Bitget has begun restoring withdrawals after a $387.5 million security breach, with the exchange saying its Protection Fund will cover the financial impact while user account balances remain unaffected.
According to Bitget’s official withdrawal schedule, Bitcoin withdrawals resumed at 08:00 UTC on Sept. 28. Ethereum withdrawals are scheduled for Sept. 29, USDT for Sept. 30, while other tokens, fiat and P2P services are expected to return by Oct. 2.
The phased reopening represents the first major operational test for the exchange since attackers compromised part of its wallet infrastructure on Sept. 24.
Bitget Says the Vulnerability Has Been Fixed
Bitget initially estimated losses at roughly $351.6 million before expanding the figure to $387.5 million after identifying additional affected transactions involving Zcash and Tron.
The revised total reflected a fuller accounting of the original attack rather than a second breach, according to the exchange.
The incident affected assets across Ethereum and other EVM networks, XRP Ledger, Zcash and Tron, with stolen tokens including XRP, ETH, USDT, USDC, BNB, AVAX and TRX.
A detailed timeline of the Bitget hack shows how the attack progressed from the initial wallet compromise to the withdrawal freeze and subsequent recovery efforts.
Bitget says the underlying vulnerability has now been identified and remediated, while Mandiant and SlowMist continue assisting with forensic analysis and fund tracing.
| Withdrawal Stage | Scheduled Return |
|---|---|
| Bitcoin | Sept. 28 |
| Ethereum | Sept. 29 |
| USDT | Sept. 30 |
| Other tokens / Fiat / P2P | Oct. 2 |
Protection Fund Now Faces Its Biggest Test
The exchange says the temporary withdrawal halt was a security measure rather than a liquidity problem.
Bitget’s Protection Fund is designed to provide additional financial protection during major platform incidents and is separate from the exchange’s proof-of-reserves system.
The company says the fund will absorb the impact of the breach, meaning users are not expected to take losses from the stolen assets.
That claim is especially important because investigators are still tracing a substantial portion of the stolen funds. Around $83 million in stolen XRP has already been moved from several attacker-controlled wallets, while native XRP cannot simply be frozen at the protocol level.
The breach has also renewed scrutiny of suspected North Korean crypto theft activity. Investigators have identified similarities with previous attacks, although the attacker’s identity has not been conclusively established. Coinpaper previously examined why North Korea emerged as a leading suspect.