Bitget has reopened Bitcoin withdrawals four days after a security incident moved an estimated $387.5 million in crypto assets to attacker-controlled addresses, beginning a phased restoration of services as the exchange deploys part of its Bitcoin-denominated Protection Fund into operational wallets.
BTC withdrawals on the Bitcoin network reopened at 08:00 UTC on September 28, according to Bitget’s official withdrawal schedule. Ether withdrawals are due to follow on September 29, USDT on September 30, and remaining cryptocurrencies, fiat withdrawals and P2P services on October 2.
Deposits and trading remained available throughout the withdrawal suspension.
The reopening also provides the first visible indication of how Bitget is positioning its Protection Fund after the attack. On-chain monitoring cited on Bitget News showed that 2,042.28 BTC, worth approximately $169 million at the time, had been transferred from Protection Fund addresses toward the exchange’s hot-wallet infrastructure.
The full Protection Fund held 5,500 BTC before the incident. The monitoring data showed another 3,457.72 BTC remaining on-chain at the time of the report. Importantly, the $169 million transfer should not be interpreted as $169 million already withdrawn by customers. Moving assets into hot wallets can pre-position liquidity for withdrawals before users actually request them.
Bitget Raises Security Incident Estimate to $387.5 Million
The September 24 incident was initially estimated at $351.6 million, but Bitget subsequently raised the figure to approximately $387.5 million after further transaction classification identified additional affected assets on Zcash and TRON.
The exchange said the revision did not reflect a second attack or additional transfers after containment. Rather, the original estimate had not captured the full scope of the transactions associated with the initial breach.
Assets affected included XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX and TRX across Ethereum and other EVM networks, XRP Ledger, Zcash and Tron.
Bitget says the attacker did not obtain private keys. Its investigation instead found that a critical backend system within the exchange’s wallet infrastructure had been compromised, allowing the attacker to spoof transaction data and trigger unauthorized transfers through the wallet authorization process.
That distinction matters because it separates the incident from attacks involving stolen signing keys. A recent compromised key incident involving ApeX Protocol led INDODAX to freeze APEX transfers, while Bitget says its own private-key layer remained intact.
Bitget also said its cold wallets were unaffected. Mandiant and blockchain security company SlowMist are supporting the continuing forensic investigation, tracing and recovery effort.
The Protection Fund Is Now Moving From Insurance Backstop to Active Liquidity
The most important development on September 28 may not simply be that withdrawals reopened. It is that Bitget’s Protection Fund is beginning to move.
Bitget established the fund in 2022 as a financial backstop for users during extreme events such as cybersecurity incidents. Before the attack, it held 5,500 BTC. The exchange valued the fund at more than $464 million around September 25, although its dollar value changes continuously with Bitcoin’s price.
That made the $387.5 million incident unusually large relative to the fund itself. Using Bitget’s stated $464 million valuation at the time, the affected amount represented roughly 84% of the fund’s dollar value.
Bitget has said the financial impact of the breach falls within the Protection Fund’s coverage and that the fund will be replenished. CEO Gracy Chen said during the September 28 incident review that Bitget intends to restore it to at least its $300 million baseline within a week after deployment.
The distinction between a Protection Fund and Proof of Reserves is important here. Proof of Reserves is intended to show assets backing customer balances. A protection fund is an additional pool designed to absorb losses from extraordinary events. Using the Protection Fund therefore does not, by itself, imply that ordinary customer reserves are being depleted.
Why Bitcoin Withdrawals Came Back First
Bitget is not reopening everything at once.
Bitcoin returned first, followed by ETH, USDT and finally the rest of the platform. The exchange says the phased process allows its technical teams to validate withdrawal infrastructure under controlled conditions before progressively increasing the number of supported assets and networks.
That approach has precedent across the industry. Exchanges frequently isolate individual funding routes when security or infrastructure concerns emerge. Crypto.com, for example, recently suspended deposits for 22 assets over a security concern rather than disabling its entire platform.
Bitcoin also has another practical advantage for Bitget: its Protection Fund is denominated in BTC.
Transferring Bitcoin directly from that reserve into operational hot wallets gives Bitget immediately available BTC liquidity as withdrawals resume. It avoids the need to sell another reserve asset, convert proceeds and then fund Bitcoin wallets.
This makes the 2,042.28 BTC transfer more significant than a simple movement between exchange-controlled addresses. It shows the Protection Fund moving from a publicly visible emergency reserve into infrastructure that can actually service customer activity.
The $169 Million Transfer Does Not Yet Show How Much Users Are Withdrawing
There is an important analytical trap in the on-chain data.
A large transfer from a protection wallet to a hot wallet can look like money leaving the exchange. It is not.
The assets remain under exchange control until they are sent onward to customers or other external addresses. Bitget can therefore move hundreds of millions of dollars internally before knowing how much withdrawal demand will ultimately materialize.
This distinction will become increasingly important over the next few days. Traders may monitor Protection Fund addresses, hot wallets and exchange outflows looking for evidence of a post-hack run. But internal wallet movements can easily be mistaken for customer withdrawals if addresses are viewed without context.
The more useful indicators will be actual outbound flows from Bitget-controlled wallets, changes in published reserve ratios and the speed at which the Protection Fund is replenished.
Operational shutdowns after security incidents are not unusual. Swiss Bitcoin Pay recently shut down its servers after detecting a suspected internal system breach. The harder test usually comes when services are switched back on and customers are once again free to move assets.
Bitget Is Entering the Harder Phase of the Recovery
Containment was the first challenge. Reopening withdrawals is the second.
Bitget says the vulnerability has been remediated, no further unauthorized transfers have been detected since containment, private keys were not compromised and customer account balances remain intact.
Those are important technical assurances, but restoring confidence requires more than stopping the attacker.
The exchange now needs to demonstrate that users can withdraw normally, that its reserve position remains sound after the loss, that the Protection Fund can be replenished as promised and that the independent forensic investigation can explain how a backend system was able to generate unauthorized wallet instructions despite existing risk controls.
The Protection Fund is particularly interesting because this incident is effectively a live test of an exchange insurance mechanism that is usually discussed only in marketing materials and monthly transparency reports.
Before September 24, the 5,500 BTC reserve was evidence of preparedness. After the breach, investors can watch what actually happens when that reserve has to be deployed.
That creates several measurable questions over the coming week: how much of the fund is ultimately used, how quickly Bitget restores it above $300 million, whether Proof of Reserves changes materially after the incident, and whether withdrawal demand accelerates as ETH, USDT and other assets are reopened.
If withdrawals proceed normally and the fund is replenished without pressure on customer reserves, Bitget will have demonstrated that the mechanism worked broadly as intended despite the scale of the loss.
If large outflows persist, reserve ratios deteriorate or the replenishment timetable slips, the security incident could evolve into a broader confidence problem.
That is why the September 28 reopening matters more than simply restoring one withdrawal button. Bitget has moved from containing a $387.5 million attack to proving that its financial safeguards, wallet infrastructure and customers can absorb the aftermath.
Johan Shamshad is a financial markets writer at Dave Finances covering cryptocurrencies, trading platforms, brokers, fintech, financial regulation, and developments across global markets. He previously worked at Gulf News, adding newsroom experience to his coverage of fast-moving financial and digital-asset markets.
His work focuses on identifying market-moving events, company developments, regulatory changes, product launches, and shifts in trading and financial infrastructure.
Johan contributes news and analysis designed to help readers understand not only what happened, but why a development matters and how it may affect the wider financial landscape.

