Bitget, the Seychelles-based cryptocurrency exchange, will begin restoring customer withdrawals on September 28, starting with Bitcoin (BTC), four days after an attacker moved about $387.5 million from parts of its wallet infrastructure. The exchange says it has fixed the flaw behind the breach, user account balances are unaffected, and it will reopen all remaining assets in stages through October 2.
Bitget published the schedule on its support center at 03:55 Coordinated Universal Time (UTC) on September 26. The exchange said its security and technical teams are running further validation checks across the withdrawal infrastructure, while Mandiant, the Google-owned cybersecurity firm, and blockchain security company SlowMist continue to support the investigation. It described the pause as a security step unrelated to the availability of user assets, and said trading and deposits remain open.
Bitget Withdrawal Resumption Schedule
Each phase opens at 08:00 UTC: Bitget
| Date | Asset | Networks |
| September 28 | Bitcoin (BTC) | Bitcoin |
| September 29 | Ether (ETH) | Ethereum, BSC, Arbitrum, Base, Optimism |
| September 30 | Tether (USDT) | Ethereum, BSC, Solana, TRON |
| October 2 | Other tokens, fiat and peer-to-peer (P2P) | Not specified |
BSC refers to BNB Smart Chain. Arbitrum, Base and Optimism are layer-2 networks that process transactions off Ethereum’s main chain and settle back to it. USDT is Tether’s US dollar-pegged stablecoin.
Several assets involved in the attack, including XRP, Zcash (ZEC), TRON (TRX) and Avalanche (AVAX), are not named in the first three phases and fall under the October 2 batch. Bitget said the rollout applies to all users on the same terms, that customers do not need to take any action, and that withdrawal availability will appear directly on the platform.
In the same notice, Bitget said Chief Executive Officer (CEO) Gracy Chen will host a live Ask Me Anything (AMA) session at 07:30 UTC on September 28, half an hour before Bitcoin withdrawals reopen, to address the incident and the restoration process.
How the Bitget Breach Unfolded
Bitget’s security systems detected unauthorized transfers from some of its hot wallets at 18:31 UTC on September 24, according to the exchange’s original security notice. Hot wallets stay connected to the internet to process routine withdrawals, while cold wallets are kept offline. Bitget uses a three-tier wallet structure, and said the breach was confined to portions of its hot and warm wallet layers while cold wallets remained secure.
The first estimate put affected funds at about $351.6 million. Bitget said the loss fell within its User Protection Fund, which held more than $464 million at the time, and paused withdrawals pending a security review while keeping deposits and trading running. It also said relevant authorities and on-chain security firms had been notified.
At the initial figure, the incident would rank as the largest reported exchange hack of 2026 so far. Chen later said, in official updates on X and in a livestream, that patterns were consistent with groups previously linked to North Korea, and said the attacker breached a backend system and spoofed transaction data rather than stealing private keys. Attribution has not been confirmed, and the investigation remains open.
Loss Figure Revised to $387.5 Million
On September 25, Bitget raised the confirmed figure to about $387.5 million after further on-chain tracing. The $35.9 million increase came from Zcash and TRON transfers left out of the first estimate, and the exchange said it did not reflect any new unauthorized movement of funds. The same update committed to announcing withdrawal timing by 04:00 UTC on September 26, a deadline the resumption notice met with five minutes to spare.
The affected assets are XRP, Ether (ETH), Tether (USDT), Zcash (ZEC), USD Coin (USDC), USDT0, Tether Gold (XAUt), BNB, Avalanche (AVAX) and TRON (TRX), spread across Ethereum and several Ethereum Virtual Machine (EVM) compatible networks, the XRP Ledger, Zcash and TRON. USDT0 is a cross-chain version of Tether’s stablecoin, and XAUt is a token backed by physical gold.
XRP made up the largest single slice of the transferred assets in early tallies, with on-chain monitor Lookonchain counting about 102.93 million XRP.
At $387.5 million, the confirmed loss equals roughly 84% of the more than $464 million the User Protection Fund held on September 24. Bitget maintains that the fund covers the financial impact of the incident.
Recovery Bounty and Fund Tracing
Bitget said some affected assets have already been frozen through coordination with industry partners. Its Recovery Bounty Program offers 5% of successfully frozen funds and 5% of successfully recovered funds to the person or entity whose voluntary efforts directly produce that result. Actions taken under court orders or law-enforcement requests are excluded, and Bitget retains final say over eligibility and payouts.
Earlier, Chen said blockchain foundations had frozen some wallet addresses used in the attack. Bitget has not disclosed the total value frozen so far.
The exchange has published a live fund tracing dashboard, a portal for submitting recovery information and a real-time API tracking attacker addresses. It will also use LazarusBounty, a recovery initiative run by rival exchange Bybit, as a core channel. Bybit lost about $1.5 billion on February 21, 2025, in a theft the US Federal Bureau of Investigation (FBI) attributed to North Korea.
What Remains Unconfirmed
Bitget has not yet published a full incident report with a root-cause analysis, and forensic work with Mandiant and SlowMist is ongoing. The identity of the attacker, the total value frozen, and whether each phase opens on schedule are still unconfirmed. The September 28 AMA is the next scheduled public briefing, and Bitget has asked users to follow only its official channels for updates.
Also Read: Is Bitget the Next FTX? What the $351.6 Million Hack Does and Doesn’t Have in Common
