Bitget has started restoring withdrawals after the September 24 security incident that resulted in approximately $388 million in unauthorized transfers. BTC withdrawals reopened on September
Bitget has started restoring withdrawals after the September 24 security incident that resulted in approximately $388 million in unauthorized transfers. BTC withdrawals reopened on September 28 across the Bitcoin and BSC networks, while the exchange continues a phased restoration of other assets. Bitget says user account balances were not affected and no additional unauthorized transfers have been identified since the incident was contained.
In brief
- Bitget has resumed BTC withdrawals following the September 24 attack.
- Around $388 million in assets were transferred during the incident.
- ETH, USDT and other withdrawal services are being restored in stages through October 2.
Bitget reopens withdrawals after the $388 million incident
BTC withdrawals reopened at 08:00 UTC on September 28. The move comes four days after the attack that temporarily forced Bitget to suspend withdrawals while its security teams reviewed the exchange’s infrastructure.
The latest figure attached to the incident stands at approximately $388 million. Bitget had initially reported a lower estimate before additional transactions on other networks were included in the reconciliation.
The higher figure does not represent a second attack. According to Bitget, it reflects a more complete classification of transactions linked to the September 24 incident.
The first stage of the reopening covered BTC withdrawals through Bitcoin and BSC. By 09:00 UTC on September 28, Bitget said it had already processed 9,585 BTC withdrawal requests representing around 4,098 BTC.
Ethereum withdrawals were scheduled for September 29 across Ethereum, BSC, Arbitrum, Base and Optimism. USDT follows on September 30 across Ethereum, BSC, Solana and Tron. Other supported tokens, fiat withdrawals and P2P services are scheduled for October 2. Trading and deposits remained available during the withdrawal suspension.
Your 1st cryptos with BitgetThis link uses an affiliate program.
A third-party security flaw opened the attack path
Bitget says its investigation traced the breach to a vulnerability in a third-party security product. The attacker allegedly used the flaw to obtain high-level internal credentials. Those credentials were then used to generate fraudulent withdrawal commands that reached Bitget’s wallet system and bypassed existing risk controls.
Private keys were not compromised, according to the exchange. Cold wallets were also unaffected.
That distinction matters for an exchange handling billions of dollars in customer assets. The incident appears to have affected part of Bitget’s hot and warm wallet infrastructure rather than the cold-storage layer where a larger share of assets is held.
Mandiant and SlowMist are supporting the forensic investigation. Bitget is also working with law enforcement agencies, exchanges, blockchain projects and onchain security specialists to trace the transferred funds. Some assets have already been frozen through cooperation with industry participants.
Security was already a major part of Bitget’s public strategy before the attack. The exchange operates a dedicated Protection Fund currently valued at more than $464 million. Earlier this year, Cointribune followed the evolution of that fund as its Bitcoin holdings increased in value.
Bitget also publishes monthly Proof of Reserves reports covering assets held against customer balances. The September breach now puts those security mechanisms under a very different kind of test.
Bitget tightens controls as the investigation continues
The vulnerability used in the attack has been remediated, according to Bitget. The exchange is also reviewing third-party security products, internal access permissions, withdrawal verification procedures and systems designed to detect abnormal activity.
An official security report is expected to provide further details once the forensic findings have been verified.
For Bitget, the work does not end with reopening withdrawals. The attack was the first incident of this nature to breach the exchange’s infrastructure in eight years of operation.
The company had already expanded its anti-fraud efforts this year, including an Anti-Scam Month campaign focused on phishing, malicious access and emerging crypto threats.
Bitget has also launched two temporary initiatives following the incident. The Bitget Alliance Program runs from September 28 to October 30 for eligible users, while Project Stand Together provides temporary fee benefits and additional protection for eligible PRO clients and market makers.
For now, the restoration schedule remains the most immediate test. BTC withdrawals are back. ETH, USDT and the rest of the platform are following in stages. The forensic investigation and efforts to recover the roughly $388 million transferred during the attack are still ongoing.