Bitget Sets Sep. 28 Restart for Bitcoin (BTC) Withdrawals in Staged Recovery Plan

Bitget will restart Bitcoin (BTC) withdrawals at 08:00 UTC on Sep. 28, stage one of a four-phase reopening after the wallet breach was revised to $387.5M.

(09:01 AM UTC)
4 min read
AI SummaryAI
  • Bitget will resume Bitcoin (BTC) withdrawals at 08:00 UTC on Sep. 28, first of four stages.
  • Losses from the Sep. 24 attack were revised up 10.2% to $387.5 million from $351.6 million.
  • Attackers breached Bitget's backend wallet system and forged transaction data; private keys were not compromised.
  • Bitquery traced at least 126.71 BTC converted from stolen funds; Tether froze about 239,000 USDT.
k7rq2fdm

Bitcoin Withdrawals Return First on Sep. 28

Bitget will restart Bitcoin (BTC) withdrawals at 08:00 UTC on Sep. 28, the first step of a four-stage reopening plan the exchange published after a security incident on Sep. 24 forced it to suspend all outbound transfers. The exchange had detected unauthorized transfers from some of its wallets that day and halted withdrawals while tracing the outflows, even as trading and deposits stayed open. According to the official announcement, Ether (ETH) withdrawals follow at the same hour on Sep. 29 across five networks — the Ethereum network, BNB Smart Chain, Arbitrum, Base and Optimism — with USDT set for Sep. 30 on Ethereum, BNB Smart Chain, Solana and Tron. Remaining tokens, fiat services and peer-to-peer transactions close out the schedule on Oct. 2. Two details in the plan matter for customers. A token's return date does not mean every network reopens at once: Bitget named five chains for ETH and four for USDT, and gave no network-by-network list for the assets in the final stage. And the pause never touched balances — the exchange described the suspension as a temporary security measure, said customer account balances were unchanged, and told users no action is required before withdrawals resume, with each service confirmed through official notices as checks complete. On the forensic side, the technical team says it has identified and fixed the vulnerabilities tied to the incident and is re-verifying withdrawal systems before they go live again, with Mandiant, the cybersecurity firm owned by Google, and blockchain security firm SlowMist assisting. The stages convert to mid-afternoon local time in Asian markets, a timing detail regional desks flagged quickly. For customers in stage one, the Sep. 28 Bitcoin window is the first hard date — and the first live test of whether the patched systems hold under real load.

$387.5M Revision and the Backend Breach

Bitget's revised accounting now puts transfers to attacker-controlled addresses at about $387.5 million, up from its initial estimate of $351.6 million — an increase of roughly $35.9 million, or 10.2%. The revision is not a second theft: continued tracing added Zcash and TRON assets the first tally had not fully counted, and the exchange says no new unauthorized transfers have occurred since the incident was contained. Confirmed affected assets span XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX and TRX, moving across Ethereum and other EVM-compatible chains, the XRP Ledger, Zcash and Tron. The root-cause disclosure is the most consequential detail in the post-mortem. Bitget says attackers did not obtain private keys; they broke into a critical backend system in the exchange's wallet infrastructure, forged transaction data and triggered the platform's own legitimate signing flow — the system itself signed malicious transactions that looked like valid authorization. In a public update on X, Bitget said its technical team has identified and fixed those vulnerabilities. Chief Executive Gracy Chen earlier raised a possible North Korean connection, citing IP-address and VPN similarities, though no government attribution has been confirmed. Recovery mechanics are already running. Bitget published the attacker addresses and launched a Recovery Bounty Program paying 5% of the value of any assets a third party freezes or helps recover; leads are being collected through Bybit's LazarusBounty platform. On-chain analytics firm Bitquery traced at least 126.71 BTC in whale-scale conversions from stolen BNB and TRX as of Sep. 25, and Tether has frozen roughly 239,000 USDT across two attacker addresses. The backstop is the User Protection Fund, which Bitget reported at more than $464 million during the pause; according to Blockcast, the fund's core holding is 5,500 BTC — a reserve that functions much like a miniature strategic bitcoin reserve — and a loss of this size equals roughly 84% of its marked value. Readers tracking the market in real time can follow live spot and futures prices on Bitget.

On-Chain Clawback Gains Urgency

COINOTAG's read of the on-chain flow is that the clock now works against the attacker: conversions into at least 126.71 BTC and Tether's freeze of about 239,000 USDT show exit liquidity being hunted in real time, while a 5% bounty turns the market itself into a distributed tracing network. The backend-signing root cause — not a private-key leak — limits the blast radius and keeps cold-wallet architecture intact, which is why the staged restart under external forensics looks credible. The open question is the fund: absorbing a hit equal to roughly 84% of its marked value is a stress test few exchange insurance funds have faced, and how Bitget replenishes it will shape how traders weigh custodial HODL convenience against self-custody — a comparison our Best Crypto Exchanges guide tracks closely.

COINOTAG News Desk

COINOTAG News Desk

COINOTAG's editorial and research desk.

How our News Desk works
AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.