Bitget’s withdrawal resumption begins with Bitcoin after $387M breach

15 hours ago 30
Bitget withdrawal resumption

Bitget has mapped out a step-by-step return of withdrawal services after a security incident forced the exchange to freeze the function on September 24, with the first phase of the Bitget withdrawal resumption set to begin at 08:00 UTC on September 28. The staggered rollout, which stretches through October 2, comes as the exchange works alongside outside cybersecurity firms to confirm its systems are safe and as investigators continue to trace hundreds of millions of dollars in unauthorized transfers.

Key takeaways

  • Bitcoin withdrawals resume first, at 08:00 UTC on September 28, with Ether, USDT and other services following in stages through October 2.
  • Bitget’s technical team says it has fixed the vulnerabilities behind the breach and is running extra checks with help from Mandiant and SlowMist.
  • The estimated value of unauthorized transfers grew from roughly $351.6 million to about $387.5 million once Zcash and TRON assets were included.
  • Bitget says its protection fund holds more than $464 million and that customer account balances were never altered.
  • CEO Gracy Chen has floated a possible North Korean link based on IP and VPN similarities, though no government has publicly attributed the attack.

Bitget maps out a four-stage return of withdrawals

The Bitget withdrawal resumption follows a fixed timetable rather than a single reopening, giving the exchange room to verify each network before customers can move funds again. Bitcoin withdrawals go first, restarting at 08:00 UTC on September 28 on the Bitcoin network itself.

Bitcoin withdrawals restart first

According to Bitget’s update, BTC withdrawals are due to resume at 08:00 UTC on September 28, making it the opening move in the exchange’s staged recovery plan.

Ether and USDT follow over the next two days

ETH withdrawals are scheduled for the same hour on September 29, covering the Ethereum, BNB Smart Chain, Arbitrum, Base, and Optimism networks. USDT withdrawals come a day later, at 08:00 UTC on September 30, across Ethereum, BNB Smart Chain, Solana, and Tron.

Fiat and remaining tokens close out the schedule

The final stage covers withdrawals of other tokens, fiat currency services, and peer-to-peer transactions, all set for 08:00 UTC on October 2. Bitget has told users to check its official channels for confirmation before assuming a given service is live, and stressed that no action is required from customers ahead of each reopening.

What triggered the pause, and how Bitget is fixing it

Bitget detected unauthorized transfers from some of its wallets on September 24 and suspended withdrawals immediately while it investigated. The exchange says its technical team has since identified and fixed the vulnerabilities tied to the incident, and it is now running further security checks before letting each withdrawal channel come back online.

Two outside firms are involved in that process: Mandiant, the cybersecurity company owned by Google, and SlowMist. Both are helping investigate how the attack happened. Bitget’s earlier account pointed to a possible breach of a backend wallet service, though the exchange had not pinned down a final entry point at that stage. Importantly, Bitget said its cold wallets remained secure and that early investigation turned up no evidence of a leaked private key.

Trading and deposits kept running throughout the suspension. Bitget describes the withdrawal freeze as a temporary security measure rather than a sign that customer funds were touched, and it said account balances did not change during the pause. That distinction matters: the exchange is drawing a line between customer-facing balances, which it says stayed intact, and the separate unauthorized transfers pulled from its own wallet infrastructure.

Losses climb as tracing work continues

The financial picture tied to this incident has shifted since Bitget’s first disclosure. The exchange initially estimated that about $351.6 million in assets were affected by the unauthorized transfers. A later account, cited by Outlook Money on September 26, put the value moved to attacker-controlled addresses at approximately $387.5 million, a figure that grew once Zcash and TRON assets were factored in — holdings absent from the first estimate.

Bitget has said tracing work is ongoing, meaning the total could still move as investigators classify additional transactions. This kind of upward revision is not unusual in the early days after a large-scale exchange breach, since forensic teams often need time to map every wallet and chain involved before settling on a final number.

To cover the financial hit, Bitget is pointing to its protection fund, which it says held more than $464 million during the withdrawal pause. The exchange has framed this fund as its mechanism for absorbing the loss without affecting customer balances. That statement describes Bitget’s plan for handling the incident financially — it does not change the fact that unauthorized transfers from its own wallets did occur.

North Korea questions and a stolen-USDC paper trail

Beyond the mechanics of the breach, two threads have drawn added scrutiny. Bitget CEO Gracy Chen raised the possibility of a North Korean connection during an earlier public discussion, pointing to similarities involving IP addresses and VPN services. She stopped short of confirming who was responsible, and no government agency has issued a public attribution tied to this attack.

Separately, security researcher Taylor Monahan tracked movements of stolen USDC she linked to the attacker, including transfers and conversions into ETH while withdrawals were still suspended. Her findings raised a pointed question: could Circle, the U.S.-based issuer of USDC, freeze those tokens? Circle has said it freezes tokens when legally compelled to do so, but the public record here does not establish whether Circle received or acted on any legal order tied to these specific addresses.

That question carries extra weight because of a separate, unrelated U.S. federal lawsuit filed after the Drift Protocol exploit, in which a claimant alleged Circle failed to stop stolen USDC from moving through its cross-chain transfer system. That allegation is part of a different legal case and is not a court finding against Circle, nor does it resolve how Circle handled the Bitget-linked funds.

Why this matters for the wider market: incidents like this test how quickly stablecoin issuers can act once tokens tied to an exploit start moving, and they put a spotlight on how exchanges communicate losses versus customer-facing risk. For Bitget users, the immediate marker to watch remains the Bitcoin withdrawal window opening at 08:00 UTC on September 28, with the exchange promising confirmation through its official notices as each stage of the security checks wraps up.

FAQ

When will Bitget resume Bitcoin withdrawals after the security incident?

Bitcoin withdrawals are scheduled to resume at 08:00 UTC on September 28.

What is the estimated value of cryptocurrency stolen in the Bitget breach?

Unauthorized transfers were initially estimated at about $351.6 million and later updated to approximately $387.5 million.

How is Bitget addressing the security vulnerabilities that led to the breach?

Bitget’s technical team has fixed the vulnerabilities and is conducting further security checks with the assistance of cybersecurity firms Mandiant and SlowMist.

Are customer assets safe despite the breach?

Bitget stated that customer account balances have not changed and that the exchange’s protection fund, holding more than $464 million, will cover the financial impact.

Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

Read Entire Article