange’s Proof of Reserves.
The fund is designed to absorb losses from eligible platform-level security events. Bitget has said customer balances were not reduced by the attack, meaning the exchange rather than individual users is carrying the immediate financial impact.
The size of the loss nevertheless makes the incident one of the largest crypto exchange security breaches of 2026 and creates a substantial test of Bitget’s protection structure, security controls and post-incident transparency.
The exchange has also launched a recovery bounty offering 5% of funds successfully frozen or recovered to eligible parties whose voluntary actions directly lead to those assets being intercepted. Bitget said some affected assets have already been frozen through cooperation with exchanges, blockchain projects and other industry participants, without disclosing a confirmed total.
Where Are The Stolen Assets Going?
Asset recovery is likely to depend heavily on the networks and services the attacker uses next. Tokens that reach centralized exchanges or issuers with freezing capabilities can potentially be intercepted, while native assets on some blockchains are harder to restrict at the protocol level.
That problem has already appeared with XRP taken in the breach. The attacker subsequently moved about $83 million in stolen XRP from several original holding wallets, complicating tracing and potential recovery as the funds spread across additional addresses.
Bitget continues to publish attacker addresses and tracing information while working with external security firms and industry counterparties. Final attribution for the breach remains unconfirmed.
Investor Takeaway
The withdrawal rollout shows Bitget believes the immediate breach has been contained. The next measures of recovery will be how much of the stolen $387.5 million can be frozen, whether all services return on schedule and what the final forensic report reveals about the failure of the exchange’s internal authorization controls.







