Mastodon Skip to content
LIVE - NYSE/-/- CRYPTO/OPEN/24/7
BTC$83,644▼ 1.60%ETH$2,692▼ 0.64%SOL$119.88▼ 2.63%TOTAL CRYPTO$2.87T▼ 4.00%S&P 5007,708.41▼ 0.04%NASDAQ26,919.12▲ 1.96%DOW51,525.15▼ 3.80%GOLD4,184.60▼ 7.62%WTI94.42▲ 13.21%BRENT99.26▲ 11.14%EUR/USD1.1369▼ 2.46%USD/JPY157.16▼ 1.36%DXY101.16▲ 1.47%
Crypto

Bitget Reopens Withdrawals Four Days After $387M Hack

Bitget starts restoring withdrawals on September 28 after a breach drained about $387.5 million. Bitcoin goes first, with full service due back by October 2.

Bitget will begin reopening client withdrawals on Monday, four days after a security breach drained roughly $387.5 million from its hot wallets. Bitcoin withdrawals go live at 16:00 UTC on September 28, and the exchange plans to restore all remaining services, including fiat rails and peer-to-peer trading, by October 2.

The Seychelles-based exchange detected unauthorized movements from several hot wallets at 18:31 UTC on September 24 and suspended withdrawals within minutes. Cold wallets were not touched, according to the company. Initial estimates put losses at $351.6 million, but later on-chain analysis raised the figure by $35.9 million to $387.5 million after investigators counted Zcash and Tron transfers that had been missed at first. The exchange said the revision reflected previously uncounted transfers, not a second wave of theft.

Phased return to service

The restart follows a fixed schedule rather than a single switch-on. Ethereum withdrawals resume on September 29 across five networks: Ethereum, BNB Smart Chain, Arbitrum, Base and Optimism. USDT withdrawals follow on September 30 on Ethereum, BNB Chain, Solana and Tron. Everything else, including remaining tokens, fiat withdrawals and P2P services, comes back on October 2.

Date Service restored
Sept 28 Bitcoin withdrawals on the Bitcoin network
Sept 29 ETH withdrawals on Ethereum, BNB Chain, Arbitrum, Base, Optimism
Sept 30 USDT withdrawals on Ethereum, BNB Chain, Solana, Tron
Oct 2 Remaining tokens, fiat withdrawals, peer-to-peer services

Before the Bitcoin restart, Bitget held a live question-and-answer session at 07:30 UTC on Monday covering the incident and the recovery plan. The company has not published a full post-mortem. The method the attacker used and the identity behind the wallets remain unknown. The staged rollout gives security teams time to verify each network individually before funds start moving at full volume again.

How the breach happened

Bitget has said the attackers combined a flaw in a third-party security product with stolen internal credentials. Private keys and cold storage were not compromised, the company maintains. The stolen assets included XRP, ETH, USDT, USDC, Zcash, BNB, Avalanche tokens and Tether Gold, a mix that suggests the attacker swept whatever the hot wallets held rather than targeting specific assets.

The exchange hired Mandiant, the cybersecurity unit owned by Google, and the blockchain security firm SlowMist to investigate. Both firms are still working through the incident. Bitget also launched a recovery bounty program and says industry partners have frozen an unspecified portion of the stolen funds. Most of the money has already moved through mixing services and cross-chain swaps, which limits what freezes can achieve in practice.

One episode drew particular attention. Some of the stolen funds moved through THORChain, the cross-chain swap protocol, and the protocol community refused to block the transfers, arguing that censorship would break its core promise of permissionless swaps. The dispute that followed, playing out publicly on X, put the industry old tension between recoverability and neutrality back on display. Exchanges want stolen funds frozen. Protocol developers argue that once a network starts picking and choosing transactions, it stops being decentralized in any meaningful sense.

Separately, about $83 million of the stolen XRP was moved on September 27, and a 577.8 million XRP transfer from Uphold added to market concerns about potential liquidation pressure. XRP traded near $1.48 on Monday, down about 2.5 percent, making it the weakest major coin over the weekend. Traders worried that a large holder might be preparing to sell, though the transfer could also reflect routine custody movements.

Who pays for the losses

Bitget says its User Protection Fund held more than $464 million when the breach occurred and will cover user losses. The final payout size depends on how much the investigation recovers. The company has not said whether it will draw down the fund at all or absorb the loss on its own balance sheet. Either way, users are not expected to take a haircut, which distinguishes this case from older exchange collapses where client funds simply disappeared.

The incident ranks among the larger exchange hacks of 2026 and comes at a sensitive moment for the market. Bitcoin fell below $83,000 on Monday as rising Treasury yields and the stalled Iran talks pushed risk assets lower, so the Bitget news landed on top of an already nervous tape. Withdrawal halts, even short ones, tend to weigh on an exchange market share, and competitors moved quickly to reassure their own users that their custody arrangements differ.

The breach also renewed questions about the industry reliance on hot wallets and third-party security tooling. Bitget says the flaw in the third-party product has been patched, but it has not named the vendor. Security researchers have asked whether other exchanges use the same product and whether they face the same exposure. Until the full forensic report lands, that question stays open.

What happens next depends on the investigation. If Mandiant and SlowMist pin down how credentials were stolen and which third-party tool failed, other exchanges will face pressure to audit the same stack. Regulators in several jurisdictions where Bitget operates will likely ask for their own briefing. For now, the exchange is managing the crisis in public: daily updates, a phased restart, and a bounty for whoever helps claw the money back.

The timing matters for another reason. Bitget had been gaining ground in derivatives volume through the summer, and a four-day withdrawal freeze gives rivals a window to court its most active traders. Several competitors posted about their own proof-of-reserves pages within hours of the incident becoming public. Whether that traffic sticks after October 2 is the commercial question the exchange now faces alongside the security one.

For users waiting on the restart, the practical advice from the exchange is straightforward: check the schedule for your asset, expect the earlier days to be congested, and treat any message asking for keys or seed phrases as an attack. Scam waves typically follow large hacks, and impersonator accounts posing as Bitget support have already appeared on social platforms within days of the breach.

SourcesBitget announcements; CoinDesk; CryptoPanic; CoinRab incident timeline
Share: X