TLDR:
- Bitget reopened BTC withdrawals on the Bitcoin network at 08:00 UTC on September 28 as scheduled.
- The September 24 exploit drained about $388 million, the largest reported crypto theft this year.
- The attacker used a flaw in a third-party security product to obtain high-level internal credentials.
- The Bitget User Protection Fund, holding 5,500 BTC, will cover all losses from the incident.
Bitget withdrawals have begun to resume following the September 24 security incident that drained about $388 million from the exchange.
The platform reopened BTC withdrawals on the Bitcoin network at 08:00 UTC on September 28, as scheduled. Bitget said it has remediated the vulnerability and identified no further unauthorized transfers since containment.
User account balances remain unaffected. The exchange also confirmed that the Bitget User Protection Fund will cover the losses in full.
Phased Schedule for Bitget Withdrawals
Bitget said each blockchain must pass a series of security checks before it reopens. For this reason, the exchange is restoring services in stages. Bitget withdrawals on each network will open only after those checks are complete.
In a post on X, Bitget said it “has begun the phased resumption of withdrawals” following the incident. BTC withdrawals started at 08:00 UTC as planned. The exchange said the resumption “follows additional security work across Bitget’s withdrawal infrastructure.”
Next, ETH withdrawals on Ethereum, BSC, Arbitrum, Base, and Optimism will open on September 29 at 8 a.m. UTC. USDT withdrawals on Ethereum, BSC, Solana, and Tron will resume at the same time on September 30.
Meanwhile, all remaining assets, fiat withdrawals, and P2P transactions will return on October 2. Bitget withdrawals will therefore be fully restored in four steps, according to the exchange.
How the Exploit Unfolded
Unauthorized transfers began at around 6:31 p.m. UTC on September 24. They involved certain assets across multiple networks and originated from Bitget’s hot and warm wallet infrastructure. Its latest statement confirmed the $388 million figure but did not list the specific tokens.
The exchange said the attacker targeted a vulnerability in a third-party security product. This allowed the attacker to obtain high-level internal credentials.
According to Bitget, the attacker sent “fraudulent withdrawal commands to the wallet system,” causing abnormal transfers that bypassed risk controls. Bitget stated that its private keys were not compromised. Cold wallets and user balances were also unaffected.
The $388 million loss is the largest reported crypto theft this year, above exploits on KelpDAO and Drift Protocol. The fund holds 5,500 BTC. CEO Gracy Chen previously said the fund would return to its $300 million baseline within a week.
Mandiant and SlowMist are assisting with further investigation into the incident. The exchange will also review how it assesses and deploys third-party security products.
Additionally, Bitget launched a bounty that pays 5% of any attacker funds frozen or recovered. However, it said it will not speculate about the attackers’ identity until the investigation reaches a firm conclusion.
The exchange described the attackers as “sophisticated” and “state-backed,” and it suspects North Korea. It said they know how to obscure stolen funds.



