Bitget is nearly two weeks into recovery from its $387.5 million security breach, with withdrawals for bitcoin, ether and USDT back online and the final tranche of services, other tokens, fiat and P2P, scheduled to reopen Friday at 08:00 UTC. Meanwhile, investigators report the first known laundering attempts on stolen Zcash.
Blockchain investigator ZachXBT reported Wednesday that wallets connected to the attack moved about $3.8 million in Zcash into the Ironwood privacy pool, roughly 14 percent of the 18,917 ZEC taken on Sept. 24. Security firm Mandiant and blockchain analytics firm SlowMist remain on forensic and tracing work, coordinating with the exchange on asset recovery.
The incident began at 18:31 UTC on Sept. 24, when Bitget detected unauthorized transfers from parts of its hot and warm wallet infrastructure. The first estimate published by the exchange, $351.6 million, grew once tracing added transfers involving Zcash and Tron. CNBC reported Sept. 25 that Bitget suspects North Korean attackers, a pattern consistent with several other major exchange breaches this decade. The company says private keys and cold wallets were not compromised.
How attackers got in
Bitget’s investigation found the intruders exploited a vulnerability in a third-party security product to obtain access credentials and forge withdrawal commands that passed routine risk checks. That is a different fingerprint from the usual phished-employee attack or an API key leak. It went after a monitoring and control layer, then used it the way an insider would, which is why forged withdrawal commands cleared automated screening without tripping anomaly flags.
The implied lesson for other exchanges concerns vendor dependency. Hot wallet risk controls are a security boundary, and the vendor software running those checks becomes part of the attack surface. A compromise there produces little on-chain noise until money actually moves. No further unauthorized transfers have been reported since containment, per the exchange, and trading and deposit services stayed up through the withdrawal freeze, which limited the episode’s market blast radius.
Stolen assets spanned Ethereum and EVM networks, the XRP Ledger, Zcash and Tron, and included XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX and TRX, according to the company’s published asset list.
Withdrawals come back in stages
The recovery plan ran in three stages. BTC withdrawals reopened first on Sept. 28, under what the exchange called a phased schedule with no priority for VIP or institutional accounts. ETH resumed Sept. 29 across Ethereum, BNB Smart Chain, Arbitrum, Base and Optimism. USDT followed Sept. 30 on Ethereum, BNB Smart Chain, Solana and Tron. The final stage, sweeping in other tokens, fiat rails and P2P, was set for Friday Oct. 2 at 08:00 UTC.
CEO Gracy Chen described the business as “gradually back to usual” in a Wednesday post on X, noting the exchange’s User Protection Fund held more than $464 million and had returned above $300 million in coverage toward affected users. Reserves were the other half of the pitch. A 09:00 UTC Sept. 29 snapshot in Bitget’s 47th proof-of-reserves report showed an overall ratio of 131 percent, with all 19 covered assets above 100 percent: bitcoin at 142 percent, ETH at 110, USDT at 107, XRP at 107 and USDC at 154.
“The phased rollout allows Bitget to resume withdrawal services in an orderly manner following the incident,” the company said in a statement. “The same approach applies consistently across users without preference.”
Tracing and frozen funds
Asset recovery has leaned on stablecoin issuers as much as on exchanges. Circle and Tether had frozen around $318,000 in USDC and USDT tied to the incident by Sept. 26, a small fraction of the total but a standard first step that walls off the easiest-to-chase part of the hoard. The rest moves across chains that require different tools.
The Zcash movement is where tracing gets harder. Privacy pools make source tracing on-chain far more difficult, and large hacks that migrate into such infrastructure tend to trap value in place rather than fight exchange withdrawal controls, with funds dribbled out over months. Bitget has offered a 5 percent bounty for information that leads to frozen funds and a separate 5 percent reward for successful recoveries, a combined incentive structure aimed at drawing out off-chain intelligence from exchanges, mixers and over-the-counter desks.
The exchange says no further unauthorized transfers have been detected since containment and that the exploited vulnerability has been remediated. Its investigation and asset-recovery work remain active while the final group of withdrawal services reopens.
Market reaction and what to watch
Traders treated the recovery as a test of how a major exchange handles forensics without ceding trust, and so far there has been no visible run on the venue. The breach ranks among the largest of 2026, and the handling, freeze, phased reopen, published proof-of-reserves, heavyweight forensic vendors, follows the playbook refined across earlier exchange failures. Bitcoin and broader crypto markets showed no sustained reaction to the incident at any point in the two weeks since.
What to watch next: the Friday reopen of remaining withdrawal rails, particularly fiat, which is usually the slowest to restore after an incident; further movement of stolen ZEC into privacy infrastructure; concrete recoveries rather than announcements; and whether regulators in Singapore, Seychelles or anywhere the entity operates open inquiries into the incident’s handling. Bitget has not announced any operational cutbacks as a result of the breach, and its User Protection Fund remained above its pre-hack published size.
