Bitget has initiated a gradual revival of platform withdrawals following a security breach on September 24 that siphoned roughly $388 million out of the system.
In an official announcement provided to The Block, the digital asset trading platform confirmed that Bitcoin payouts have started on the Bitcoin and BSC networks as planned at 8 a.m. UTC on Monday.
Before turning payouts back on, Bitget noted that every blockchain network requires a thorough series of security assessments, prompting the step-by-step restoration process. Subsequent to today’s reactivation of Bitcoin transfers, Ethereum withdrawals across the Ethereum, BSC, Arbitrum, Base, and Optimism networks will go live on September 29 at 8 a.m. UTC, the company stated.
Tether payouts on the Ethereum, BSC, Solana, and Tron networks will unlock simultaneously the next day, whereas all remaining coins, fiat cash-outs, and peer-to-peer services are scheduled to come back online on October 2, as outlined by the platform.
The exploit
Around 6:31 p.m. UTC on September 24, illicit token movements across several chains originated from Bitget’s active and intermediate wallet reserves. The trading venue reported that the hacker exploited a flaw in an external security tool utilized by Bitget to gain privileged internal access rights.
The hacker subsequently leveraged those permissions to transmit fraudulent payout requests to the wallet architecture, forcing it to carry out irregular transactions that evaded security safeguards, according to the platform.
Although Bitget refrained from naming the specific digital currencies taken in its recent update, prior reporting by The Block indicated that ether, USDT, USDC, AVAX, and BNB formed part of the illicitly transferred funds.
The exchange clarified that its cryptographic private keys remained secure, while user account balances and offline cold storage vaults were untouched. Management announced plans to re-evaluate how external security vendor solutions are vetted and integrated to fortify defenses, with firms like Mandiant and SlowMist aiding the ongoing probe. Bitget anticipates wrapping up a formal security assessment over the course of the week and sharing additional discoveries once verified.
Bitget stated that the security flaw has been fixed and the breach isolated. It also confirmed that no further unauthorized token movements have taken place, while verifying the total stolen value at $388 million.
This $388 million loss stands as the biggest documented digital asset theft so far this year, eclipsing security incidents affecting KelpDAO and Drift Protocol. Nevertheless, Bitget assured that all damages stemming from the event will be completely absorbed by the Bitget User Protection Fund, which maintains a reserve of 5,500 BTC.
Aiming to retrieve the missing capital, Bitget introduced a reward initiative where participants whose efforts directly lead to the freezing or recovery of misappropriated funds will be awarded 5% of the secured amount. The platform subsequently mentioned that a portion of the impacted tokens has already been frozen through joint efforts with sector allies, though the exact sum was left unannounced.
While Bitget emphasized it will refrain from guessing who is behind the hack until the inquiry concludes definitively, it described the perpetrators as advanced and state-sponsored actors skilled at hiding stolen capital. The firm previously indicated to journalists that North Korea is suspected of orchestrating the assault.
Updated with additional details from Bitget.
Originally published at https://www.theblock.co/news/business/2026-09-28-bitget-starts-phased-withdrawal-resumption-416965.