Bitget Raises Hack Loss Estimate to $387.5 Million, Sets Staged Withdrawal Restart Plan
Key Takeaways
- •Bitget increased its loss estimate from the security breach to approximately $387.5 million, up from the initially reported $351.6 million, after tracing uncovered additional affected assets.
- •The exchange states it has identified and remediated the vulnerability used in the attack, and that independent firms Mandiant and SlowMist are participating in the investigation.
- •The compromised assets are spread across multiple networks, including Ethereum and other EVM-compatible chains, the XRP Ledger, Zcash, and TRON, which complicates tracing and recovery work.
- •Bitget introduced a bounty program that rewards parties whose actions directly lead to funds being frozen or recovered, and some assets have already been frozen through coordination with industry partners.
- •Withdrawal services will restart in stages, with Bitcoin resuming on September 28, Ether on September 29, USDT on September 30, and other tokens, fiat, and peer-to-peer services returning by October 2.

Cryptocurrency exchange Bitget has published a detailed update on this week's security breach, raising the confirmed value of assets transferred to attacker-controlled wallets and setting out a timetable for restoring withdrawal services.
The exchange now estimates the affected assets at approximately $387.5 million, up from its initial estimate of $351.6 million. According to Bitget, the revision reflects additional assets identified during transaction tracing rather than a second wave of unauthorized transfers. Loss estimates in major security breaches often move in the opening days of an investigation, as tracing work uncovers additional affected assets.
Vulnerability Patched, Bitget Says
According to the exchange, its security team has now identified the attack path and the method used to bypass existing controls. Bitget said the underlying vulnerability has been remediated and that no further unauthorized transfers are possible.
Independent teams from Mandiant and SlowMist are participating in the investigation. Both firms are established names in cybersecurity: Mandiant in incident response and SlowMist in blockchain security.
The revised loss estimate includes assets across multiple networks, including Ethereum and other EVM-compatible chains, the XRP Ledger, Zcash, and TRON. The breadth of networks involved complicates recovery work, because tracing and freezing assets must be coordinated separately on each chain.
Bitget has also launched a recovery bounty program. Eligible parties whose voluntary actions directly result in funds being frozen or recovered can receive a bounty calculated as a percentage of the assets secured. The exchange said some funds have already been frozen through coordination with industry partners.
Withdrawals to Return in Stages
Rather than switching everything back on at once, Bitget plans to reopen withdrawals gradually.
- Bitcoin withdrawals are scheduled to resume first, on September 28.
- Ether withdrawals across several supported networks are expected to follow on September 29.
- USDT withdrawals are set for September 30.
- Other tokens, fiat services, and peer-to-peer withdrawals are planned to return by October 2.
The staged restart means full withdrawal functionality will not return until early October at the earliest. Gradual reopens of this kind mean any issue can be isolated to a single asset category instead of affecting the platform as a whole.
That timetable is now one of the most important operational tests following the breach. Bitget has maintained that customer account balances remain intact and that its protection arrangements cover the financial impact. Restoring withdrawals is where users get to test that assurance in practice.
The updated $387.5 million figure also makes this a materially different story from the initial breach report. With the incident itself confirmed, the focus is shifting to remediation, asset recovery, and whether the exchange can reopen normally without creating another security problem.
For Bitget, containing the attack was step one. Getting customers their withdrawal access back is the next.
This article was written by the News Desk and edited by Samuel Rae.
Source: NewsBTC