Bitget Resumes Bitcoin (BTC) Withdrawals After $388M Hack
Bitget resumed Bitcoin (BTC) withdrawals at 08:00 UTC on Sept 28, four days after a $388M hack. ETH and USDT follow as security checks complete.
AI SummaryAI
- Bitget resumed Bitcoin withdrawals at 08:00 UTC on Sept 28 after the Sept 24 breach.
- Bitget revised the stolen total to $387.5 million after Zcash and Tron transfers.
- The attacker swapped stolen ETH for BTC via THORChain, which says no selective freeze exists.
- Bitget moved 2,042.28 BTC, worth about $169 million, from its Protection Fund to hot wallets.
Bitcoin Withdrawals Resume on Bitget
Bitget switched Bitcoin (BTC) withdrawals back on at 08:00 UTC on Monday, four days after a Sept. 24 security breach that touched roughly $388 million in assets. The Bitcoin network and BNB Smart Chain came online first, with additional assets and networks set to follow over the coming days. Speaking during a Monday ask-me-anything session, Bitget CEO Gracy Chen explained that BTC returned first because its withdrawal pipeline was the earliest to clear internal checks, while Ether (ETH) and Tether's USDT would follow as security reviews progress. Under the published schedule, ETH withdrawals resume Tuesday across Ethereum, BNB Smart Chain, Arbitrum, Base and Optimism, with USDT following Wednesday on Ethereum, BNB Smart Chain, Solana and Tron. Remaining assets, fiat rails and peer-to-peer services are slated for Oct. 2. The exchange stressed the timetable applies to every user — no priority lanes for institutions, VIP clients or employees — and account holders need no extra steps.
Forged Credentials, $387.5M Drained
The breach itself traces to the evening of Sept. 24, when unauthorized transfers began moving out of Bitget's hot and warm wallet infrastructure. According to the exchange's incident disclosures, the attacker exploited a vulnerability in a third-party security product the platform relied on, obtained high-level internal credentials, and pushed forged withdrawal data through the wallet system to trigger approvals and bypass risk controls. Critically, private keys were not compromised, cold wallets stayed untouched, and user balances were never affected. Bitget initially put the damage at $351.6 million, then revised the figure to $387.5 million after accounting for additional movements on Zcash and Tron — making this the largest crypto theft recorded so far in 2026. External security firms Mandiant and SlowMist are assisting the investigation, and the exchange says it has patched the flaw, confirmed no new unauthorized transfers since containment, and already frozen a portion of the stolen assets.
THORChain Can't Selectively Freeze Funds
Recovering the money is proving harder than containing the breach. On-chain data shows Ether linked to the attacker flowing into THORChain vaults, where it is being swapped for Bitcoin — a whale-sized trail now crossing chains through the decentralized swap protocol, the same cross-chain rails that power Wrapped Bitcoin (WBTC)-style asset movement between networks. Chen publicly called on THORChain to refuse services to addresses tied to the attack, but the protocol pushed back in a Monday statement, arguing its network halt is an emergency security mechanism that affects the system broadly and cannot selectively freeze specific funds. Analysts note THORChain has no built-in address blacklist, so halting trading or pausing a connected chain would hit ordinary users as much as the attacker — leaving Bitget's freeze-and-recover strategy dependent on external jurisdictions and its bounty program rather than protocol-level enforcement.
5,500 BTC Fund Absorbs the Loss
Bitget is funding the restart from its own reserves. Ahead of Monday's reopening, 2,042.28 BTC — roughly $169 million — was moved from the exchange's strategic Bitcoin reserve-style Protection Fund into hot wallets, per the exchange's own data; on-chain records show 3,457.72 BTC still sitting at fund-linked addresses. The transfer was made to pre-fund expected withdrawal demand, not to reflect user outflows, and drew from a fund holding about 5,500 BTC at the time of the hack. Bitget has committed to covering the full loss from that fund, which stood near $464 million when the incident hit — more than the stolen amount. It has also launched a bounty promising 5% of any attacker funds successfully frozen or recovered, a pot worth up to roughly $19.4 million at the current theft figure and among the largest recovery rewards in industry history. Readers tracking the market in real time can follow live spot and futures prices on MEXC.
Supply-Chain Risk Defines the Aftermath
Read together, these threads form one arc: containment within hours, restitution inside a week, and a laundering battleground the attacker still controls. Our reading of the on-chain evidence and the exchange's incident disclosures is that the root cause — a third-party vendor flaw paired with compromised internal credentials, not key theft — is now firmly established, with the drained total verifiable on-chain across multiple chains, including Zcash and Tron. Whether venues ranked among the best crypto exchanges harden their third-party security reviews — and whether the bounty actually recovers funds — will define how this case closes. Track our latest Bitcoin news as the phased restart unfolds through Oct. 2.
Related Tags

AI-generated, AI-reviewed, under COINOTAG editorial oversight.


