Bitget Resumes Some Withdrawals After a Reported $388 Million Hack. What Is Confirmed?
Bitget, a Seychelles-based crypto exchange, says attackers took about $387.5 million from its hot and warm wallets in an incident that began on Sept. 24, 202...
Bitget, a Seychelles-based crypto exchange, says attackers took about $387.5 million from its hot and warm wallets in an incident that began on Sept. 24, 2026. The exchange paused withdrawals the next day and has been reopening them in stages. Customers want to know two things: which withdrawals work now, and how far Bitget's assurances can be checked. This article separates what Bitget has published from what outside sources have established.
What Bitget says happened
According to Bitget's security incident page, it detected unauthorized transfers from certain hot and warm wallets at 18:31 UTC on Sept. 24. Hot wallets are connected to the internet so an exchange can process withdrawals quickly. Warm wallets sit between hot storage and offline cold storage.
Bitget says the attacker exploited a vulnerability in a third-party security product, stole internal network credentials and forged withdrawal commands to get around its risk controls. It says private keys were not compromised, cold wallets were unaffected, and trading and deposits stayed online. The affected assets include XRP, ETH, USDT, ZEC, USDC, BNB, AVAX and TRX, across Ethereum and compatible networks, the XRP Ledger, Zcash and TRON.
These are company statements. Reuters reported the withdrawal pause on Sept. 25 and quoted Bitget's CEO saying the pause was not caused by a shortfall in funds.
Why the loss figure changed from $351.6 million to $387.5 million
Bitget first estimated the loss at about $351.6 million. In a Sept. 25 update, it raised the figure to about $387.5 million. The exchange says the change reflects a more complete accounting that added Zcash and TRON assets missing from the first estimate, and that it does not reflect further unauthorized transfers. It also says the figure may change as more transactions are classified, so treat $387.5 million as a working estimate.
Which withdrawals have resumed
Bitget's withdrawal plan sets this schedule, in UTC:
- Bitcoin on the Bitcoin network: Sept. 28 at 8:00. BleepingComputer reported that these restarted.
- ETH on Ethereum, BSC, Arbitrum, Base and Optimism: Sept. 29 at 8:00.
- USDT on Ethereum, BSC, Solana and Tron: Sept. 30 at 8:00.
- All other coins, plus fiat and peer-to-peer (P2P) withdrawals: Oct. 2 at 8:00.
USDT is where the sources differ. The incident page, last updated at 00:00 UTC on Sept. 30, still listed USDT as pending. That is earlier than the 8:00 UTC reopening time. At 09:39 UTC on Sept. 30, Bitget's CEO wrote on X that withdrawals for BTC, ETH and USDT had resumed and that everything else would open Friday. A follow-up post said P2P withdrawals would start Friday at 8:00 UTC with the rest.
The reviewed materials did not include a dated support notice confirming the USDT restart. Check the withdrawal page in your own account for the current status of each coin and network.
What the protection fund does and does not establish
Bitget says its Protection Fund covers the financial impact of the incident and that the cost will not be passed on to user balances. It also says user balances are accurate and unaffected. These are assurances from the company. The reviewed materials did not include an independent verification of the fund or of the coverage.
Bitget's own pages give different fund figures. The incident page lists 5,500 BTC, valued at more than $464 million. The Protection Fund page showed about $309 million, or 3,705 BTC, when we checked. The CEO's post says the fund is back above $300 million. Bitget has not explained the difference in the materials reviewed, so the size of the fund is an open question. The fund page also says Bitget reserves the right to assess each claim.
Bitget also cites a 127% overall reserve ratio on the incident page and a 131% figure from its Sept. 28 proof-of-reserves update. Proof of reserves is a snapshot of assets against customer balances at one moment. It is not a full audit and does not show an exchange's liabilities or controls. Our explainer on proof of reserves covers what these snapshots can and cannot show.
What the Mandiant report says so far
Bitget engaged the security firm Mandiant and published a Sept. 28 status update. The preliminary findings say an attacker gained privileged access to two third-party security appliances on Sept. 24, installed a web shell, then moved to the production wallet job server and deployed malicious packages. Mandiant says the investigation is ongoing. It says Bitget has not seen evidence that private keys were compromised.
The report was commissioned and published by Bitget, so it is not fully independent. The exchange's Sept. 30 notice says the Mandiant and SlowMist reports broadly align with its own account of the attack path.
The update also says the malicious transfers ran alongside normal Ethereum wallet operations until about 21:23 UTC on Sept. 24, almost three hours after detection. BleepingComputer reported that Bitget's CEO earlier blamed North Korean hackers. The Mandiant excerpt names no actor, and this article does not treat attribution as established.
Stolen funds: what the Zcash movement shows
CoinDesk reported on Sept. 30 that, based on its review of transaction records, about 2,746 ZEC, worth around $3.9 million, entered Zcash's shielded pool in three transfers that morning. Shielded transfers hide the sender, recipient and amount. Investigators can still see the amounts going in and out and the timing.
That movement is a data point about where some funds went. It does not show that the funds were cashed out or cannot be recovered. Bitget says some assets were frozen but has not given amounts. It has also offered a bounty of 5% of frozen or recovered funds.
What remains unverified
- The final loss figure, since Bitget says its estimate may change.
- The size of the Protection Fund, given the different figures on Bitget's own pages.
- Whether USDT withdrawals are open on every listed network, pending a dated notice.
- How much has been frozen or recovered.
- Who carried out the attack.
- The findings of the full Mandiant investigation, which is still in progress.
A caution about scams
Bitget warns that it will never ask users to transfer funds or share seed phrases to recover funds or resume withdrawals. Incidents like this draw impersonators, so treat any message that says otherwise as a scam. Whether to keep funds on an exchange is a personal decision that depends on your own circumstances.
Disclosure: This article relies on Bitget's published incident notices, its Mandiant status update and its CEO's posts, plus Reuters, BleepingComputer and CoinDesk. Claims about the cause, the fund and the withdrawal timing are attributed to Bitget, and no independent audit of its figures was found. This article is not financial, legal, or investment advice. AI-assisted research and writing. Cited sources, not AI alone, support the claims.


