Bitget Restarts Withdrawals After $388M Exploit

Bitget has started restoring cryptocurrency withdrawals after an exploit resulted in roughly $388 million in unauthorized transfers from the exchange on Sept. 24.
The exchange began the recovery process on Monday by reopening Bitcoin withdrawals through the Bitcoin network at 8 a.m. UTC. Bitget said withdrawals will return in stages as each blockchain completes additional security checks.
Ethereum withdrawals across Ethereum, BNB Smart Chain, Arbitrum, Base, and Optimism are scheduled to resume on Sept. 29 at 8 a.m. UTC. USDT withdrawals on Ethereum, BNB Smart Chain, Solana, and Tron are expected to follow on Sept. 30 at the same time.
The exchange plans to restore withdrawals for other assets, along with fiat withdrawals and peer-to-peer transactions, on Oct. 2.
The incident occurred at around 6:31 p.m. UTC on Sept. 24, when unauthorized transfers were detected across several networks involving Bitget's hot and warm wallet infrastructure. According to the exchange, the attacker exploited a weakness in a third-party security product to obtain high-level internal credentials.
Those credentials were then allegedly used to issue fraudulent withdrawal commands to Bitget's wallet system. The exchange said the transactions bypassed existing risk controls and resulted in abnormal transfers.
Assets reportedly moved during the attack included ETH, USDT, USDC, AVAX, and BNB. Bitget said its private keys were not compromised and that user balances and funds held in cold wallets remained unaffected.
The exchange has since patched the vulnerability and said the incident has been contained, with no additional unauthorized transfers detected. Bitget is also reviewing its procedures for evaluating and deploying third-party security tools.
Mandiant and SlowMist are assisting with the investigation as the exchange works to determine how the attack was carried out and track the stolen funds.
Bitget confirmed that approximately $388 million in assets were lost, making the incident one of the largest crypto exchange-related thefts reported this year. The exchange said the losses will be fully covered through its User Protection Fund, which holds 5,500 BTC.
Bitget has also introduced a recovery bounty for stolen funds. Parties that directly help freeze or recover assets can receive 5% of the value successfully recovered.
The exchange has not publicly confirmed the identity of the attackers. Bitget described the group as sophisticated and capable of concealing stolen funds, while previously saying it suspected a North Korean connection. The investigation remains ongoing.
