key insights
- Bitcoin’s reopening provides the first operational test of Bitget’s revised withdrawal security controls.
- The exchange’s protection fund also provides financial support but successful customer withdrawals are another key indicator of recovery.
- Investigators are still working to track assets on networks and more discoveries may shed light on the third party security breach.
Bitget has started allowing Bitcoin withdrawals at 08:00 UTC on September 28. This happened four days after a security problem sent about $387.5 million to addresses controlled by attackers. The exchange is now giving customers access again while people look into the attack and try to find the stolen money.
This new step is the clear part of Bitgets plan to get withdrawals back. Ethereum, USDT, fiat currencies and peer-to-peer services are still going through planned security checks. Bitget says the money that customers have is still safe. The protection fund, from Bitget will take care of the losses.
Bitcoin withdrawal services return after four-day suspension
Bitget began processing Bitcoin withdrawals on September 28 after suspending withdrawals on September 24. The exchange confirmed that its security teams had completed checks on the Bitcoin withdrawal infrastructure.
Bitget has begun the phased resumption of withdrawals following the security incident identified on September 24, with BTC withdrawals on the Bitcoin network started at 08:00 UTC on September 28 as scheduled.
The resumption follows additional security work across Bitget's…
— Bitget (@bitget) September 28, 2026
By 09:00 UTC, Bitget had processed 9,585 withdrawal requests totaling approximately 4,098 BTC, according to the supplied reporting. The exchange also reported that it had contained the vulnerability and identified no further unauthorized transfers.
Chief Executive Gracy Chen addressed the incident during a livestream on September 28. She explained how the company identified the breach and outlined the security measures supporting the reopening.
Meanwhile, Bitget has maintained deposits and trading throughout the withdrawal suspension. The company says user account balances remained unaffected, although customers must still wait for individual networks and services to reopen.
The exchange has also stated that its User Protection Fund will absorb the financial losses. However, the reopening of Bitcoin withdrawals alone does not establish that every customer can access every affected asset.
Third-party security flaw exposed wallet infrastructure
The breach began at approximately 18:31 UTC on September 24, when Bitget detected unauthorized transfers involving parts of its hot and warm wallet infrastructure.
Bitget initially said the loss was around $351.6 million. Later after looking at blockchain data the number went up to about $387.5 million in funds sent to addresses controlled by the attacker.
Chen explained that the attacker found a weakness, in a third-party security tool. This flaw let the attacker get hold of top-level network access details. With those credentials the attacker could send withdrawal requests.
Bitget said the attacker used those stolen credentials to skip security checks. They were able to change how wallet approvals worked. Investigators also looked into how fake transaction records made it into backend systems.
The exchange maintains that attackers did not obtain private keys or compromise its cold wallets. However, the incident exposed weaknesses in the systems connecting internal security controls with withdrawal authorization.
Mandiant and blockchain security firm SlowMist are assisting the investigation. Bitget says its teams have patched the vulnerability and strengthened validation procedures before reopening withdrawal services.
The company also expects to publish an official security report this week, providing further details about the attack and its response.
Withdrawal schedule and financial protection measures
Bitget has scheduled additional services to return in phases, with each reopening dependent on security checks.
- September 28, 08:00 UTC — Bitcoin withdrawals resumed on the Bitcoin network.
- September 29, 08:00 UTC — ETH withdrawals are scheduled across Ethereum, BNB Smart Chain, Arbitrum, Base and Optimism.
- September 30, 08:00 UTC — USDT withdrawals are scheduled across Ethereum, BNB Smart Chain, Solana and Tron.
- October 2, 08:00 UTC — Remaining tokens, fiat withdrawals and peer-to-peer transactions are scheduled to return.
These dates represent Bitget’s announced timetable, rather than confirmation that every service has reopened.
The exchange previously valued its User Protection Fund at more than $464 million. Bitget has also said the fund has about 5500 BTC and they will compensate losses due to the breach.
However, this valuation of the funds is not sufficient to prove the speed at which any fund’s assets can be cashed out by their customers. The exchange must demonstrate that each withdrawal route operates securely as services return.
Stolen assets and industry security implications
Bitget keeps on following the stolen money with help from security firms and blockchain partners. The exchange has started a bounty program that gives a five percent reward for each asset that is frozen and for each successful recovery.
Circle and Tether had put about ninety‑nine thousand nine hundred ninety USDC and two hundred eighteen thousand twenty‑three USDT into a freeze that was tied to the attack as of September twenty‑six according to reports.
AMLBot, a blockchain compliance firm also followed about four bitcoins that were linked to the breach into a Wasabi CoinJoin transaction. The firm said that those bitcoins travelled through networks before arriving on the Bitcoin chain via THORChain.
At the time Bitget has released the addresses used by the attackers and set up a tracing portal. AMLBot estimated that about three hundred forty‑three million dollars were still idle in thirteen attacker wallets, as of September twenty‑five.





