Mastodon Skip to content
LIVE - NYSE/-/- CRYPTO/OPEN/24/7
BTC$83,857▼ 0.28%ETH$2,676▼ 0.21%SOL$117.10▼ 1.54%TOTAL CRYPTO$2.88T▼ 2.58%S&P 5007,623.48▼ 0.10%NASDAQ26,757.74▲ 2.52%DOW50,588.22▼ 4.13%GOLD4,193.00▼ 4.63%WTI92.53▲ 2.56%BRENT101.72▲ 7.47%EUR/USD1.1233▼ 3.31%USD/JPY157.50▼ 1.41%DXY101.90▲ 2.24%
Crypto

Bitget Restores All Withdrawals as Fund Hits $309M

Bitget said withdrawals for all tokens resume Friday after a $388 million security breach, while its insurance fund rebuilt to $309 million.

Pexels – Melvin Silva

Bitget said Wednesday that withdrawals for all tokens would resume on Friday, the clearest sign yet that the exchange is recovering from a security breach that cost users $388 million. CEO Gracy Chen broke the news in an X post, adding that access to Bitcoin, Ether and USDt had already been restored and that the company’s Protection Fund now stands at $309 million.

Operations back on track

The phased restart began days earlier. Bitcoin network withdrawals reopened on September 28, Ethereum followed on September 29 and Tether services returned on September 30. Other tokens, fiat withdrawals and peer-to-peer services are now scheduled to come back online by Friday, roughly a week after the breach was detected.

Chen said the platform is gradually returning to normal and that customer service queues, which reached thousands of open tickets at the peak of the incident, have largely cleared. The exchange froze withdrawals immediately after the attack, a step that drew some criticism from traders at the time but is now being credited with limiting how much of the stolen cache could be moved in the first hours. Trading itself never stopped, which analysts noted separates this playbook from the full-halt approach some rivals took in past incidents.

The fund that caught the loss

The Protection Fund sits at the center of the response. Bitget created it in January 2022 with an initial allocation of 5,500 BTC, meant to cover user losses that were not the fault of the user, and the company says the assets stay held for instant deployment whenever the need arises. “The Protection Fund was created for moments like this and absorbed the financial impact of the incident,” Chen said in a company blog post.

The balance dipped below $300 million as payouts went out and has since been rebuilt past $309 million, according to figures the exchange published this week. Bitget has not detailed exactly how much of the $388 million hole came from the fund versus its own operating reserves, an accounting question analysts may press on once the full incident report appears. The shortfall, if any, would show up in the next monthly proof-of-reserves snapshot rather than in daily statements.

Alongside the fund, the company opened a bounty program after the breach. It offers 5 percent of any frozen funds and another 5 percent of whatever is ultimately recovered to whoever provides information that helps trace the stolen assets. Several exchanges, chains and protocol teams have coordinated with the program in the days since, though results so far are uneven.

“The Protection Fund was created for moments like this and absorbed the financial impact of the incident.” – Gracy Chen, CEO of Bitget, in a company statement published Wednesday

Stolen funds keep moving

Recovering the assets themselves is going less smoothly. Blockchain investigator ZachXBT reported Wednesday that wallets tied to the hack moved about $3.8 million in Zcash through the network’s Ironwood privacy pool. That represents roughly 14 percent of the 18,917 ZEC stolen in the attack. Zcash is attractive to launderers for the same reason investigators find it frustrating: shielded transactions hide amounts and counterparties by design, so once funds enter the pool they are hard to trace further.

The laundering trail has branched across several protocols. On Tuesday the attacker swapped 2,390 ETH into 75.2 BTC through THORChain after the protocol’s community refused Bitget’s request to block the transfers. Contributors to THORChain argued the network cannot and should not censor swaps, a decision that has since drawn legal debate over whether decentralized frontends could face liability for knowingly processing stolen funds. Separately, NEAR Intents said it blocked about $50 million in transfers tied to the hackers, a reminder that teams running similar infrastructure are making very different calls under the same pressure.

Investigation firm SlowMist traced the initial compromise to a zero-day exploit used on August 31, meaning the attacker appears to have held access for days before the breach became visible. Chen told Cointelegraph this week that the company has not ruled out any suspects, including the possibility of an inside job or North Korean hackers. Forensic teams are still working through internal access logs alongside on-chain data, and no arrest has been announced. Security engineers at other exchanges are watching the root-cause findings closely, since a zero-day in shared vendor software would put every similar platform on notice.

What it means for exchanges

Restoring every withdrawal within roughly a week keeps this incident far from the scale of historical collapses like FTX or Mt. Gox, where users waited years for partial payouts. The quick restart, funded first from reserves and then backstopped by the insurance fund, strengthens the argument of large platforms that deep reserve cushions let them absorb shocks that would sink smaller operators. Critics counter that fresh disclosures will be needed to show the fund math holds if a larger exchange ever faces a similar hit.

Markets have barely reacted. Bitcoin traded near $84,000 through Wednesday, Ether hovered around $2,680 and on-chain dashboards showed no unusual outflow spike from Bitget once withdrawals reopened. Sentiment on crypto social channels has shifted from anger at the freeze to cautious approval of the payout speed, though traders say trust will only return fully with a published post-mortem.

Attention now shifts to whether the bounty program produces names before the remaining stolen funds vanish into privacy pools, and to whether regulators in the exchange’s main Markets ask harder questions about custody architecture than they did before this breach.

SourcesCointelegraph; Bitget company statements and blog, Sept. 30, 2026; ZachXBT investigations channel entry on ZEC movements; SlowMist report on the Aug. 31 exploit.
Share: X