Bitget Resumes Withdrawals Following $388 Million Security Breach
Bitget has begun a phased restoration of withdrawal services after a security exploit drained $388 million from its operational wallets, triggering significant customer outflows.

Bitget has started allowing users to withdraw funds again following a security breach on September 24 that resulted in the loss of approximately $388 million. The exchange, which previously held over $6.7 billion in total balances, reported that its reserves have since fallen to around $5.7 billion.
The breach was attributed to a zero-day vulnerability within a third-party security application. According to the exchange, attackers managed to spoof transactions by gaining access to internal credentials, though Bitget stated that cold wallets and private keys remained secure.
Withdrawals are being restored in phases to manage liquidity. Bitcoin withdrawals were enabled on September 28, followed by Ethereum on September 29 and USDT on September 30. The exchange plans to restore other assets and peer-to-peer transactions by October 2.
In the first 24 hours after withdrawals resumed, the exchange saw roughly $463 million in customer outflows. Shortly after the Bitcoin withdrawal window opened, the platform processed over 4,098 BTC in transactions.
CEO Gracy Chen stated that the exchange intends to cover all user losses using its User Protection Fund. Prior to the incident, the fund was valued at over $464 million, providing enough capital to cover the $388 million theft.
Bitget has engaged cybersecurity firms Mandiant and SlowMist to investigate the incident. Initial assessments have pointed to potential involvement from North Korean-linked hacking groups.
The breach highlights risks associated with third-party application security. While the exchange maintains a remaining reserve of $5.7 billion, the rapid outflow of customer funds indicates a significant impact on user trust following the event.



