Bitget Resumes BTC Withdrawals Following $388M Hack

BTC
ETH
USDT
USDC
BNB
SOL
XRP
LINK
UNI
ZEC
withdrawal suspensionhack
1 hour agoSource: crypto.news
Bitget Resumes BTC Withdrawals Following $388M Hack

Bitget has reopened Bitcoin withdrawals on the Bitcoin network after a hack moved approximately USD 387.5 million to attacker-controlled addresses and forced the exchange to suspend withdrawals on September 24.

Summary

  • Bitcoin withdrawals resumed at 08:00 UTC September 28, four days after Bitget suspended customer withdrawals.
  • Bitget says attackers exploited a third-party security product to obtain credentials and forge withdrawal commands.
  • Bitget has confirmed approximately USD 387.5 million moved to attacker-controlled addresses during the September breach.
  • Ether withdrawals are scheduled for September 29, followed by USDT withdrawals on September 30 worldwide.
  • Mandiant and SlowMist are assisting the investigation while Bitget continues tracing and recovering stolen assets.

Bitget said BTC withdrawals became available at 08:00 UTC on September 28 as scheduled, beginning a phased restoration of services after security checks across its withdrawal infrastructure. The exchange said the vulnerability tied to the incident has been remediated and no further unauthorized transfers have been identified following containment.

User account balances remain unaffected, according to the company. Deposits and trading continued while withdrawals were suspended, and Bitget says its User Protection Fund will cover the financial loss from the attack.

Bitget hack investigation identifies third-party security flaw

The September 24 Bitget hack began at approximately 18:31 UTC, when unauthorized transfers were detected from portions of the exchange’s hot and warm wallet infrastructure. Bitget initially estimated that roughly USD 351.6 million had been affected before later tracing raised the amount sent to attacker-controlled addresses to approximately USD 387.5 million.

During a September 28 livestream, CEO Gracy Chen said the attacker exploited a vulnerability in a third-party security product and obtained high-level internal network credentials. According to the company’s account, those credentials were then used to create fraudulent withdrawal instructions that bypassed existing risk controls.

“The attacker then used these credentials to send fraudulent withdrawal commands to the wallet system,” Bitget said in its account of the breach.

The company says no private keys were leaked and its cold wallets were not affected. Bitget’s published incident timeline describes an attacker compromising backend wallet infrastructure and feeding false transaction information into its authorization process.

Mandiant and blockchain security company SlowMist continue to assist the investigation. Bitget said its own teams have identified the attack path, patched the underlying vulnerability and carried out extra validation before allowing affected withdrawal services to return.

BTC withdrawals reopen before ETH and USDT

Bitcoin is the first asset covered by Bitget’s withdrawal restart. The exchange opened BTC withdrawals on the Bitcoin network at 08:00 UTC on September 28, four days after the suspension began.

Ether is next in the timetable. ETH withdrawals are scheduled to reopen at 08:00 UTC on September 29 across Ethereum, BNB Smart Chain, Arbitrum, Base and Optimism. USDT withdrawals are scheduled for September 30 at 08:00 UTC across Ethereum, BNB Smart Chain, Solana and Tron.

Other token withdrawals, fiat withdrawal services and peer-to-peer transactions are scheduled to return at 08:00 UTC on October 2. Bitget has said each part of the rollout remains subject to security checks for the relevant asset and network.

The BTC reopening follows the timetable announced two days earlier. As crypto.news previously reported, Bitget had set September 28 as the first withdrawal-restoration date while Mandiant and SlowMist reviewed the incident and the exchange checked its infrastructure.

Bitget’s initial security notice said the User Protection Fund held more than USD 464 million when withdrawals were halted. The company says the fund will absorb losses from the breach, although the later USD 387.5 million theft figure was published after that original fund valuation.

Stolen Bitget funds remain under investigation

Recovery efforts have continued while withdrawal services return. Bitget launched a bounty program covering parties whose work directly results in stolen assets being frozen or recovered. The program offers separate 5% rewards tied to qualifying freezes and successful recoveries.

Circle and Tether had frozen approximately 99,990 USDC and 218,023 USDT linked to the attack by September 26, according to information reported by crypto.news. Bitget has published attacker addresses and opened a tracing portal as investigators follow transactions across several chains.

Some stolen assets have continued moving between networks. In related coverage, crypto.news reported that funds linked to the breach were routed through THORChain, prompting a dispute after Bitget requested action against addresses associated with the attacker. THORChain said its protocol does not provide a mechanism for selectively blocking individual addresses.

Blockchain compliance firm AMLBot later traced roughly four BTC connected to the stolen funds into a Wasabi CoinJoin transaction. The firm said the funds moved from TRON through USDT0 and Ethereum before being converted through THORChain into Bitcoin.

AMLBot estimated on September 25 that approximately USD 343 million it associated with the breach remained dormant across 13 attacker wallets. The firm identified eight Ethereum wallets holding approximately 68,300 ETH, four XRP addresses containing around 83 million XRP and another wallet holding close to 18,900 ZEC.