Key Insights:
- Bitget will bring back withdrawals from September 28 to October 2 after the $387.5 million security breach.
- The exchange says its protection fund will pay for the losses. Investigators are still tracking down the assets.
- The step-by-step return to operations and the ongoing forensic investigation mean the final amount recovered and the full reason, for the incident are still not known.
Bitget withdrawal restart will begin on September 28, four days after a security breach drained approximately $387.5 million from the exchange. The Seychelles-based cryptocurrency platform will restore services gradually through October 2, while security investigations continue and its protection fund covers the financial impact.
Bitget sets four-stage withdrawal restoration schedule
Bitget announced its withdrawal schedule on September 26 through its official support center. Chief Executive Officer Gracy Chen also outlined the timeline on September 25 through an update on X.
The exchange will reopen Bitcoin withdrawals at 16:00 UTC on September 28. Ethereum withdrawals will follow on September 29, covering several supported blockchain networks.
USDT withdrawals will resume on September 30, followed by other cryptocurrencies, fiat withdrawals, and peer-to-peer services on October 2.
Bitget will begin resuming withdrawals in orderly phases following the security incident identified on September 24.
The vulnerability involved in the incident has been identified and remediated.
Bitget's security and technical teams have since been conducting additional… https://t.co/VZu59GnLAN
— Bitget (@bitget) September 26, 2026
The restoration schedule covers the following services.
- September 28 – Bitcoin withdrawals on the Bitcoin network.
- September 29 – ETH withdrawals across Ethereum, BNB Smart Chain, Arbitrum, Base, and Optimism.
- September 30 – USDT withdrawals across Ethereum, BNB Smart Chain, Solana, and Tron.
- October 2 – Remaining tokens, fiat withdrawals, and peer-to-peer services.
Bitget said the phased approach allows its technical and security teams to validate withdrawal infrastructure before restoring additional services. Moreover, the exchange confirmed that users will receive access automatically. Customers do not need to submit requests or complete additional procedures.
Trading and deposits remain operational throughout the withdrawal suspension. Bitget also maintained that the incident did not affect customer account balances.
Security breach drains $387.5 million across networks
Bitget detected asset movements from several hot wallets at 18:31 UTC on September 24. Bitget immediately suspended withdrawals while Bitget investigated transactions and secured its infrastructure.
Hot wallets support transactions through internet-connected systems. However Bitget said that the attacker compromised portions of Bitgets warm wallet infrastructure.
Bitget reported that its offline cold wallets remained secure. Bitget also said that security teams identified and patched the vulnerability, for the incident. Initial estimates placed the losses at $351.6 million. However further blockchain investigations increased the figure to $387.5 million.
Bitget attributed the additional $35.9 million to previously uncounted Zcash and Tron transfers. The exchange said the revision did not represent additional unauthorized transactions.
The attack affected several blockchain networks and digital assets.
- XRP and ETH accounted for significant portions of the transferred funds.
- USDT, USDC, and USDT0 featured among the affected stablecoins.
- Zcash, Tron, BNB, Avalanche, and Tether Gold also appeared in the investigation.
Blockchain monitoring platform Lookonchain reported approximately 102.93 million XRP among the transferred assets.
Meanwhile, Bitget said its User Protection Fund held more than $464 million when the incident occurred. The exchange maintains that the fund will cover the financial impact of the breach.
Bitget expands recovery efforts and investigation
Bitget has enlisted Mandiant, the cybersecurity unit of Google and the blockchain security firm SlowMist to investigate the incident. Both Mandiant and SlowMist are helping with analysis and security validation.
The people looking into the matter have not shared a full report, about what caused the problem. The person who did this and the exact way they broke into the system are still not known.
Chen previously said the attack displayed patterns associated with groups linked to North Korea. She also indicated that the attacker compromised backend systems and manipulated transaction data. Nevertheless, authorities have not publicly confirmed that attribution.
Bitget has also launched recovery initiatives to trace and freeze the stolen assets. The exchange said industry partners have already frozen some affected funds. Its Recovery Bounty Program offers rewards for successful recovery efforts.
Eligible participants can receive 5% of funds they successfully freeze and another 5% of funds they recover. However, Bitget excludes actions performed under court orders or law-enforcement requests.
The exchange also has added a recovery information portal, a fund-tracing dashboard, and an API to track addresses of attackers.
Furthermore, Bitget is going to adopt Bybit’s LazarusBounty recovery initiative as one of its main channels. In February 2025, Bybit’s exchange suffered a significant breach of $1.5 billion. There was a previous $1.5 billion hack of Bybit in February 2025.
Industry implications and upcoming security briefing
The Bitget withdrawal restart shows the difficulties that exchanges have when dealing with security problems. Getting withdrawals online means more checks, especially when bad people move money between different blockchains.
The incident also comes with some questions regarding the security of exchange wallets and the protection measures taken by them to safeguard their customers.
The protection fund set up by Bitget offers a financial cushion, but its ultimate payouts are yet to be determined in ongoing investigations. Meanwhile, the exchange’s gradual rollout provides security teams extra time to verify each withdrawal network.
On September 28, 07:30 UTC, Chen will be holding a live Ask Me Anything session. The session will take place 30 minutes prior to the reopening of the Bitcoin withdrawals, and will cover the incident and the recovery process.
Bitget hasn’t disclosed the full amount of assets that were frozen or published its final conclusions. The next briefing and rollout of withdrawal will deliver additional updates.





