0x6d2edb286d2e…6d2edb2b
Bitget Reopens Bitcoin Withdrawals After $387.5 Million Breach
Bitget has resumed Bitcoin withdrawals roughly $387.5M drained from its hot wallets, while ETH and USDT remain paused and CEO Gracy Chen pledges to top up a $300M user protection fund within seven days.
Outputs
Bitget disclosed a $387.5 million hot-wallet breach on September 28, 2026
Bitcoin withdrawals resumed while ETH and USDT withdrawals remain paused
CEO Gracy Chen pledged to replenish the user protection fund above $300 million within the week
The protection fund top-up deadline falls on or before October 5, 2026
Bitget's Seychelles, Lithuania and Australia entities each carry separate breach-disclosure obligations
Exchange Restores BTC Flow, Caps Other Assets at $387.5M Loss
Bitget has resumed Bitcoin withdrawals after a hot-wallet exploit that drained approximately $387.5 million from the exchange, the firm disclosed on September 28, 2026. The trading venue kept Ether (ETH) and Tether (USDT) withdrawals frozen while engineers completed what it described as targeted security checks on the affected infrastructure.
The selective reopening is the most concrete operational signal from Bitget since news of the breach first surfaced, and it sets up a tiered recovery process in which the most liquid asset moves first while stablecoin and altcoin rails stay under review.
Who Is Accountable for the Loss?
The incident is the largest disclosed exchange loss of 2026 to date and ranks among the top five by nominal dollar value across centralized venues since the 2022 cycle, based on previously tracked incidents. Bitget has named the breach as a hot-wallet compromise rather than a broader treasury failure, a distinction that matters for custody architecture and for which wallets sit on the loss side of the firm's books.
CEO Gracy Chen has framed the response around a pre-funded backstop rather than a post-hoc socialized loss. "We pledge to replenish the protection fund above $300 million this week," Chen said in remarks reported by The Defiant, committing to capital that the exchange would deploy to cover affected users before any external reimbursement.
What Does the Protection Fund Actually Cover?
Bitget's protection fund is a discretionary reserve the firm draws on to compensate retail users when internal controls fail. The model mirrors Binance's SAFU and OKX's emergency fund, both of which have become standard reassurance devices for centralized exchanges after a string of high-profile failures.
The $300 million commitment signals that the depletion from the breach pushed the fund below its stated floor and that Bitget intends to restore that floor inside seven days. For users, the practical question is the gap between the $387.5 million disclosed loss and the $300 million top-up target — a roughly $87.5 million shortfall that would either be absorbed by Bitget's balance sheet, recovered through on-chain tracing, or split across users on a pro-rata basis.
Why Are ETH and USDT Still Paused?
The continued freeze on ETH and USDT suggests the attack vector has not been fully ring-fenced across asset classes. Bitcoin hot-wallet systems typically run on a different signing stack than ERC-20 and TRC-20 deployments, so a compromise of one key path does not necessarily imply a compromise of the others — but the time required to audit each rail explains the staged reopening.
For market makers and arbitrage desks, a partial halt on USDT rails is the more disruptive constraint, since most cross-exchange settlement routes tether into Tether. Independent OTC desks reported wider spreads on Bitget USDT pairs during the freeze, though quoting normalized after the BTC channel reopened.
What Comes Next for Bitget?
The protection fund top-up, due by October 5 based on Chen's "this week" framing, will be the next verifiable milestone. Bitget has also signaled that ETH and USDT withdrawals will resume once per-asset forensic reviews conclude, with no public timeline yet attached.
The exchange's longer task is regulatory: Bitget's Seychelles-registered operating entity and its licensed regional arms in Lithuania and Australia each maintain separate reporting obligations, and any breach above the materiality thresholds in those jurisdictions triggers disclosure to local supervisors. The exchange has not yet confirmed whether it has filed such notifications, a step that would determine whether the incident becomes a multi-jurisdictional enforcement matter or remains confined to internal remediation.
via fil.org (Original)