Bitget Reopens Bitcoin Withdrawals After $387.5 Million Breach as Forensic Investigation Continues
Key Takeaways
- •Attackers exploited a vulnerability in a third-party security product to obtain internal access credentials and submit forged withdrawal commands that bypassed existing risk checks, while private keys and cold wallets were not compromised.
- •The loss estimate rose from $351.6 million on September 24 to $387.5 million after additional Zcash and TRON transactions were classified as part of the incident.
- •Bitget is reopening withdrawals in phases, with Bitcoin live since September 28 and Ethereum, USDT, remaining tokens, fiat and P2P services scheduled for September 29, September 30 and October 2 respectively.
- •Bitget's Protection Fund, holding more than $464 million when assessed, exceeds the identified loss and will absorb the impact, leaving user account balances unchanged.
- •Mandiant and SlowMist are conducting an independent forensic investigation with attacker attribution still unconfirmed, and THORChain's refusal to block exploiter addresses has sparked a debate over decentralization in permissionless protocols.

Bitget has begun reopening withdrawals after attackers drained roughly $387.5 million from parts of the exchange's hot and warm wallet infrastructure, while forensic teams continue tracing the funds and examining how the breach was carried out. Hot and warm wallets are the internet-connected systems exchanges use to process day-to-day withdrawals, while cold storage sits offline as a separate layer of protection.
According to Bitget's official incident disclosure, the attackers exploited a vulnerability in a third-party security product to obtain internal access credentials, then submitted forged withdrawal commands directly to the exchange's wallet systems. Because those instructions appeared as authorized activity, they slipped past existing risk checks. Private keys were not compromised, and Bitget's cold wallets remained unaffected.
The loss estimate was raised from the $351.6 million first identified on September 24 — when Crypto Adventure initially reported the breach — to $387.5 million after additional Zcash and TRON transactions were classified as part of the incident.
Bitcoin Withdrawals Resume After Four-Day Pause
BTC withdrawals went back online at 08:00 UTC on September 28 on Bitcoin and BNB Smart Chain, following extra security checks across Bitget's withdrawal infrastructure, per the exchange's published incident timeline. ETH withdrawals are scheduled for September 29 at 08:00 UTC across Ethereum, BNB Smart Chain, Arbitrum, Base and Optimism. USDT is set for September 30, with remaining tokens, fiat withdrawals and P2P services scheduled for October 2. The staged reopening means each network group comes back only after its checks are completed, so users on later phases face staggered timing for moving funds out. Throughout the suspension, trading and deposits remained available.
Bitget's Protection Fund held more than $464 million when the incident was assessed, exceeding the currently identified loss. The exchange has designated the fund — a reserve it maintains as a backstop against losses — to absorb the financial impact, leaving user account balances unchanged.
Attacker Attribution Still Unconfirmed
Bitget has stopped short of formally attributing the breach to North Korea or any other state-backed group. Mandiant, a threat intelligence firm, and SlowMist, a blockchain security company, are carrying out the independent forensic investigation, and attribution remains outside the exchange's confirmed findings while that work is ongoing. Until that work concludes, the full loss tally and the recovered share of funds remain open items.
The response has already progressed past containment into fund tracing and recovery. Some affected assets have been frozen through coordination with exchanges, blockchain projects and security firms, and Bitget is offering a 5% bounty for eligible voluntary actions that directly lead to assets being frozen or recovered.
The push to lock down the stolen funds has also exposed a dispute over permissionless cross-chain infrastructure. THORChain declined Bitget's request to block identified exploiter addresses, igniting a broader decentralization debate over whether validator-operated protocols should intervene when known stolen assets move through their systems. The disagreement turns on a structural difference from centralized venues: permissionless protocols operate without a central administrator, so there is no single party with the unilateral authority to block an address.
Bitget has ruled out private-key compromise and isolated the affected systems, and is strengthening controls around third-party security products — the entry point for the breach — as well as internal access, withdrawal verification and abnormal-activity monitoring. ETH withdrawals remain on schedule for 08:00 UTC on September 29, followed by USDT on September 30 and remaining withdrawal services on October 2, giving the coming days clear checkpoints for whether each restoration phase holds to its timetable.
Bitget's leadership has addressed the incident publicly, including in a post from Gracy Chen on X. This report is based on Crypto Adventure's coverage of the incident.