NEWS

Bitget Resumes Bitcoin Withdrawals After $387.5 Million North Korea-Linked Heist

Bitget restored BTC withdrawals Sep 28 in a phased restart after its $387.5M breach, with ETH, USDT, and fiat/P2P to follow through Oct. 2.

Dylan H.

News Desk

September 28, 2026
6 min read
Bitget Resumes Bitcoin Withdrawals After $387.5 Million North Korea-Linked Heist

Bitget Restarts Withdrawals, Bitcoin First

Four days after suspected North Korean hackers drained roughly $387.5 million from its hot and warm wallets, cryptocurrency exchange Bitget has begun restoring customer withdrawals — starting with Bitcoin. CosmicBytez Labs has covered the breach itself in detail (Sep 25, Sep 26, Sep 27); this update covers what actually resumed, the security work Bitget says it did first, and what it means for users still waiting on other assets.


Restart at a Glance

AttributeDetail
Withdrawals suspendedSeptember 24, 2026, immediately after the breach was detected
First asset restoredBitcoin (BTC) — September 28, 2026, 08:00 UTC, across both native BTC and BNB Smart Chain networks
Still paused at restartETH and other EVM-chain tokens, USDT, remaining tokens, fiat services, P2P trading
Root cause (refined)A vulnerability in a third-party security product used by Bitget was exploited to obtain high-level internal credentials, which were then used to issue fraudulent withdrawal commands that bypassed risk controls
Remediation before restartVulnerability patched; Bitget says it completed "additional security work across its withdrawal infrastructure"
Bitget's assuranceNo further unauthorized transfers have occurred since containment; user account balances were unaffected throughout
User Protection Fund$464 million+ (5,500 BTC) — Bitget says it fully covers the loss
Trading/depositsContinued operating normally during the withdrawal freeze

A Phased Reopening, Not a Full Restart

Bitget did not flip withdrawals back on all at once. Instead, it published a staged schedule that brings assets back online in order of exposure and liquidity:

  • September 28, 08:00 UTC — Bitcoin (native BTC network and BNB Smart Chain)
  • September 29, 08:00 UTC — Ether across Ethereum, BNB Smart Chain, Arbitrum, Base, and Optimism
  • September 30, 08:00 UTC — USDT across Ethereum, BNB Smart Chain, Solana, and Tron
  • October 2, 08:00 UTC — remaining tokens, plus fiat services and peer-to-peer (P2P) trading

Only Bitcoin withdrawals are live as of this writing. Every other asset class — including the chains that were actually drained in the breach (Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Chain, Base, plus Zcash and Tron in the revised total) — remains paused until its scheduled date. Bitget has framed the staggered approach as a deliberate control measure to reopen the exchange without re-exposing wallets that haven't cleared additional verification.

What's New Since the Initial Disclosure

Bitget's original account, given by CEO Gracy Chen in the days after the breach, described a backend compromise: attackers spoofed the transaction data shown to Bitget's internal transfer-approval process, tricking it into authorizing transfers it should have rejected, without ever obtaining a private key. The account given alongside the withdrawal restart adds a more specific initial-access step: investigators determined the intrusion began with a vulnerability in a third-party security product Bitget relied on internally, which the attacker exploited to obtain high-level internal credentials. Those credentials were then used to issue the fraudulent withdrawal commands that bypassed risk controls — consistent with, but more precise than, the "spoofed backend" description given immediately after detection.

Bitget maintains that private keys were never exposed and that its cold wallets were untouched throughout. The company says Mandiant and SlowMist continue to assist with the investigation and on-chain tracing, and that it has published the attacker's identified wallet addresses publicly to support industry-wide freezing and recovery efforts.

Recovery Efforts Are Only Partially Working

Bitget's Recovery Bounty Program — offering 5% of any funds frozen and 5% of any funds recovered — remains open, but results so far are modest against the scale of the theft. Circle and Tether have frozen roughly $318,000 in USDC/USDT tied to a single exploiter-associated address, a small fraction of the total loss. Stolen assets have continued moving across chains since the breach, including through THORChain, and according to Cointelegraph's reporting, THORChain node operators declined a request to block the attacker's associated wallets — leaving that laundering route open. Ether and most of the other stolen assets cannot be unilaterally frozen by an issuer the way stablecoins can, so the bulk of the $387.5 million remains outside Bitget's or law enforcement's direct control for now.

What This Means for Bitget Users

  • No action is required to protect your balance. Bitget says account balances were never altered by the breach; the loss hit exchange-operated hot/warm wallets, not individual user ledgers, and the Protection Fund is intended to make any shortfall whole.
  • Only BTC withdrawals work right now. If you hold ETH, USDT, or other assets on Bitget, withdrawals are still paused and will come online on their scheduled date — attempting workarounds or third-party "unlock" services is unnecessary and risky.
  • Watch for phishing. High-profile exchange incidents reliably draw impersonation scams — fake "verify your withdrawal" links, spoofed Bitget support accounts, and fraudulent "recovery agent" offers. Use only Bitget's official app/site and announced channels for withdrawal status.
  • Track the schedule directly from Bitget, not secondhand reports, since exact restart times for ETH, USDT, and fiat/P2P could shift if further verification issues surface.

Key Takeaways

  1. Only Bitcoin withdrawals have resumed so far (September 28), as the first step of a four-stage restart running through October 2.
  2. The root-cause narrative was refined, not reversed: a third-party security product vulnerability gave attackers the internal credentials used to spoof approval and issue fraudulent transfers — private keys and cold wallets were never touched.
  3. The $464 million+ User Protection Fund is Bitget's stated mechanism for covering the full loss to users, separate from any on-chain recovery.
  4. Recovery has netted only ~$318,000 frozen so far, and THORChain node operators have declined to block attacker-linked wallets, leaving most of the $387.5 million still in motion.
  5. Users should expect a staged return of functionality, not a single reopening — and should be alert to phishing that exploits the ongoing news cycle.

Sources