Bitget Restarts Withdrawals in Phases After $388M Security Breach
After a September 24 exploit that moved about $388 million, Bitget says withdrawals will reopen by asset and network while independent forensics verify containment and trace funds.
After a September 24 exploit that moved about $388 million, Bitget says withdrawals will reopen by asset and network while independent forensics verify containment and trace funds.
Crypto exchange Bitget has officially initiated a phased resumption of user withdrawals following a $388 million security exploit on September 24, 2026.
These stolen credentials were used to push unauthorized, fraudulent withdrawal commands through the system, bypassing automated risk filters.
The breach represents the first major security compromise affecting Bitget's core exchange infrastructure in its eight-year operating history.
# What happened On September 24, Bitget experienced an unauthorized transfer of roughly $388 million in crypto assets. The exchange says the attacker obtained high-level internal credentials by exploiting a vulnerability in a third-party security product. Those credentials were then used to submit fraudulent withdrawal commands that bypassed automated risk filters. Bitget reports that private keys were not exposed and cold wallets remained intact.
# How withdrawals are being restored Bitget has implemented a phased reopening to control traffic and confirm system stability. The publicly stated schedule is:
# Security response and forensic work
# Financial backing and coverage for users To reassure users, Bitget disclosed its financial protections: a User Protection Fund of over $464 million and a proof-of-reserves ratio reported at 127%. The company says these measures support solvency and asset coverage while investigations continue.
# Customer support and retention measures Bitget announced several programs aimed at stabilizing liquidity and rewarding users during recovery:
# What remains unresolved Bitget's public account describes containment and remediation steps, but the forensic process is ongoing. The firm will publish a complete incident report when investigations by the retained cybersecurity teams finish. The exchange is coordinating legal and on-chain recovery efforts, and monitoring for any further unauthorized activity.
# Bottom line Bitget has resumed withdrawals in stages while external forensics verify the fix and trace funds. The exchange says core vaults and cold storage were not compromised and that financial protections are in place to cover user assets. Users should monitor official Bitget notices for precise timing and network availability as the phased schedule continues.

Bitget has set a Sep. 28 restart for Bitcoin withdrawals after a Sep. 24 security incident, with Ether, USDT, and other withdrawal services scheduled to follow through Oct. 2. Bitget said in an update that its technical team had identified…

Bitget CEO Gracy Chen has provided a detailed account of the Sept. 24 security incident, explaining how an attacker obtained internal credentials and initiated about $388 million in unauthorized transfers.

TL;DR Bitget has increased the confirmed value of assets transferred to attacker-controlled addresses from $351.6 million to about $387.5 million. The exchange says the underlying vulnerability has been identified and remediated. Withdrawals are scheduled to return in stages beginning with Bitcoin on September 28 and c

Bitget has reopened BTC withdrawals after its USD 388 million hack, with ETH, USDT and other services scheduled to return through Oct. 2.

The company also stated that Bitget Wallet, its decentralized wallet application, operates independently from the exchange infrastructure and was not impacted.
What is a business? The conventional economic answer tends to focus on firms, markets, capital and profit. I think that misses the most important part Read the full article...
Loading more related stories...
Open the app view to save this story, compare related coverage, and continue from the same source.