Bitget to Resume Withdrawals From Sept. 28 as Hack Loss Estimate Rises to $387.5 Million
Key Takeaways
- •Bitget raised its estimated losses from the September 24 hack to roughly $387.5 million, up from an earlier estimate of about $351 million, after additional linked assets were identified.
- •Withdrawal services will resume in phases, with Bitcoin returning on September 28, ETH on September 29, USDT on September 30, and other tokens, fiat, and P2P services from October 2.
- •Bitget said user account balances remain unaffected and its User Protection Fund will cover the hack's financial impact, while additional security checks continue.
- •Circle and Tether froze approximately $318,000 in stablecoins at an attacker-linked address, though other attacker-linked wallets still hold more than 63,000 ETH beyond the issuers' freezing power.
- •CEO Gracy Chen announced a September 28 AMA ahead of the Bitcoin withdrawal restart and reiterated Bitget's plan to pursue an IPO within the next three years.

Bitget will begin restoring withdrawals in stages from Sept. 28 after revising its estimated losses from the Sept. 24 crypto hack to approximately $387.5 million, a figure that rose after additional assets linked to the incident were identified. The revised estimate is up from an earlier figure of about $351 million. The exchange said the underlying vulnerability has been fixed and that additional security checks remain underway. Bitcoin withdrawals are scheduled to return first, followed by ETH and USDT on selected networks.
Phased Resumption Starts With Bitcoin
In an official announcement, Bitget said its security and technical teams have been conducting additional validation and security checks across its withdrawal infrastructure following the Sept. 24 incident.
Under the restoration schedule, BTC withdrawals will be available on the Bitcoin network on September 28. On September 29, ETH will resume on Ethereum, BSC, Arbitrum, Base and Optimism. USDT withdrawals will follow on September 30 on Ethereum, BSC, Solana and Tron, while withdrawals for other tokens, fiat and P2P services will begin from October 2.
Bitget said user account balances remain unaffected by the hack. The exchange's User Protection Fund will cover the financial impact, with losses valued at $351 million.
CEO Cites Approach Distinct From Bybit's
Bitget CEO Gracy Chen said in a post on X that the exchange is taking a different approach from Bybit's response to its $1.5 billion hack, noting that the Sept. 24 Bitget incident involved multiple blockchains and cryptocurrencies. Bybit's hack, which took place in February 2025, is the largest recorded theft from a crypto exchange to date.
Chen also announced a live AMA scheduled for September 28 at 07:30 UTC, 30 minutes before Bitcoin withdrawals are due to resume. She said she will cover the withdrawal restoration, next steps and community questions during the session.
Chen added that she hopes Bitget can turn the crisis into an opportunity to demonstrate that users' trust in the exchange is well placed. She also said Bitget still plans to proceed with an IPO in the next three years.
Circle and Tether Freeze $318,000 in Stablecoins
According to an earlier CoinDesk investigation, Circle and Tether have frozen approximately $318,000 in stablecoins linked to the Bitget hack. The two issuers blacklisted an address labeled "Bitget Exploiter 8," freezing 218,023 USDT and 99,990 USDC. The freezes came as Bitget moved to trace funds across attacker-linked addresses.
Both issuers control their tokens at the contract level, allowing them to blacklist addresses and block further transfers of USDT and USDC by their holders.
Circle took action at 05:00 UTC on September 25, while MistTrack later confirmed that Tether had also blacklisted the address. The frozen funds represent only a small portion of the stolen assets. MistTrack data indicates that other attacker-linked addresses still hold more than 63,000 ETH, which falls outside the stablecoin issuers' freezing powers.
In a post on X, Chen said: "Thank you to Circle and Tether for moving quickly. Every address frozen matters."
Chen further said that the exchange has publicly identified and is actively tracking addresses linked to the attacker, and that Bitget is formally asking THORChain, a cross-chain protocol, to refuse service to those addresses. Cross-chain protocols such as THORChain enable asset swaps between different blockchains without a centralized intermediary.
$1.23 Million in ETH Sent to Attacker-Linked Wallet
Citing data from Arkham Intelligence, on-chain analytics platform Lookonchain reported that a wallet identified as 0x4885 transferred 457.9 ETH, worth approximately $1.23 million, to a wallet linked to the Bitget hacker.
According to the report, the wallet withdrew 257.6 ETH, valued at around $692,000, and 545,000 USDT from Binance about 11 hours earlier. It then swapped the USDT for 200.2 ETH before transferring the combined 457.9 ETH to the attacker-linked wallet approximately an hour before the report, with the transactions spanning a roughly 12-hour window.
With the phased restart underway, the near-term milestones are the September 28 AMA and Bitcoin resumption, the September 30 USDT rollout and the October 2 return of remaining withdrawal channels, alongside the completion of Bitget's remaining security checks.
The investigation remains ongoing, and on-chain wallet labels do not establish legal ownership or attribution. This article is for informational purposes only and does not constitute financial or investment advice.