0x765a7f95765a…765a7f98

ConfirmedSecurity593 vB105 sat/vB3 min decode

Bitget Restores Withdrawals After $388M Hack as Protection Fund Hits $309M

Bitget CEO Gracy Chen says withdrawals for all tokens resume Friday after a $388M breach, with the exchange's Protection Fund at $309M covering user losses.

Outputs

  1. Bitget CEO Gracy Chen said withdrawals for all tokens resume Friday after a breach that cost users $388 million.

  2. Bitget's Protection Fund, launched in January 2022 with 5,500 BTC, reached $309 million and covered the losses from the incident.

  3. ZachXBT reported wallets tied to the hack moved about $3.8 million in ZEC — 14% of the 18,917 ZEC stolen — into Zcash's Ironwood privacy pool.

Crypto exchange Bitget is resuming withdrawals for all tokens on Friday, CEO Gracy Chen announced in a Wednesday post on X, marking a staged return to normal operations after a security breach that drained $388 million in user funds.

Bitget has already restored user access to Bitcoin (BTC), Ether (ETH) and Tether (USDT), Chen said. The Seychures-registered exchange's self-funded insurance mechanism, the Bitget Protection Fund, grew to $309 million as part of the recovery effort.

"The Protection Fund was created for moments like this and absorbed the financial impact of the incident," Chen said in the post.

Bitget established the fund in January 2022, seeding it with 5,500 BTC to reimburse losses that were "not a result of any misconduct from the user or the platform itself" — a definition that covers certain security breaches. The company has said the capital is available "for instant deployment whenever the need arises."

Investigation continues amid attribution uncertainty

Speaking to Cointelegraph this week, Chen said Bitget has not narrowed its list of suspects for the $388 million attack. The exchange is still considering an inside job and North Korean state-linked hackers as possible explanations.

In response to the incident, Bitget launched a bounty program offering 5% of any frozen funds and 5% of recovered funds to parties who help secure or return the assets. The structure effectively deputizes third parties — including other exchanges, investigators and intermediaries handling laundered funds — to freeze and return stolen assets in exchange for a cut.

On-chain evidence shows the attackers remain active. Blockchain investigator ZachXBT reported on Wednesday that wallets tied to the Bitget hack moved roughly $3.8 million in Zcash (ZEC) into the network's Ironwood pool, a privacy mechanism that obscures transaction provenance. The transfers represented approximately 14% of the 18,917 ZEC stolen in the attack.

The movement signals an ongoing laundering phase. Zcash's shielded pools, including Ironwood, allow attackers to break the on-chain trail that investigators rely on to flag and freeze funds at downstream exchanges. The choice of a privacy chain over more common laundering routes through Ethereum-based bridges or cross-chain swaps suggests the perpetrators are prioritizing obfuscation over liquidity.

Containment efforts across the ecosystem

At least one adjacent protocol has acted to block the flow of stolen funds. NEAR Intents, a cross-chain interoperability service, said it blocked $50 million tied to the Bitget hackers — an indication that some of the stolen assets attempted to route through NEAR-based infrastructure before reaching their final destination.

The scale of the loss — $388 million — places the Bitget incident among the largest exchange breaches of the year, and the response playbook is now well-established across the industry: halt withdrawals, restore access to core assets first, deploy an insurance buffer, and publish bounty terms to create financial incentives for freezing funds in transit.

For Bitget, the operational stakes extend beyond reimbursement. The $309 million Protection Fund covers the immediate financial shortfall, but the exchange must now demonstrate that its custody and internal controls can withstand scrutiny — particularly given Chen's public acknowledgment that an insider compromise remains a live hypothesis. Exchanges that suffer large breaches typically face elevated withdrawal pressure, heightened regulatory attention and demands for proof-of-reserves verification once trading fully resumes.

The Friday withdrawal restart is the next checkpoint. A smooth resumption across all tokens would signal that Bitget has contained the operational damage; renewed delays or discrepancies could deepen confidence concerns and invite closer examination from regulators in the jurisdictions where the exchange operates.

via x.com (Original)

More from Marcus Bennett

Marcus Bennett

Show full bio

Senior reporter covering business strategy at Mempool Brief.

413 articles