Bitget Hack: $387.5M Impact and Phased Withdrawal Recovery Explained

KTX
KTX
  • Updated

Bitget has set a four-stage withdrawal timetable after confirming that approximately $387.5 million in assets were transferred to attacker-controlled addresses during a September 24 security incident. Bitcoin withdrawals were scheduled to reopen first at 08:00 UTC on September 28, followed by selected Ethereum-compatible networks, USDT routes and, finally, other assets, fiat withdrawals and P2P services on October 2.

The revised impact is $35.9 million above Bitget's initial $351.6 million estimate. According to the exchange, the increase came from adding previously unclassified Zcash and TRON transfers to the total, rather than from new unauthorized transfers after the incident was contained. That distinction matters: the larger figure changes the scale of the event, but it does not by itself show that the breach remained active.

KTX News cover explaining the $387.5 million Bitget security incident and phased withdrawal recovery

$387.5 million measures the transfers, not confirmed customer losses

Bitget said the incident affected part of its hot- and warm-wallet infrastructure across Ethereum and other EVM networks, XRP Ledger, Zcash and TRON. The assets identified so far include XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX and TRX.

The $387.5 million figure describes the estimated value transferred to attacker-controlled addresses. It should not automatically be read as the final loss borne by customers. Bitget says customer account balances remain unaffected and that its Protection Fund will absorb the platform's financial impact. Those are company statements while the investigation and recovery process remain open; a final accounting will depend on funds frozen or recovered, incident-related costs and any later revisions to the traced amount.

Bitget has disclosed that some affected assets were frozen through coordination with exchanges, blockchain projects and security firms, but it has not published a consolidated dollar value for those freezes. The company also opened a recovery bounty that can pay 5% of funds frozen or recovered when eligible voluntary action directly produces that result.

Why withdrawals are returning network by network

The announced schedule does not restore every withdrawal route at once:

Time (UTC) Assets and services Networks
September 28, 08:00 BTC withdrawals Bitcoin
September 29, 08:00 ETH withdrawals Ethereum, BSC, Arbitrum, Base and Optimism
September 30, 08:00 USDT withdrawals Ethereum, BSC, Solana and Tron
October 2, 08:00 Other tokens, fiat withdrawals and P2P Availability varies by service

Four-stage Bitget withdrawal timetable for BTC, ETH and EVM networks, USDT networks, and remaining services

A phased reopening lets an exchange validate signing, balance reconciliation, address screening and broadcast behavior for a smaller group of networks before expanding access. Each blockchain has different wallet software, transaction formats and confirmation behavior. Passing checks on Bitcoin therefore says little about whether every token contract or withdrawal route is ready.

The timetable should also be treated as a restoration target, not proof that each route will operate without queues or later adjustments. The practical test is whether users can submit, receive and verify withdrawals on the specific asset and network listed as available.

Trading continued because order matching and withdrawals are separate systems

Bitget said trading and deposits continued during the withdrawal pause. That can sound contradictory, but the functions are different. A spot trade can update balances inside an exchange's internal ledger, while a withdrawal requires the exchange to authorize and broadcast an onchain transaction from its wallet infrastructure.

The KTX guide to crypto spot trading explains how ownership changes through exchange execution. The guide to order books and market depth covers how bids and asks are matched. Neither function, by itself, demonstrates that external wallet settlement is available.

This separation is why continued trading volume should not be used as evidence that the withdrawal system had fully recovered. It only shows that the trading engine and related account functions were still operating.

The current account points to a backend compromise, not stolen private keys

Bitget's preliminary account says a critical backend system was compromised and transaction data was spoofed in a way that triggered authorization. The exchange says cold wallets were unaffected and that investigators had ruled out a private-key compromise at the time of its update. Mandiant and SlowMist are supporting the investigation.

That explanation narrows the suspected attack path, but it is not yet a complete postmortem. A full report would need to explain which controls accepted the manipulated data, how the activity evaded monitoring, when the first unauthorized transaction occurred and what technical changes prevent the same method from working again.

The distinction also affects remediation. Rotating wallet keys addresses suspected key exposure; a backend authorization failure requires changes to transaction construction, approval separation, anomaly detection and the evidence needed before a transfer can be signed.

What users should check during the phased recovery

  • Match both the asset and network. ETH on Ethereum and a token on another EVM network are separate withdrawal routes even when the address format looks similar.
  • Check the live withdrawal page. A published timetable can change if validation reveals another problem.
  • Use a small test first. Confirm the destination address, network, fee and arrival before moving a larger amount.
  • Ignore recovery messages sent by strangers. A genuine withdrawal restoration does not require users to disclose seed phrases or send funds to an “activation” address.
  • Keep records. Save transaction IDs, account notices and support correspondence if a withdrawal remains pending.

Readers comparing centralized trading venues should review custody arrangements, withdrawal rules and incident procedures before moving funds. Eligible users can create a KTX account and examine the products available in their region, along with the applicable fees and risk terms.

What comes next

Four points will show whether the recovery is progressing as announced: actual withdrawal availability at each scheduled stage, any queue or processing delays, the amount of funds frozen or returned, and publication of a detailed technical postmortem. A further revision to the traced total would also matter, because Bitget has said transaction classification is still continuing.

The phased schedule is evidence that the exchange has moved from containment toward operational restoration. It is not the end of the incident. The stronger test will be whether withdrawals remain stable across networks and whether the final investigation provides enough detail to evaluate the controls that failed.

Frequently Asked Questions

Did Bitget lose $387.5 million of customer funds?

The figure refers to assets Bitget says were transferred to attacker-controlled addresses. The exchange says customer balances are unaffected and its Protection Fund will cover the platform impact. The final net loss cannot be established until recovery, freezing and accounting are complete.

Why did the estimate rise from $351.6 million?

Bitget said the revised figure includes Zcash and TRON transfers that were not in the initial estimate. It said the increase does not represent new unauthorized transfers after containment.

Does the reopening of BTC withdrawals mean all withdrawals are back?

No. The schedule separates BTC, selected ETH and EVM routes, specified USDT networks, and all remaining services into different stages through October 2.

Risk disclosure: This article is for information only and is not investment advice. Digital assets and centralized platforms involve market, custody, liquidity, operational and cybersecurity risks.

Was this article helpful?

0 out of 0 found this helpful

Have more questions? Submit a request