Bitget resumes withdrawals in stages after $388m exploit
The exchange says it has patched the vulnerability behind the Sept. 24 theft and that its user protection fund will cover all losses.
Key points
- Bitget began processing BTC withdrawals on the Bitcoin network at 8 a.m. UTC on Monday, Sept. 28.
- ETH withdrawals on Ethereum, BSC, Arbitrum, Base and Optimism open on Sept. 29; USDT on Ethereum, BSC, Solana and Tron follow on Sept. 30.
- All remaining assets, fiat withdrawals and P2P transactions are due to be restored on Oct. 2.
- The Sept. 24 exploit drained about $388 million, the largest reported crypto theft of the year, exceeding KelpDAO and Drift Protocol.
- The Bitget User Protection Fund, holding 5,500 BTC, will fully cover losses, and a bounty pays 5% of any frozen attacker funds.
Bitget has started a phased resumption of withdrawals after an exploit drained about $388 million from the exchange on Sept. 24, The Block reports. The exchange said it patched the vulnerability and that a user protection fund will fully cover the losses.
In a statement shared with The Block, Bitget said it began processing BTC withdrawals on the Bitcoin network at 8 a.m. UTC on Monday, as scheduled. Each chain must pass a series of security checks before withdrawals can restart, which is why the exchange is restoring services in stages rather than all at once.
Withdrawals restart in stages
Under the timetable, ETH withdrawals on Ethereum, BSC, Arbitrum, Base and Optimism open on Sept. 29 at 8 a.m. UTC. USDT withdrawals on Ethereum, BSC, Solana and Tron resume at the same time the following day, while all remaining assets, fiat withdrawals and P2P transactions are restored on Oct. 2.
The incident began at around 6:31 p.m. UTC on Sept. 24, when unauthorised transfers involving certain assets took place across multiple networks from Bitget's hot and warm wallet infrastructure. According to the exchange, the attacker exploited a vulnerability in a third-party security product to obtain high-level internal credentials.
How the exploit unfolded
Bitget said the attacker then used those credentials to send fraudulent withdrawal commands to the wallet system, causing abnormal transfers that bypassed risk controls. The Block previously reported that ether, USDT, USDC, AVAX and BNB were among the assets moved, though Bitget did not name the stolen assets in its latest statement.
The exchange said its private keys were not compromised and that user balances and cold wallets were unaffected. It plans to review how it assesses and deploys third-party security products, with Mandiant and SlowMist assisting the investigation. Bitget said the vulnerability is patched, the incident contained and no further unauthorised transfers have occurred.
Fund covers losses
The $388 million loss is the largest reported crypto theft so far this year, above exploits on KelpDAO and Drift Protocol. Bitget said the Bitget User Protection Fund, which holds 5,500 BTC, will cover the losses in full, and it has launched a bounty paying 5% of any attacker funds successfully frozen or recovered.
Bitget said it will not speculate on the attackers' identity until the investigation concludes, but described them as sophisticated and state-backed, with knowledge of how to obscure stolen funds. It previously told media it suspects North Korea is behind the attack.