Bitget Hack Update: BTC Withdrawals Are Open; ETH Restoration Is Next After $388M Breach

Extracto:Bitget confirms BTC withdrawals reopened Sep. 28 at 08:00 UTC on Bitcoin and BSC after its ~$388M backend breach. ETH is scheduled Sep. 29 at 08:00 UTC, while forensic investigation and stolen-fund recovery continue.

Bitget has completed the first planned withdrawal-recovery milestone after the September 24 breach.

The exchange confirms that:

BTC withdrawals resumed at 08:00 UTC on September 28

and are open on:

  • the Bitcoin network;
  • BNB Smart Chain.

This materially improves the user-access picture compared with the full withdrawal freeze in place immediately after the incident.

What is open now

BTC withdrawal support is confirmed operational on two networks.

Bitgets remaining schedule is:

  • Sep. 29 08:00 UTC: ETH on Ethereum, BSC, Arbitrum, Base and Optimism;
  • Sep. 30 08:00 UTC: USDT on Ethereum, BSC, Solana and Tron;
  • Oct. 2 08:00 UTC: other supported tokens, fiat withdrawals and P2P.

At this reports cutoff, the ETH milestone remains in the future.

The incident amount is now described as approximately $388M

Bitgets updated incident page uses approximately:

$388 million

as its current estimate.

The exchange says the incident involved 12 wallet addresses associated with hot or warm wallet infrastructure and activity across 11 blockchains.

Affected assets identified to date include:

  • XRP;
  • ETH;
  • USDT;
  • ZEC;
  • ATOM;
  • USDC;
  • USD0;
  • XAUt;
  • BNB;
  • AVAX;
  • TRX;
  • ALGO;
  • TIA.

The estimate can still be adjusted as transaction classification and on-chain tracing continue.

The current attack explanation is more specific

Bitget now says the attacker may have exploited a vulnerability in a:

third-party security product

to potentially obtain high-level internal credentials.

The attacker then appears to have:

  • impersonated authorized activity;
  • sent fraudulent withdrawal commands to the wallet system;
  • bypassed existing risk controls;
  • triggered abnormal transfers from hot/warm wallet infrastructure.
  • This is more specific than the earlier description of a generic “wallet backend” compromise.

    Private keys remain ruled out

    Bitget says its investigation has ruled out:

    • private-key compromise;
    • cold-wallet compromise.

    That means the current evidence points to an access/control-plane failure around credentials and transaction authorization rather than theft of the cryptographic signing secrets themselves.

    Why third-party security products matter

    Exchanges increasingly depend on third-party infrastructure for:

    • security monitoring;
    • access management;
    • endpoint control;
    • credential brokering;
    • policy enforcement;
    • wallet-risk systems.

    A vulnerability in a trusted security product can create an unusually privileged attack path because it may be deployed precisely where the exchange assumes stronger trust.

    The incident therefore adds a supply-chain dimension to the earlier “transaction context” lesson.

    Bitgets remediation

    Bitget says it has:

    • isolated affected systems and servers;
    • remediated the underlying vulnerability;
    • revoked and reissued internal login credentials;
    • restructured access to highly sensitive systems;
    • added multiple approvals for critical operations;
    • disabled affected third-party functionality pending fixes;
    • strengthened withdrawal verification;
    • strengthened abnormal-activity monitoring;
    • engaged Mandiant and SlowMist;
    • notified law enforcement and financial-intelligence units.

    No further unauthorized transfers have been identified after containment, according to the exchange.

    User balances and Protection Fund

    Bitget says user account balances were not affected and the withdrawal pause was a security-validation measure rather than an asset-availability issue.

    It says the Protection Fund covers the platform-wide financial impact.

    The operational evidence is improving because customers can now withdraw BTC, but the independent financial picture remains incomplete until:

    • all withdrawals reopen;
    • final recovery is known;
    • updated reserve verification is published;
    • any Protection Fund use is disclosed.

    BTC withdrawal restoration is more meaningful than a timetable

    A scheduled date is a promise.

    A live withdrawal route is a verifiable operational state.

