Bitget Restarts Bitcoin Withdrawals After $388M Hack as Investigation Points to Third-Party Security Flaw
Crypto exchange Bitget has restarted Bitcoin withdrawals four days after attackers moved approximately $388 million in digital assets from parts of its hot and warm wallet infrastructure.
Bitcoin withdrawals began reopening at 08:00 UTC on September 28, 2026, following additional security checks. Bitget says withdrawals are being restored gradually across different assets and networks rather than switching everything back on at once. The restart comes as the investigation into the September 24 attack has produced a clearer picture of what may have gone wrong.
According to Bitget’s latest account, the attacker may have exploited a vulnerability in a third-party security product, obtained high-level internal credentials and used those credentials to send fraudulent withdrawal instructions into Bitget’s wallet infrastructure. Crucially, Bitget says the attacker did not steal the private keys controlling its wallets, and its cold-storage wallets were not affected. The result was still enormous.
Bitget currently estimates approximately $387.5 million worth of assets was transferred to attacker-controlled addresses. That makes this a useful reminder that sometimes you do not need to break into the vault. You just need to convince the system that you are allowed to open the door.
What Happened to Bitget?
Bitget says its security systems detected unauthorised transfers at approximately 18:31 UTC on September 24.
Its initial security notice estimated the value of affected assets at around $351.6 million and said the incident involved only part of its hot and warm wallet infrastructure.
Hot wallets are cryptocurrency wallets connected to online systems so exchanges can process customer transactions quickly.
Cold wallets are normally kept more isolated from the internet and are generally used to store larger amounts of cryptocurrency more securely.
Bitget operates a three-tier system consisting of hot, warm and cold wallets.
The company says its cold wallets remained secure throughout the incident.
Withdrawals were suspended shortly after the incident while deposits and trading continued operating.
Bitget says the withdrawal freeze was a security measure designed to prevent further movement while engineers investigated the attack.
The Loss Estimate Rose From $351.6 Million to $387.5 Million
The first number published by Bitget was approximately $351.6 million.
That figure later increased to approximately $387.5 million after investigators completed more on-chain tracing and transaction classification.
According to Bitget’s September 25 investigation update, the additional amount included affected transactions involving Zcash and TRON that had not been included in the initial estimate.
The company says this does not mean attackers stole another $35.9 million after the breach was contained.
Instead, investigators discovered that the original attack involved more assets than initially calculated.
The affected assets identified so far include cryptocurrencies and tokens such as XRP, ETH, USDT, ZEC, USDC, XAUt, BNB, AVAX and TRX, spread across several blockchain networks.
Bitget’s later incident summary says activity linked to the breach touched 11 blockchains, including Ethereum, XRP Ledger, TRON, BNB Smart Chain, Avalanche, Arbitrum, Optimism and Base.
Investigators Now Point to a Third-Party Security Product
The most important new development concerns how the attackers reportedly got in.
Bitget’s updated investigation says the attacker may have exploited a vulnerability in a third-party security product used by the exchange.
That weakness appears to have allowed the attacker to obtain high-level internal credentials.
Those credentials could then be used to make malicious activity look like authorised internal activity.
Bitget says the attacker appears to have used them to send fraudulent withdrawal commands to the wallet system, causing transfers that bypassed existing risk controls.
CEO Gracy Chen separately told Cointelegraph that the credentials allowed the attacker to issue fraudulent withdrawal commands while the actual private keys remained uncompromised.
Bitget has not publicly named the third-party security product.
This was not, according to the investigation so far, a case where hackers simply obtained a wallet’s private key and started sending cryptocurrency.
They appear to have compromised the infrastructure responsible for deciding which transactions should be authorised.
Bitcoin Withdrawals Are Back
After several days of security validation, Bitget began restoring withdrawals on September 28.
According to its updated incident timeline, BTC withdrawals resumed at 08:00 UTC, initially across the Bitcoin network and subsequently BNB Smart Chain.
The exchange’s staged schedule currently provides for:
Bitcoin on September 28, Ether on September 29, USDT on September 30, and remaining supported tokens, fiat withdrawals and P2P services on October 2.
Bitget says each asset and blockchain must pass additional security checks before its withdrawal route is reopened.
