Thu. Oct 1st, 2026

Bitget Reopens USDT Withdrawals After the $388M Security Incident

ByShane Neagle

September 30, 2026 #Bitget
BitgetBitget

Bitget has restored USDT withdrawals as the crypto exchange moves through the third stage of its recovery from a security breach that resulted in approximately $387.5 million in unauthorized transfers.

USDT withdrawals returned on September 30 across Ethereum, BNB Smart Chain, Solana and Tron, following the restoration of Bitcoin withdrawals on September 28 and Ethereum withdrawals across several networks on September 29.

The remaining stage is scheduled for October 2 at 08:00 UTC, when Bitget plans to restore withdrawals for other cryptocurrencies as well as fiat and peer-to-peer services. Deposits and trading continued operating during the withdrawal restrictions.

The reopening gives customers access to one of the exchange’s most important settlement assets. USDT is widely used by traders to move dollar-linked liquidity between exchanges, wallets and blockchains, making its restoration a more significant liquidity test than reopening a single volatile asset.

Bitget Raises the Incident Total to $387.5 Million

The incident began at 18:31 UTC on September 24, when Bitget detected unauthorized transfers from parts of its hot and warm wallet infrastructure. Its initial estimate placed the affected funds at $351.6 million, but the figure was subsequently increased to approximately $387.5 million after additional Zcash and Tron assets were incorporated into the accounting.

The revision did not represent a second breach. According to Bitget’s official incident timeline, it resulted from more complete accounting of transactions associated with the same attack.

Affected assets included XRP, ETH, USDT, USDC, ZEC, USDT0, XAUt, BNB, AVAX and TRX across Ethereum and other EVM networks, XRP Ledger, Zcash and Tron. Cold wallets, which Bitget says hold the majority of platform assets, were not affected.

The exchange also says customer account balances remained intact and that its Protection Fund, valued at more than $464 million around the incident, is intended to absorb the financial impact rather than pass the loss to customers.

The Attack Did Not Require Stealing Bitget’s Private Keys

The technical findings make the incident more complicated than a conventional hot-wallet private-key theft.

Bitget says investigators determined that the attacker exploited a zero-day vulnerability in a third-party security product, obtained internal network credentials and used that access to send forged withdrawal commands into the exchange’s wallet infrastructure. Those commands allegedly caused the system to execute abnormal transfers while bypassing existing risk controls.

Private keys themselves were not compromised, according to the exchange. That supports earlier evidence that Bitget’s backend wallet infrastructure was compromised rather than the cryptographic keys controlling its wallets.

The distinction matters. Protecting private keys is essential, but an exchange’s signing architecture still depends on systems that determine which transactions are legitimate. If an attacker can compromise the information or commands entering that process, a technically secure key can still end up authorizing a malicious withdrawal.

Bitget says the vulnerability has been remediated. Google-owned cybersecurity firm Mandiant and blockchain security company SlowMist are assisting with the investigation, while efforts to trace and recover stolen assets continue. Some attacker-linked funds have already moved through multiple networks and cross-chain services, although one recent attempt involving Chainflip was rejected by the broker processing the deposit.

A 131% Reserve Ratio Arrives at a Critical Time

Bitget also published a new Proof-of-Reserves snapshot immediately after the incident, giving traders a fresh data point for assessing the exchange’s financial position as withdrawals reopen.

The snapshot, taken at 09:00 UTC on September 29, showed an overall reserve ratio of 131% across 19 covered assets. Every covered asset was reported above 100%, including BTC at 142%, ETH at 110%, USDT at 107%, USDC at 154% and BNB at 104%.

The timing is unusually important. Proof-of-reserves disclosures can feel routine during normal market conditions. After an exchange absorbs a loss approaching $400 million and customers regain the ability to withdraw, the same figures become part of a real-world stress test.

That does not mean a 131% ratio settles every financial question. Proof of Reserves is designed to compare covered customer balances with specified reserve assets. It does not, on its own, provide the equivalent of a complete corporate balance-sheet audit covering every liability, operating obligation and potential contingent claim.

Still, the September 29 snapshot gives investors a measurable baseline to compare with subsequent reserve reports and on-chain flows. It is particularly relevant because the data was captured after the security incident rather than relying exclusively on a pre-breach reserve report.

