0x6fdc49fd6fdc…6fdc49fa
Bitget Restarts Bitcoin Withdrawals After $388 Million Hack
Bitget resumed BTC withdrawals on September 28, four days after a $388 million exploit, with ETH, USDT and all remaining assets set to return by October 2 under a phased plan.

Outputs
Bitget resumed BTC withdrawals at 08:00 UTC on September 28 after a $388 million exploit on September 24.
ETH withdrawals reopen September 29 on Ethereum, BSC, Arbitrum, Base and Optimism; USDT follows September 30.
All remaining assets, fiat and P2P transactions are scheduled to be fully restored by October 2.
The attacker exploited a vulnerability in a third-party security product to steal internal credentials; cold wallets and user balances were untouched.
Bitget's User Protection Fund, holding 5,500 BTC, will cover the full loss; Mandiant and SlowMist are investigating.
Bitget suspects a state-backed attacker, telling media it believes North Korea was behind the operation.
Crypto exchange Bitget reactivated Bitcoin withdrawals at 08:00 UTC on September 28, four days after hackers drained roughly $388 million from the platform on September 24 — the largest reported crypto theft this year, exceeding exploits tied to KelpDAO and Drift Protocol.
The restoration is deliberately staggered. Bitget said in a post on X that it "has begun the phased resumption of withdrawals" and that the move "follows additional security work across Bitget's withdrawal infrastructure."
What does the recovery schedule look like?
Each blockchain network must clear its own security review before withdrawals reopen, according to the exchange. The full timeline runs to October 2:
- September 28: BTC withdrawals resumed on schedule.
- September 29, 08:00 UTC: ETH withdrawals reopen across Ethereum, BSC, Arbitrum, Base and Optimism.
- September 30: USDT withdrawals follow on Ethereum, BSC, Solana and Tron.
- October 2: All remaining assets, fiat withdrawals and P2P transactions fully restored.
How did the attackers get in?
The breach did not originate in Bitget's own wallet code. Unauthorized transfers began around 6:31 p.m. UTC on September 24, moving assets out of the exchange's hot and warm wallet infrastructure across multiple networks.
Bitget said the attacker exploited a vulnerability in a third-party security product it uses and obtained high-level internal credentials. "The attacker then used these credentials to send fraudulent withdrawal commands to the wallet system, causing it to execute abnormal transfers that bypassed risk controls," the exchange said in its statement.
Bitget did not list the specific tokens stolen in its latest statement, though The Block previously reported that ether, USDT, USDC, AVAX and BNB were among the assets moved.
The exchange maintains that containment held: private keys were never compromised, and user account balances and cold wallets remained unaffected throughout the incident. Bitget said it has patched the vulnerability and identified no further unauthorized transfers since containing the breach. It also committed to reviewing how it evaluates and deploys third-party security tools.
Who pays for the $388 million loss?
Bitget's User Protection Fund will cover the loss in full. The fund holds 5,500 BTC, and CEO Gracy Chen previously said it would return to its $300 million baseline within a week.
The exchange has also launched a bounty program offering 5% of any attacker funds frozen or recovered as a direct result of outside tips or action.
Who is behind the attack?
Bitget has engaged Mandiant and SlowMist to investigate the breach. The exchange described the attackers as "sophisticated" and "state-backed," noting they know how to obscure stolen funds, and told media outlets it suspects North Korea. It has declined to confirm attribution until the investigation reaches a firm conclusion.
The incident underscores a widening pattern in crypto security: attackers now target the vendors and tooling that exchanges rely on rather than the exchanges' own code. For centralized custody platforms, a breach routed through a third-party security product demonstrates that operational defenses extend beyond internal code audits to supply-chain risk — a factor likely to reshape how platforms vet outside vendors.
The October 2 deadline for full restoration of withdrawals, fiat and P2P services now serves as the market's next checkpoint on whether Bitget's recovery plan holds.
via en.cryptonomist.ch (Original)