0x07bef42f07be…07bef432
Bitget Resumes BTC Withdrawals After $388M Hot-Wallet Exploit
Bitget restored BTC withdrawals Sept. 28 after a $388M hot-wallet exploit. The exchange said its User Protection Fund will absorb losses; full service resumes Oct. 2.

Outputs
Roughly $388 million was drained from Bitget's hot and warm wallets beginning around 6:31 p.m. UTC on Sept. 24
BTC withdrawals reopened at 8:00 a.m. UTC on Sept. 28, four days after the intrusion
Full restoration, including fiat and P2P services, is scheduled for Oct. 2
Bitget's User Protection Fund, which holds 5,500 BTC, will absorb the entire loss
The incident is the largest reported crypto hack of 2026, surpassing earlier breaches at KelpDAO and Drift Protocol
Bitget resumed bitcoin withdrawals at 8:00 a.m. UTC on Sept. 28, restoring the first leg of service four days after an exploit drained roughly $388 million from its hot and warm wallets.
The exchange described the unauthorized transfers, which began around 6:31 p.m. UTC on Sept. 24, in a written statement. "The attacker then used these credentials to send fraudulent withdrawal commands to the wallet system, causing it to execute abnormal transfers that bypassed risk controls," Bitget said.
What happened during the attack?
The breach originated in a vulnerability in a third-party security product that let the attacker obtain high-level internal credentials, according to the exchange. With those credentials in hand, the intruder instructed the wallet system to execute abnormal transfers that sidestepped risk controls.
Bitget emphasized that private keys, cold wallets and user balances were not compromised, limiting the blast radius to operational hot and warm wallet infrastructure. The flaw has since been patched, though the exchange did not name the third-party vendor involved.
The intrusion unfolded over a narrow window, beginning around 6:31 p.m. UTC on Sept. 24 and culminating in the roughly $388 million loss that Bitget confirmed four days later.
How is Bitget rolling out withdrawals?
The exchange is taking a staggered approach, restarting withdrawals chain by chain only after each network clears a fresh round of security checks. BTC withdrawals opened first, at 8:00 a.m. UTC on Sept. 28.
Ethereum, BSC, Arbitrum, Base and Optimism withdrawals are scheduled for Sept. 29. USDT on Ethereum, BSC, Solana and Tron follows on Sept. 30. All remaining tokens, fiat withdrawals and P2P transactions are scheduled to return on Oct. 2.
Bitget said the schedule applies to every user equally. Trading and deposits have continued throughout the incident, allowing users to reposition funds even while withdrawals were paused.
Who is investigating the breach?
Mandiant and blockchain forensics firm SlowMist are assisting with the investigation, according to Bitget. An official security report is expected within the week.
CEO Gracy Chen is set to host a live AMA at 7:30 a.m. UTC on Monday to walk through the incident and the restoration plan.
How will Bitget cover the losses?
Bitget said the $388 million theft will be absorbed entirely by its User Protection Fund, which holds 5,500 BTC. The exchange has launched a bounty offering 5% of any attacker funds that investigators freeze or recover.
Some assets have already been frozen with help from industry partners, the exchange added. Bitget characterized the attackers as "sophisticated" and "state-backed," and has previously told media outlets it suspects North Korea was behind the incident.
What is the broader context?
The exploit is the largest reported crypto hack of 2026 so far, surpassing earlier incidents at decentralized finance protocols KelpDAO and Drift Protocol. The case underscores the operational risk that concentrated hot-wallet balances pose for centralized exchanges, where the bulk of customer deposits typically sits in cold storage but a working float remains online.
It also highlights how a single third-party software compromise can cascade into privileged internal access, even when private keys themselves are untouched. Whether Bitget completes the multi-chain restoration by Oct. 2 — and whether the official report names a specific threat actor — will shape the regulatory and reputational fallout for the rest of the year.
via bitbo.io (Original)
More from Elena Vasquez
Show full bio
Staff writer covering marketplaces and e-commerce at Mempool Brief.
440 articles