The broader exchange industry is making the same transparency mechanism increasingly prominent. Bybit released its 40th Proof-of-Reserves report on September 30, reporting $19.6 billion in mainstream assets, up from $18.1 billion in August, while expanding coverage to 50 tokens. It reported reserve ratios of 110% for USDT, 223% for USDC, 104% for BTC and 103% for ETH.

USDT May Be the Most Revealing Withdrawal Test Yet

Bitget reopening USDT matters because stablecoins make leaving an exchange relatively simple.

A customer withdrawing Bitcoin may still be maintaining the same directional exposure while changing custody. USDT is different. It can move quickly to another centralized exchange, a self-custody wallet or on-chain trading infrastructure without exposing the user to the volatility involved in converting into another cryptocurrency.

That makes the next few days useful for judging customer confidence.

A large initial wave of withdrawals would not necessarily be alarming. Customers were unable to withdraw for several days, so some pent-up demand is inevitable. Traders may also move funds simply because they want to reduce counterparty exposure after a major security incident.

The more meaningful signal would be whether elevated withdrawals persist after that initial backlog clears. Sustained outflows accompanied by declining reserve ratios would tell a very different story from a short post-reopening surge followed by normalization.

The exchange already processed substantial demand during the first phase. By 17:00 UTC+8 on September 28, CEO Gracy Chen said Bitget had completed 9,585 Bitcoin withdrawal orders totaling 4,098.036 BTC. The subsequent Ethereum withdrawal rollout expanded the test across Ethereum, BSC, Arbitrum, Base and Optimism before the USDT stage added another group of heavily used networks.

The Bigger Test Comes After Withdrawals Are Fully Restored

Getting withdrawal infrastructure running again solves only one part of the problem.

Bitget still needs to demonstrate how effectively its Protection Fund absorbs the loss, how quickly that fund is replenished, whether reserve coverage remains stable after customers regain unrestricted access to their assets and what the final forensic investigation says about controls surrounding its wallet authorization systems.

The incident also exposes a broader weakness in the way exchange security is often discussed. The industry spends enormous attention on key management and cold storage, but the Bitget attack suggests sophisticated attackers may not need to defeat those defenses directly. Compromising trusted software, internal credentials or the systems feeding instructions into a signing process can potentially produce the same outcome.

That makes third-party software risk a much bigger issue for centralized exchanges. Every security product, credential-management layer and automated wallet component added to an exchange can improve defenses, but it can also expand the number of systems whose compromise could eventually reach transaction infrastructure.

For Bitget, the 131% Proof-of-Reserves figure is therefore encouraging data, but it is not the end of the recovery story. The stronger test is whether those ratios remain healthy after withdrawals have been open long enough for customers to act freely.

October 2 is the next obvious checkpoint. If Bitget restores the remaining tokens, fiat withdrawals and P2P services on schedule, it will effectively return customers to full mobility roughly eight days after the breach. After that, the story shifts away from whether users can withdraw and toward what the incident ultimately costs, how much stolen cryptocurrency can be recovered, how the Protection Fund is rebuilt and whether the security changes prevent another attack through the same class of infrastructure.

For traders, those are more useful signals than any single headline reserve ratio. A crypto exchange proves resilience after a hack not when it publishes reassuring numbers, but when customers are free to test those numbers by taking their money out.

Financial Markets Analyst and Digital Assets Journalist at  |  More Posts

Shane Neagle is a financial markets analyst and digital assets journalist specializing in cryptocurrencies, memecoins, prediction markets, and blockchain-based financial systems. His work focuses on market structure, incentive design, liquidity dynamics, and how speculative behavior emerges across decentralized platforms.

He closely covers emerging crypto narratives, including memecoin ecosystems, on-chain activity, and the role of prediction markets in pricing political, economic, and technological outcomes. His analysis examines how capital flows, trader psychology, and platform design interact to create rapid market cycles across Web3 environments.

Alongside digital assets, Shane follows broader fintech and online trading developments, particularly where traditional financial infrastructure intersects with blockchain technology. His research-driven approach emphasizes understanding why markets behave the way they do, rather than short-term price movements, helping readers navigate fast-evolving crypto and speculative markets with clearer context.

Leave a Reply

Your email address will not be published. Required fields are marked *