Bitget withdrawal resumption begins with BTC after $388 million hack
0
0
Crypto exchange Bitget has started giving users back access to their funds, marking the beginning of a carefully staged Bitget withdrawal resumption after hackers drained roughly $388 million from the platform on September 24. The exchange reopened Bitcoin withdrawals first, with other assets set to follow over the coming days as each blockchain network clears a round of security checks.
Key takeaways
- Bitget resumed BTC withdrawals on September 28 at 08:00 UTC, days after a $388 million exploit hit the exchange.
- ETH withdrawals across Ethereum, BSC, Arbitrum, Base and Optimism reopen on September 29, followed by USDT across Ethereum, BSC, Solana and Tron on September 30.
- All remaining assets, plus fiat and P2P transactions, are scheduled to fully return by October 2.
- The attacker exploited a vulnerability in a third-party security product to steal internal credentials, but user balances and cold wallets were not touched.
- The Bitget User Protection Fund, which holds 5,500 BTC, will cover the entire loss, while Mandiant and SlowMist assist with the investigation.
Bitget Resumes Withdrawals in Phases Following $388 Million Exploit
The Bitget withdrawal resumption is happening one blockchain at a time, not all at once, because the exchange says every network needs its own round of security clearance before it reopens. That staggered approach explains why some users got their money moving again this week while others are still waiting.
BTC Withdrawals Resume First
Bitget switched Bitcoin withdrawals back on at 08:00 UTC on September 28, exactly on the schedule it had announced. The exchange said in a post on X that the process “has begun the phased resumption of withdrawals” following the incident. According to Bitget, the move “follows additional security work across Bitget’s withdrawal infrastructure.”
ETH, USDT and Full Restoration Timeline
Ether withdrawals come next. According to Bitget, September 29 at 8 a.m. UTC marks the opening of ETH transfers across Ethereum, BSC, Arbitrum, Base and Optimism. A day later, on September 30, USDT withdrawals across Ethereum, BSC, Solana and Tron follow the same schedule. The exchange says all remaining assets, along with fiat withdrawals and P2P transactions, will be fully restored by October 2, closing out a four-step recovery plan.
Details of the Security Exploit and Its Impact
The breach that triggered this whole recovery effort did not come from a flaw inside Bitget’s own wallet code. Instead, attackers found a weak point in a security tool built by an outside vendor and used it to slip past the exchange’s defenses.
A Third-Party Security Flaw
Unauthorized transfers began around 6:31 p.m. UTC on September 24, moving assets across multiple networks out of Bitget’s hot and warm wallet infrastructure. Bitget said the attacker exploited a vulnerability in a third-party security product it uses, obtaining high-level internal credentials in the process. “The attacker then used these credentials to send fraudulent withdrawal commands to the wallet system, causing it to execute abnormal transfers that bypassed risk controls,” the exchange said. Bitget’s latest statement did not list the specific tokens stolen, though The Block had previously reported that ether, USDT, USDC, AVAX and BNB were among the assets moved during the incident.
Cold Wallets and User Funds Untouched
Despite the scale of the theft, Bitget maintains that the damage stayed contained to a specific part of its infrastructure. The exchange said its private keys were never compromised and that user account balances and cold wallets remained unaffected throughout the attack. Bitget also said it has since patched the vulnerability and identified no further unauthorized transfers since containing the breach, adding that it will review how it evaluates and deploys third-party security tools going forward.
Investigation, Fund Coverage, and Attacker Profile
With roughly $388 million gone, the question users care about most is whether they’ll be made whole. Bitget’s answer, so far, is yes.
User Protection Fund Steps In
Bitget confirmed that its User Protection Fund will cover the losses from the exploit in full. The fund holds 5,500 BTC, and CEO Gracy Chen previously said it would return to its $300 million baseline within a week. The $388 million loss ranks as the largest reported crypto theft so far this year, surpassing exploits tied to KelpDAO and Drift Protocol. To help claw back stolen funds, Bitget also launched a bounty program offering 5% of any attacker funds that are frozen or recovered as a direct result of outside tips or action.
Tracing a Suspected State-Backed Attacker
Bitget brought in Mandiant and SlowMist to help dig into how the breach happened and who was behind it. The exchange has been cautious about naming a culprit, saying it won’t speculate on the attackers’ identity until the investigation reaches a firm conclusion. Even so, Bitget described the attackers as “sophisticated” and “state-backed,” noting they know how to obscure stolen funds, and it has told media outlets it suspects North Korea was behind the operation.
The episode adds to a running pattern in crypto security: attackers increasingly go after the vendors and tools exchanges rely on rather than the exchanges’ own code. For an industry still leaning on centralized custody for daily liquidity, a breach routed through a third-party security product is a reminder that an exchange’s defenses are only as strong as the weakest link in its supply chain — a lesson that will likely shape how other platforms audit outside vendors in the months ahead.
FAQ
What caused the $388 million exploit at Bitget?
The exploit targeted a vulnerability in a third-party security product used by Bitget, allowing unauthorized withdrawals from hot and warm wallets.
Are user balances and cold wallets affected by the Bitget hack?
User account balances and cold wallets were not compromised and remain unaffected.
When will Bitget fully restore all withdrawals after the exploit?
All asset withdrawals, fiat, and P2P transactions are scheduled to be fully restored by October 2.
Who is suspected to be behind the Bitget exploit?
The attackers are described by Bitget as sophisticated and state-backed, and the exchange has said it suspects North Korea, though it has not confirmed this pending its ongoing investigation.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.
0
0
Securely connect the portfolio you’re using to start.





