Bitget has started restoring customer withdrawals after a hack that stole roughly $387.5 million in digital assets. The exchange, one of the larger venues by derivatives volume, shut exits on September 25 once the theft became visible and has been bringing corridors back by chain, starting with Bitcoin’s network at 08:00 UTC on September 28, Ethereum a day later and Tether on September 30.
The theft came from a hole in third-party security appliances rather than a lost key or a smart contract bug. According to the exchange’s account, attackers used a zero-day vulnerability in a security appliance to reach Bitget’s systems, installed a web shell and then waited. Two weeks passed between the initial compromise and the transfer of funds, a lag that let the intruders map the environment and pick a quiet window to move the money.
Damage estimates climbed as the scope became clear. The first notice put the figure at $351.6 million. Follow-up analysis and checks by outside trackers brought it to $387.5 million, spread across several chains and a mix of tokens. Circle, Tether and Paxos froze about $318,000 in stablecoins linked to attacker wallets, and the exchange offered bounties while contacting law enforcement.
The restoration plan
| Date | Step |
|---|---|
| Sept. 25 | Breach detected, withdrawals paused |
| Sept. 26, 08:00 UTC | First estimate, $351.6 million, published |
| Sept. 28 | Bitcoin withdrawals restored |
| Sept. 29 | Ethereum withdrawals restored |
| Sept. 30 | Tether withdrawals resumed |
| Later | Damage revised up to $387.5 million |
CEO Gracy Chen said emergency protocols had contained the breach and that the exchange’s $464 million User Protection Fund would cover every lost asset in full. She also promised a complete incident report within 24 hours of the first security notice, and a forensic firm has been engaged to reconstruct the attack path and identify the appliance vendor involved.
Client reaction through the weekend was uneven. Some trading desks reduced Bitget exposure in the first days, treating the freeze as the start of something longer, while others redeposited once withdrawals began resuming. Volume data shows the exchange keeping a visible share of derivatives flow, though rivals advanced on custody comparisons that now matter more for institutional business.
The vendor angle is the detail most exchanges will study. Buying security appliances is standard practice across the industry, and a zero-day in that layer gives attackers a path that bypasses endpoint controls entirely. Bitget is not the first victim of this pattern, and the appliance vendors involved in past incidents have shipped patches. Exchanges and funds have spent the days since the disclosure re-checking their own perimeters.
Insurance mathematics usually keep the damage off the customer, and Bitget’s fund has been built from trading revenue and marked at $464 million. The exchange said it drew on that reserve immediately. Whether the full $387.5 million has been reimbursed right away or as assets move back through the restore window has not been spelled out publicly.
History says these events are survivable when the reimbursements land. Bybit reimbursed users in full after a $1.5 billion theft in February 2024 and kept its rank among the top exchanges. Bitget’s case has the same shape: a contained perimeter failure, a funded insurance vehicle, and a withdrawal freeze that is shorter than the market feared on day one.
What the market did about it
The breach arrived during a stretch when exchange business is catching a second wind. Crypto job postings have tripled since July, the two largest US spot bitcoin ETF complexes are back to net inflows, and CFTC chair Michael Selig has said the agency will draft crypto rules under its existing authority after the Clarity Act stalled in the Senate. None of that erases the loss, but it does mean Bitget is operating in a market more forgiving of a security stumble than the one exchanges faced a year ago.
Bitget also traced activity that preceded the theft. On-chain data noted by CryptoSlate found the exchange had flagged suspicious behavior well before the two largest transfer waves hit, evidence that at least some monitoring worked even though the escape itself went undetected for two weeks.
What remains to be seen is the final report: how the zero-day got past intake, which appliance vendor was involved, and what monitoring gap let two weeks of dwelling go unnoticed. The exchange has promised that detail once the forensic work is done, and traders will watch whether Bitget’s market share survives one of the largest exchange thefts of the year intact.
Recovery timing also matters for the broader market. A fast, clean restoration tends to calm depositors and keeps trading flow on the platform. A drawn-out freeze, or a second incident while the first one is still under review, would push more of the derivatives order flow toward rivals that escaped this particular vendor exposure. Past episodes suggest the first outcome is more common when the reserve is sized to the loss, which it is in this case.
The user experience angle is also worth noting. Bitget said recovery windows will be staggered across chains so that a single large withdrawal burst does not overwhelm any one network. Trading remained available throughout. Users who needed to exit quickly could do so on chains already restored, which keeps some withdrawal pressure off the ones still closed.
For the industry, the case fits a pattern. Exchange thefts in 2024 and 2025 have come overwhelmingly from third-party software and vendor relationships rather than from lost private keys. The response each time is the same: a freeze, a public bounty, a phased restoration, and a report that arrives weeks later. What separates survivors from casualties is whether user funds are made whole, and on that test the early signs from Bitget are so far positive.