The exchange’s withdrawal restoration announcement says the same published schedule applies to ordinary users, institutional clients, VIP customers and employees.
Trading and deposits continued operating while withdrawals were suspended.
Bitget Says Customer Balances Are Unaffected
Bitget maintains that customer account balances have not been reduced because of the attack.
The company says the financial impact will be covered through its User Protection Fund.
At the time the breach was first disclosed, Bitget said the fund held more than $464 million, which was above the exchange’s initial estimate of the loss.
The revised $387.5 million figure still sits below that amount.
Bitget describes the Protection Fund as a separate financial-protection mechanism designed for eligible platform-level security incidents.
It is different from the exchange’s Proof of Reserves, which is intended to show assets held relative to customer balances.
The claim that customers remain financially protected is Bitget’s position, and the exchange says further post-incident reserve information will be published as verification work continues.
Mandiant and SlowMist Are Investigating
Bitget has brought in external cybersecurity specialists to support the investigation.
The company says Mandiant, which is part of Google Cloud, and blockchain security firm SlowMist are involved in forensic analysis, attack-vector investigation and asset tracing.
The investigation includes examining which systems were affected, validating Bitget’s remediation work and following the movement of stolen assets across different blockchains.
Bitget says it has already:
- revoked and reissued internal credentials,
- restructured access to highly sensitive systems,
- added multiple approvals for critical operations,
- strengthened withdrawal verification,
- expanded abnormal-activity monitoring.
It has also disabled the affected third-party functionality and notified the vendor involved.
The obvious question for exchanges everywhere will now be whether they have spent so much time protecting private keys that they have underestimated the software and vendors surrounding those keys.
Some of the Stolen Assets Have Been Frozen
The theft did not end when the funds left Bitget.
Blockchain investigators, exchanges, stablecoin companies and other infrastructure providers have been tracking the attacker-controlled addresses.
Bitget says some affected assets have already been frozen, although it has not published a verified total showing how much has been recovered.
The exchange has published attacker addresses and created a live tracing system intended to help other industry participants identify the stolen funds.
It has also launched a Recovery Bounty Program.
Under the programme, eligible voluntary efforts that directly result in stolen assets being frozen or recovered can qualify for a bounty equal to 5% of the affected amount successfully frozen or recovered.
Bitget is also using Bybit’s Lazarus Bounty programme as one of its recovery channels.
Is North Korea Behind the Attack?
Possibly.
But it has not been conclusively established.
Blockchain intelligence company Elliptic says multiple indicators make a connection to North Korean-linked hackers highly likely.
Its analysis of the Bitget attack points to similarities in laundering behaviour, connections to infrastructure previously associated with DPRK-linked attacks and patterns similar to previous large cryptocurrency thefts.
Elliptic also identified links between funds associated with the Bitget attack and addresses involved in laundering assets from earlier attacks attributed to North Korea.
Chen has also said publicly that aspects of the attack appear consistent with techniques previously associated with DPRK-linked groups.
However, Bitget’s own updated incident report says its independent forensic investigation remains ongoing and warns that unverified attribution should not be treated as a confirmed conclusion.
So the accurate position for now is: North Korean involvement is suspected, not proven.
Frequently Asked Questions
How much was stolen from Bitget?
Bitget currently estimates that approximately $387.5 million, or about $388 million, was transferred to attacker-controlled addresses during the September 24 incident. The figure was revised upward from an initial $351.6 million estimate after additional affected transactions were identified.
Have Bitget withdrawals resumed?
Yes. Bitcoin withdrawals began resuming on September 28 at 08:00 UTC. Ether, USDT and other services are being restored in phases.
Were Bitget’s private keys stolen?
Bitget says no. Its investigation has so far ruled out private-key compromise, and cold wallets were not affected.
How did the attacker get into Bitget?
Bitget’s preliminary investigation says the attacker may have exploited a vulnerability in a third-party security product to obtain high-level internal credentials, which were then allegedly used to issue fraudulent withdrawal commands.
Will customers lose their money?
Bitget says customer account balances remain unaffected and that its Protection Fund will cover the financial impact of the incident.
Was North Korea responsible?
That has not been conclusively established. Blockchain intelligence firm Elliptic assesses the attack as highly likely to be DPRK-linked, while Bitget says the formal forensic investigation and attribution process remain ongoing.