    BTC restoration therefore reduces one major risk: the exchange has demonstrated that at least part of its rebuilt withdrawal infrastructure is functioning after the breach.

    WikiBit nevertheless keeps the overall incident at Critical because the restoration remains partial.

    ETH is the next test

    ETH withdrawals are scheduled for September 29 at 08:00 UTC across:

    • Ethereum;
    • BSC;
    • Arbitrum;
    • Base;
    • Optimism.

    Multi-network ETH restoration is more complex than a single-network BTC route because Bitget must validate multiple chain integrations and wallet paths.

    Any delay, partial network reopening or renewed pause would be material.

    Stolen-fund recovery remains separate

    Bitgets internal recovery does not mean the stolen assets have stopped moving.

    The exchanges own incident page says:

    • fund tracing continues;
    • recovery efforts continue;
    • a bounty program is active;
    • frozen, recovered and outstanding figures should be reported only when verified.

    Bitgets bounty offers 5% for eligible voluntary actions that directly result in affected funds being frozen or recovered, subject to program terms.

    Attacker attribution

    Bitget previously said it suspected a state-backed actor and publicly discussed North Korea as a leading hypothesis.

    The updated official incident page does not treat final attacker identity as confirmed.

    WikiBit therefore maintains:

    • DPRK attribution: Developing;
    • official final attribution: not established.

    Bitget Wallet boundary

    Bitget says its non-custodial Bitget Wallet was not affected.

    It operates separately from the centralized-exchange wallet infrastructure involved in the incident.

    Evidence Status

    Confirmed / Official Bitget

    • Incident Sep. 24 at ~18:31 UTC.
    • Current affected estimate ~ $388M.
    • 12 hot/warm wallet addresses involved.
    • 11 blockchains involved.
    • Third-party security-product vulnerability is the leading attack path.
    • Private-key compromise ruled out.
    • Cold wallets unaffected.
    • Vulnerability remediated.
    • No further unauthorized transfers after containment.
    • BTC withdrawals reopened Sep. 28 08:00 UTC on Bitcoin and BSC.
    • ETH scheduled Sep. 29 08:00 UTC.
    • User balances unaffected.
    • Protection Fund covers the financial impact.

    Developing

    • Full independent forensic report.
    • Exact third-party product and initial exploit.
    • ETH/USDT/full-platform restoration.
    • Final frozen/recovered amount.
    • Final economic loss.
    • Final attacker attribution.

    Risk Assessment

    Critical, but materially improving.

    Bitget has moved from a total withdrawal freeze to verified partial withdrawal functionality. The incident remains Critical until the withdrawal stack is broadly restored and the forensic/recovery accounting is complete.

    What to Watch Next

    ETH withdrawals at Sep. 29 08:00 UTC, USDT Sep. 30, full platform restoration Oct. 2, updated reserves, Mandiant/SlowMist findings, Protection Fund accounting and stolen-fund recovery.

    FAQ

    Are Bitget BTC withdrawals open?

    Yes. Bitget says BTC withdrawals on Bitcoin and BSC reopened at 08:00 UTC on September 28.

    When is ETH scheduled to reopen?

    September 29 at 08:00 UTC across Ethereum, BSC, Arbitrum, Base and Optimism.

    How much was affected?

    Bitgets latest official estimate is approximately $388 million.

    Were private keys stolen?

    Bitget says private-key compromise has been ruled out.

    What caused the breach?

    The leading official explanation is exploitation of a vulnerability in a third-party security product that allowed high-level internal credentials to be abused for fraudulent withdrawal commands.

    Is the investigation finished?

    No. Independent forensics, asset tracing and recovery remain ongoing.

Descargo de responsabilidad

Las opiniones de este artículo solo representan las opiniones personales del autor y no constituyen un consejo de inversión para esta plataforma. Esta plataforma no garantiza la precisión, integridad y actualidad de la información del artículo, ni es responsable de ninguna pérdida causada por el uso o la confianza en la información del artículo.
El anterior

Top 3 altcoins a observar: 1ra semana de octubre de 2026

El siguiente

¿Por qué Quant (QNT) sube 322%? JPMorgan, Citi y Barclays tienen la respuesta