Mastodon Skip to content
LIVE - NYSE/-/- CRYPTO/OPEN/24/7
BTC$83,705▲ 0.31%ETH$2,683▲ 0.18%SOL$117.93▼ 0.80%TOTAL CRYPTO$2.88T▼ 2.65%S&P 5007,651.54▼ 0.45%NASDAQ26,861.06▲ 1.86%DOW50,906.05▼ 4.29%GOLD4,189.10▼ 6.52%WTI90.34▲ 5.34%BRENT97.92▲ 8.21%EUR/USD1.1334▼ 2.76%USD/JPY157.33▼ 1.25%DXY101.45▲ 2.03%
Crypto

Bitget Restores Withdrawals as CEO Doubts Fund Recovery

Bitget reopened ETH withdrawals on schedule, but CEO Gracy Chen expects only a small share of the $387.5 million stolen to be frozen or recovered.

Pexels – Melvin Silva

Bitget reopened Ethereum withdrawals on schedule Tuesday morning, the second stage of a phased restart after a September 24 breach drained about $387.5 million from the exchange, while its chief executive said she expects only a small fraction of the stolen funds to come back. In the first hour after ETH withdrawals reopened at 08:00 UTC, the exchange reported roughly 9,674 ETH in inflows against 9,023 ETH in outflows, a net gain of about 651 ETH that CEO Gracy Chen framed as a sign of user confidence.

Bitcoin withdrawals had returned a day earlier across the Bitcoin and BNB Smart Chain networks. USDT withdrawals are scheduled for September 30 on Ethereum, BNB Smart Chain, Solana and Tron, with remaining tokens, fiat services and peer-to-peer trading set for October 2. Trading and deposits stayed open throughout the four-day withdrawal freeze.

Recovery expectations are low

Chen was blunt about the recovery outlook in an interview released Tuesday. “I am actually not very optimistic because after a year or so of Bybit hack, they have only been able to freeze about 3.5 percent of the total stolen funds,” she said, referring to the February 2025 theft of $1.5 billion from Bybit, which recovered roughly $80 million.

The numbers so far bear out the caution. Circle and Tether blacklisted one attacker wallet, freezing about $318,000 in USDT and USDC. NEAR Intents, a cross-chain bridge, intercepted more than $50 million in laundering flows but could freeze only about $503,000 of it. Blockchain trackers show attacker-controlled wallets still holding tens of thousands of ETH, an asset with no issuer able to blacklist addresses. Bitget has offered a bounty of 5 percent of funds frozen and 5 percent of funds recovered to parties whose actions directly produce those results.

On-chain investigators, including Elliptic, assess the attack as likely linked to North Korea, based on connections between the stolen XRP and ether from earlier DPRK-attributed thefts. Chen said IP addresses used in the attack matched VPN infrastructure previously tied to North Korean-linked groups. The stolen funds have moved through THORChain, the cross-chain swap protocol that declined Bitget’s formal request to block attacker addresses, citing its neutrality policy.

How the breach happened

Attackers compromised a backend component of Bitget’s wallet infrastructure and fed falsified transaction data into the authorization system, which approved the transfers, according to Chen. She ruled out a private key compromise, and the exchange says its cold storage was untouched. Bitget revised its loss estimate from $351.6 million to $387.5 million after counting Zcash and TRON assets missed in the first accounting, not because of new theft.

The exchange is covering the loss through its User Protection Fund, valued above $464 million before the incident. Chen said on September 28 the fund would be replenished to above $300 million from company capital within a week. Tracked reserves stand near $5.7 billion, but roughly $463 million in customer outflows left the platform within 24 hours of withdrawals resuming, a combined decline of about $600 million counting the theft itself.

XRP was the largest single asset stolen, about 102.93 million tokens, and the attacker has moved roughly $83 million of it out of the original holding wallets. Ripple cannot freeze XRP because it is the native asset of the XRP Ledger, not an issued token, leaving exchanges as the only realistic intervention point when the coins arrive.

The Mandiant and SlowMist forensic report is expected this week. Whether the remaining withdrawal phases open on schedule and how quickly the protection fund is rebuilt will shape how the episode is judged. The $387.5 million itself, on current evidence, is mostly gone.

SourcesCointelegraph (Chain Reaction interview, Sept 29); CoinDesk; crypto.news; TechTimes; Bitget security incident notice.

Withdrawal schedule and user response

The phased reopening follows a schedule Bitget published on September 26. Each phase opens at 08:00 UTC: Bitcoin on September 28, Ether across Ethereum, BNB Smart Chain, Arbitrum, Base and Optimism on September 29, USDT on four networks on September 30, and everything else, including fiat rails and peer-to-peer services, on October 2. The exchange told users no action was needed ahead of each phase and that availability appears as each network opens.

Chen quoted the first-hour ETH figures with a note of thanks: “Following ETH withdrawal today at UTC 8:00, we actually saw a net inflow. Thank you for your trust.” The net inflow is a data point, not a verdict. Customer outflows of roughly $463 million in the first 24 hours after Bitcoin withdrawals reopened suggest a meaningful share of users took the first chance to move funds off the platform.

For comparison, when Bybit was hacked for $1.5 billion in February 2025, its liquidity position allowed withdrawals to continue without a comparable freeze. Bitget’s five-day pause was a security review, not a solvency event, the company says, and its protection fund absorbed the loss without writing down any customer balances.

The bounty economics

Bitget’s recovery bounty pays 5 percent of funds a participant directly helps freeze and another 5 percent of funds directly recovered. Voluntary freezes completed before the program was announced can qualify. NEAR Intents, the bridge that intercepted more than $50 million in flows tied to the attack, froze about $500,000, which would translate to a $25,000 bounty under the program if it qualifies.

The arithmetic explains why few expect much recovery. Of the $387.5 million taken, verified freezes total under $503,000, or about 0.13 percent. Most of the stolen value was converted to ETH within minutes of the breach and distributed across fresh wallets on multiple chains, the playbook the FBI described after the Bybit hack as designed to launder and eventually convert to fiat. THORChain, the rail carrying much of the flow, has refused to block attacker-linked addresses in this case and in prior major thefts.

Bitget is also using Bybit’s LazarusBounty tracing platform as a recovery channel and has published live tracing information for industry coordination. Chen asked THORChain publicly to refuse service to the flagged addresses, writing that decentralization is a principle, not a shield for known stolen funds. The protocol declined.

What happens next

Three checkpoints remain. USDT withdrawals reopen September 30, the largest token by customer exposure after the theft. The October 2 phase restores everything else. And the Mandiant and SlowMist forensic report, promised this week, should confirm the attack path and whether any customer data beyond wallet infrastructure was touched.

The protection fund rebuild matters most for confidence. It was denominated largely in bitcoin, so its dollar value moves with the market, and Chen’s $300 million replenishment target assumes BTC holds near its September 24 level through the rebuild window. At $387.5 million, the theft consumed about 83 percent of the pre-breach fund.

Bitget says it serves more than 120 million users. The breach was one of the largest centralized exchange hacks of 2026, and the response, a fast fix, a staged reopening and a fund that covered users in full, will be compared against how Bybit managed a theft four times larger. The difference so far is recovery: Bybit froze 3.5 percent over a year. Bitget is at a fraction of that after five days.

Sources: Cointelegraph; CoinDesk; crypto.news; Cryptotimes; Bitget official incident timeline.

Share: X