# What happened Bitget, a Seychelles-based crypto exchange, halted withdrawals after a Sept. 24 incident that moved roughly $388 million in crypto to attacker-controlled addresses. The exchange began reopening withdrawals in phases. Within the first hour of restarted withdrawals, customers processed 9,585 orders totaling 4,098 bitcoins, Bitget CEO Gracy Chen said.
# How the attack worked, according to Bitget Bitget reported that attackers obtained internal credentials by exploiting vulnerabilities in third-party products. Attackers used those credentials to submit fraudulent withdrawal commands that bypassed Bitget's risk controls. Bitget says cold storage funds were not touched.
# Immediate effects after the restart Withdrawals surged in the first hour after services reopened, then "stabilized a lot," Chen told Bloomberg Television. The exchange also said the incident is contained and that no further unauthorized transfers are possible.
# Financial position and protection fund Before the hack, Bitget's protection fund stood at $464 million. After covering shortfalls following the incident, Bloomberg reported the fund had fallen below $200 million. Bitget said it was using its own money to top the protection fund back up.
# Attribution and context Bitget said the attack pattern is highly consistent with known North Korean hacker groups. North Korea-linked attackers have repeatedly targeted exchanges and are known for multi-chain, sophisticated operations. Bitget is the sixth-largest exchange by trading volume, with most customers based in Asia.
# What the company has said and next steps Bitget reported it identified and remediated the underlying vulnerability and structured a phased withdrawal restart, beginning with Bitcoin. The exchange described this as its first security incident of this nature in eight years and stated the incident remains contained.
# Why this matters to users and markets Large, concentrated withdrawals can move markets and create liquidity pressure. The rapid pace of withdrawals in the first hour suggests many customers moved assets off exchange custody quickly once withdrawals were available. The reduction in the protection fund could affect the exchange's ability to cover customer losses if further issues arise.
# Concrete facts to remember
- Total moved to attacker addresses: about $388 million (company estimate).
- Withdrawals processed in first hour after restart: 9,585 orders for 4,098 BTC.
- Attribution: Bitget says pattern is consistent with North Korean hacker organizations.
# Short-term signals to watch
- Whether remaining phased withdrawals proceed without incident.
- Any forensic updates showing where stolen funds move on-chain.
- Replenishment level and transparency of Bitget's protection fund.
- Regulatory and customer responses in Asia, where most users are based.
# Bottom line Bitget resumed withdrawals after a major security incident that shifted hundreds of millions of dollars. A large proportion of customer withdrawals happened immediately when access returned. The exchange says it contained the incident, fixed the vulnerability, and used internal funds to shore up its protection fund.