Bitget Gradually Resumes Withdrawals After $388 Million Hack, Targets Full Recovery by Oct. 2
Summary
- Bitget said it has begun gradually restoring withdrawals, starting with Bitcoin (BTC), after a hack worth about $388 million.
- It said the remaining crypto and fiat withdrawals, including Ethereum (ETH) and Tether (USDT), as well as P2P trading, will be restored by Oct. 2.
- The exchange said it will fully cover the losses through its user protection fund, has already frozen some of the stolen assets, and is operating a bounty program that pays 5% of recovered funds to tipsters.
Forecast Trend Report by Period



Crypto exchange Bitget has begun gradually resuming withdrawals after suspending the service following a roughly $388 million hack.
The Block reported on Sept. 28 that Bitget resumed Bitcoin withdrawals at 8 a.m. UTC on the Bitcoin and BNB Smart Chain networks. The exchange said it is restoring withdrawals in phases after completing security checks on each network.
Ethereum withdrawals will resume at 8 a.m. UTC on Sept. 29 across the Ethereum, BNB Smart Chain, Arbitrum, Base and Optimism networks. Tether withdrawals will restart at the same time on Sept. 30 on the Ethereum, BNB Smart Chain, Solana and Tron networks. The remaining cryptocurrency and fiat withdrawals, as well as peer-to-peer trading, are scheduled to be restored by Oct. 2.
The breach came to light on Sept. 24 after abnormal fund transfers were detected across multiple networks from Bitget's hot and warm wallets. According to Bitget, the attacker exploited a vulnerability in a third-party security product used by the exchange to gain a high level of internal access. The attacker then issued false withdrawal instructions to the wallet system, bypassing risk-control procedures.
Bitget said $388 million of crypto assets was stolen in the attack. It was the largest reported cryptocurrency hack this year. The exchange said private keys were not compromised, and customer account balances and cold wallets were unaffected. The vulnerability has been fixed, and no additional unauthorized transfers have been detected.
The exchange said it will fully cover the losses through its user protection fund, which holds 5,500 Bitcoin. It is also operating a bounty program that will pay 5% of recovered funds to tipsters who directly help freeze or recover the stolen assets. Some of the assets have already been frozen through industry cooperation, though Bitget did not disclose the amount.
Bitget is investigating the incident with support from Mandiant, a Google Cloud security company, and blockchain security firm SlowMist. It plans to release an official security report this week. The exchange said a sophisticated state-backed hacking group may have been involved and had previously said it suspected North Korea. The attacker's identity has not been confirmed.
Suehyeon Lee
shlee@bloomingbit.ioI'm reporter Suehyeon Lee, your Web3 Moderator.