Bitget indicates that after the security incident on September 24th, Bitcoin withdrawals will be resumed from September 28th onwards. ETH, USDT and other withdrawal services are planned to be gradually restored by October 2nd.
- The Bitcoin withdrawal plan will reopen at 08:00 on September 28th ( UTC ).
- Withdrawals using ETH and USDT will be resumed on the designated networks within the next two days.
- According to Bitget, the relevant vulnerabilities have been fixed, and further security checks are currently underway.
- Subsequent statements regarding this incident claimed that the assets transferred to the attacker-controlled address amounted to approximately 387.5 million US dollars.
Bitget stated in an update that its technical team has identified and fixed the vulnerabilities related to this incident. The exchange mentioned that they are checking the withdrawal system before reopening withdrawals; meanwhile, Google's cybersecurity company Mandiant and blockchain security firm SlowMist are assisting in the investigation of this attack.
These dates are part of a phased restart plan. Bitget reminds users to refer to the notifications issued by the platform and its official channels to confirm whether all services have been restored. The company stated that customers do not need to take any action before the withdrawal of funds is resumed.
Bitget Withdrawal services will be restored in four phases.
According to the schedule, withdrawals of BTC on the Bitcoin network will resume at 08:00 (UTC) on September 28th. Withdrawals of ETH are scheduled to resume at the same time on September 29th, covering the Ethereum, BNB Smart Chain, Arbitrum, Base, and Optimism networks.
The withdrawal plan USDT will resume at 08:00 on September 30 ( UTC), covering Ethereum, BNB Smart Chain, Solana, and Tron networks. Bitget has scheduled the withdrawal of other tokens, fiat currency services, and peer-to-peer transactions for the last phase, which is planned to resume at 08:00 on October 2 ( UTC).
For customers holding ETH or USDT, the network list is very important: the resumption of a certain token project does not mean that withdrawals on all networks will be available simultaneously. Bitget listed 5 networks for the first phase of ETH, and USDT listed 4 networks. For the remaining tokens in the schedule, Bitget does not list the recovery status of each network individually in the arrangements shared with users.
According to the exchange, trading and deposit services continued during the withdrawal suspension period. Bitget described this suspension as a temporary security measure and stated that there were no changes to customer account balances. What they referred to as "user assets not being affected" refers to customer balances; at the same time, the exchange also reported separately that unauthorized transfers occurred within its own wallet infrastructure.
Reported losses have increased compared to the initial estimate of Bitget.
As reported by Bitget, on September 24th, they discovered unauthorized transfers from some wallets and temporarily suspended coin withdrawals during the investigation period. As crypto.news reported on Friday, the exchange initially estimated that about $351.6 million in assets were affected. Bitget stated at the time that their cold wallets were secure, and preliminary investigations did not find any evidence of private key leakage.
According to subsequent statements cited by Outlook Money on September 26, Bitget estimated the value of assets that were transferred to the attacker-controlled addresses to be approximately $387.5 million. This later disclosed figure includes assets from Zcash and TRON that were not included in the initial estimate. Bitget stated that the tracking efforts are still ongoing, so this figure may change as investigators categorize more transactions.
According to reports previously cited by crypto.news from Bitget, initial investigations pointed to the possibility of an intrusion into the backend wallet service. At that time, it was stated that the exchange had not yet identified the exact entry point for the intrusion. The latest statement from Bitget indicates that the relevant vulnerabilities have been fixed, while Mandiant and SlowMist are still continuing to assist with the investigation.
Bitget indicates that the financial impact of this incident will be borne by its protection fund. During the period of suspended withdrawals, the exchange stated that the fund held over $464 million and claimed that customer balances were still accurate. The description of the fund is Bitget's explanation of how it intends to absorb the losses; this does not mean that unauthorized transfers did not occur.
The CEO, Gracy Chen, also mentioned in a public discussion earlier that the attack might be related to North Korea, on the grounds that there were similarities between the IP address and the VPN service. However, she did not confirm the identity of the attackers. In previous investigative reports by crypto.news, no public attribution by any government agency was found either.
The theft of USDC and its transfer to the United States has drawn attention.
During the period of coin withdrawal suspension, security researcher Taylor Monahan identified some transfers that she believed were related to the attackers, including both transfers and operations to exchange for ETH. On September 25th, crypto.news reported that her findings raised a question: whether it is possible to stop the circulation of the stolen USDC. Public information has not confirmed whether Circle has received any legal orders related to these addresses.
This issue is directly related to the United States, as Circle is the issuer of USDC, which is headquartered in the US. Circle has stated that tokens will only be frozen under legal requirements. In a federal lawsuit filed in the US following the incident of Drift Protocol being exploited, one plaintiff alleged that Circle failed to prevent the stolen USDC from circulating through its cross-chain transfer system. This allegation is part of that lawsuit and does not constitute a ruling by the court against Circle; nor can it be used to assess Circle's response in the Bitget incident.
For Bitget customers, the next actual operation step is still the Bitcoin withdrawal window that will be opened at 08:00 on September 28th ( UTC ). The exchange stated that once the security checks are completed, they will confirm the restoration of each service through official notifications.












