Bitget reopens withdrawals after major security breach drains roughly $388 million

Photo: Pixabay / Pexels

Bitget reopens withdrawals after major security breach drains roughly $388 million

The exchange says its protection fund will cover all user losses, but nearly half a billion dollars in customer funds have already walked out the door.

Bitget, one of the world’s largest centralized crypto exchanges, has begun letting users pull their money out again after a security breach on September 24 siphoned off approximately $388 million from its operational wallets. The exchange’s tracked reserves have dropped to around $5.7 billion, and roughly $463 million in customer outflows piled up within the first 24 hours of withdrawal resumption alone.

What happened and how withdrawals are returning

The attack exploited a zero-day vulnerability in a third-party security application. Attackers were able to spoof transactions by obtaining internal credentials, though Bitget says private keys and cold wallets were never compromised.

Bitget suspended withdrawals immediately after detecting the breach while keeping trading and deposits operational. The resumption has been phased rather than all-at-once: Bitcoin withdrawals came back online on September 28, Ethereum on September 29, and USDT on September 30. Other assets and peer-to-peer transactions are targeted for October 2.

Advertisement

The exchange processed over 4,098 BTC in withdrawals shortly after the Bitcoin window reopened. Prior to the hack, Bitget’s total balance sat above $6.7 billion, meaning the breach itself represented roughly 5-6% of total reserves.

The protection fund and the North Korea question

CEO Gracy Chen moved quickly to reassure users that account balances would remain whole. The exchange is absorbing the loss through its User Protection Fund, which was valued at over $464 million before the incident. That fund was specifically designed for scenarios like this, and its pre-breach size was just large enough to cover the $388 million theft with some cushion remaining.

On the investigation side, Bitget has brought in cybersecurity heavyweights including Mandiant and SlowMist to trace the stolen funds and identify the attackers. Initial assessments suggest potential involvement from North Korean-linked hacking groups, which would place this breach squarely in the pattern of state-sponsored crypto theft that has defined exchange security nightmares for the past several years.

The real damage: trust

Customer outflows of approximately $463 million in just 24 hours tell a story that no CEO statement can fully counteract. The total balance decline of about $600 million since the day before withdrawal resumption, combining the theft itself with voluntary outflows, underscores the dual hit.

The phased withdrawal approach is a pragmatic choice. Reopening everything at once could have triggered a bank-run dynamic, while a controlled rollout gives the exchange time to manage liquidity and demonstrate operational stability.

What this means for centralized exchanges

The zero-day vector, originating in a third-party application rather than Bitget’s own infrastructure, raises particular questions about supply-chain security standards that most regulatory frameworks haven’t yet addressed.

For Bitget specifically, if the exchange can fully restore withdrawals on schedule by October 2, demonstrate that the protection fund has made every user whole, and provide credible forensic findings from its investigation partners, it has a reasonable path to recovery. The $5.7 billion in remaining reserves is still a substantial war chest. But the $463 million that left in 24 hours represents users who voted with their wallets.

Disclosure: This article was edited by John Chen. For more information on how we create and review content, see our Editorial Policy.
Bitget reopens withdrawals after major security breach drains roughly $388 million
Bitget reopens withdrawals after major security breach drains roughly $388 million

The exchange says its protection fund will cover all user losses, but nearly half a billion dollars in customer funds have already walked out the door.

Share

Add us on Google

Photo: Pixabay / Pexels

Bitget, one of the world’s largest centralized crypto exchanges, has begun letting users pull their money out again after a security breach on September 24 siphoned off approximately $388 million from its operational wallets. The exchange’s tracked reserves have dropped to around $5.7 billion, and roughly $463 million in customer outflows piled up within the first 24 hours of withdrawal resumption alone.

What happened and how withdrawals are returning

The attack exploited a zero-day vulnerability in a third-party security application. Attackers were able to spoof transactions by obtaining internal credentials, though Bitget says private keys and cold wallets were never compromised.

Bitget suspended withdrawals immediately after detecting the breach while keeping trading and deposits operational. The resumption has been phased rather than all-at-once: Bitcoin withdrawals came back online on September 28, Ethereum on September 29, and USDT on September 30. Other assets and peer-to-peer transactions are targeted for October 2.

Advertisement

The exchange processed over 4,098 BTC in withdrawals shortly after the Bitcoin window reopened. Prior to the hack, Bitget’s total balance sat above $6.7 billion, meaning the breach itself represented roughly 5-6% of total reserves.

The protection fund and the North Korea question

CEO Gracy Chen moved quickly to reassure users that account balances would remain whole. The exchange is absorbing the loss through its User Protection Fund, which was valued at over $464 million before the incident. That fund was specifically designed for scenarios like this, and its pre-breach size was just large enough to cover the $388 million theft with some cushion remaining.

On the investigation side, Bitget has brought in cybersecurity heavyweights including Mandiant and SlowMist to trace the stolen funds and identify the attackers. Initial assessments suggest potential involvement from North Korean-linked hacking groups, which would place this breach squarely in the pattern of state-sponsored crypto theft that has defined exchange security nightmares for the past several years.

The real damage: trust

Customer outflows of approximately $463 million in just 24 hours tell a story that no CEO statement can fully counteract. The total balance decline of about $600 million since the day before withdrawal resumption, combining the theft itself with voluntary outflows, underscores the dual hit.

The phased withdrawal approach is a pragmatic choice. Reopening everything at once could have triggered a bank-run dynamic, while a controlled rollout gives the exchange time to manage liquidity and demonstrate operational stability.

What this means for centralized exchanges

The zero-day vector, originating in a third-party application rather than Bitget’s own infrastructure, raises particular questions about supply-chain security standards that most regulatory frameworks haven’t yet addressed.

For Bitget specifically, if the exchange can fully restore withdrawals on schedule by October 2, demonstrate that the protection fund has made every user whole, and provide credible forensic findings from its investigation partners, it has a reasonable path to recovery. The $5.7 billion in remaining reserves is still a substantial war chest. But the $463 million that left in 24 hours represents users who voted with their wallets.

Disclosure: This article was edited by John Chen. For more information on how we create and review content, see our Editorial Policy.