Wed. Sep 30th, 2026

Bitget Replenishes Protection Fund Above $300M as Incident Page Still Shows Older $464M Figure

ByJohan Shamshad

September 30, 2026 #Bitget
BitgetBitget

Bitget says it has replenished its User Protection Fund to more than $300 million following the exchange’s $388 million security breach, completing a capital injection only two days after promising to rebuild the fund within a week.

The September 30 update confirms that the fund has been restored above Bitget’s long-standing minimum threshold after being designated to absorb the financial impact of the September 24 attack.

Bitget said the replenishment was made using its own capital. The company has historically described the Protection Fund as self-funded rather than an insurance policy financed by an outside provider.

In its September 30 Protection Fund announcement, Bitget said the estimated amount affected by the security incident was approximately $388 million and reiterated that customer account balances remained intact.

The company had committed on September 28 to restore the Protection Fund to at least $300 million within one week. It now says that target has already been reached.

But there is an important disclosure wrinkle.

Bitget’s main security-incident page still lists the Protection Fund at more than $464 million, the figure the exchange was citing immediately after the attack and before the fund was deployed to absorb the loss.

The page also says it was last updated before the latest replenishment announcement, making the most likely explanation straightforward: the $464 million figure is a historical pre-deployment snapshot rather than the fund’s current value.

The $464 Million Figure Should Not Be Read as the Current Balance

When Bitget first disclosed the breach, the Protection Fund held 5,500 BTC worth approximately $464 million at prevailing prices.

At the time, that figure gave the exchange a relatively simple message: the stated value of the fund exceeded the initial loss estimate.

The arithmetic became tighter when Bitget revised the affected amount from $351.6 million to approximately $387.5 million after identifying additional transfers involving Zcash and TRON.

Bitget subsequently said the fund would cover the financial impact of the breach and that it would replenish the reserve afterward.

The company’s own incident hub, however, continues to say “Protection Fund $464M+” and tells users that the fund is sufficient to cover the full financial impact. That wording appears to reflect conditions when the incident page was assembled, not the post-loss fund position Bitget disclosed on September 30.

This distinction matters because simply seeing “$464M+” on the incident page alongside “$300M+” in the latest announcement could make the two figures look contradictory.

They do not have to be.

The first describes the fund around the time the breach was disclosed. The second describes the rebuilt reserve after capital was deployed and the fund was subsequently replenished.

On-Chain Movements Show the Fund Was Already Being Put to Work

The fund’s movements had begun becoming visible before Wednesday’s announcement.

Dave Finances previously reported that approximately 2,042.28 BTC had moved from Protection Fund addresses toward Bitget-controlled hot-wallet infrastructure as the exchange began its phased withdrawal recovery.

At the time, those coins were worth roughly $169 million.

That transfer was significant because Bitcoin withdrawals had just restarted after several days of suspension, creating an immediate need for operational liquidity in the exchange’s hot-wallet system.

But an internal wallet transfer should not automatically be treated as a $169 million economic loss to the Protection Fund.

If Bitcoin moves from a designated fund address to another Bitget-controlled address, Bitget still controls the asset. The blockchain proves that the coins moved; it does not establish whether they were sold, used to satisfy customer withdrawals, reclassified as operational liquidity or later returned to another protected wallet.

That makes tracing the actual fund drawdown more complicated than subtracting visible transfers from the original 5,500 BTC.

Bitget Has Not Disclosed the Exact Assets Added Back to the Fund

The September 30 announcement confirms that the fund is above $300 million, but it does not specify exactly how much capital was injected, the exact number of BTC added, whether the replenishment consisted entirely of Bitcoin, or whether other liquid assets were involved.

That is the biggest remaining financial disclosure gap.

Before the incident, Bitget presented the Protection Fund primarily as a 5,500 BTC reserve. Its public materials also emphasize that the associated wallets can be monitored on-chain.

That transparency theoretically makes the replenishment independently traceable.

In practice, researchers still need to distinguish several types of movement: transfers between fund wallets, transfers into operational hot wallets, customer withdrawals, treasury funding, recovered stolen assets and genuine new capital being added to the protection reserve.

The exact injection therefore cannot be established simply from the difference between $464 million and $300 million.

Bitcoin’s price changed during the period, the breach involved multiple cryptocurrencies rather than BTC alone, and some fund assets may have remained inside Bitget-controlled infrastructure even after leaving addresses publicly labeled as Protection Fund wallets.

The Financial Recovery Is Happening Alongside the Technical Recovery

The replenishment comes as Bitget continues rebuilding normal exchange operations after the September 24 breach.

The attack did not involve theft of Bitget’s private keys, according to the company. Investigators instead found that attackers exploited a vulnerability in a third-party security product, obtained internal access credentials and fed fraudulent withdrawal commands into the exchange’s backend wallet infrastructure.

Those commands were then processed by systems responsible for authorizing transfers.

That distinction is important. The attack demonstrated that protecting cryptographic keys is not enough if an attacker can compromise the infrastructure deciding what those keys should sign.

Bitget says the vulnerability has been identified and remediated and that no additional unauthorized transfers are possible.

Meanwhile, Bitcoin withdrawals resumed on September 28, Ethereum withdrawals followed, and USDT withdrawals were scheduled to reopen across several networks on September 30. Other cryptocurrency, fiat and peer-to-peer withdrawals are due to return on October 2.

The Protection Fund and Proof of Reserves Measure Different Things

There is another number investors should not confuse with the $300 million replenishment.

Bitget published a fresh Proof of Reserves snapshot on September 30 showing an overall reserve ratio of 131%, based on data captured at 09:00 UTC on September 29.

The company reported reserve coverage above 100% across all 19 assets included in the snapshot, including 142% for Bitcoin, 110% for Ether and 107% for both USDT and XRP.

Those figures address a different question.

Proof of Reserves is intended to show whether Bitget holds assets sufficient to cover reported customer balances. The Protection Fund is an additional reserve intended to absorb qualifying losses from events such as a platform security breach.

A company could theoretically have fully backed customer liabilities while its separate protection reserve had been heavily depleted. Conversely, a large protection fund would not by itself prove that ordinary customer deposits were fully backed.

That is why the post-hack picture requires looking at both.

Recovery of the Stolen Assets Could Still Reduce the Ultimate Cost

The approximately $388 million breach figure represents the value of assets transferred to attacker-controlled addresses, but Bitget’s final economic loss could still change if investigators recover or freeze part of the stolen portfolio.

The stolen XRP has already shown how difficult that process can be. More than half of the XRP taken in the breach moved out of its original holding wallets during the days after the attack.

Stablecoins create more opportunities for intervention because issuers can blacklist identified addresses. Native assets such as BTC, ETH and XRP generally cannot be remotely frozen while they remain in self-custodied wallets.

The attacker has also continued moving stolen funds through cross-chain infrastructure, although at least one attempted Chainflip route was rejected by a broker and returned to the originating address.

Any successful recovery would ultimately reduce the net amount Bitget has to absorb from its own balance sheet.

The More Important Number Is What the Fund Holds After the Dust Settles

Bitget deserves credit for completing the $300 million replenishment faster than the one-week timetable it announced on September 28.

But the more interesting question is not whether the exchange can place a headline number back above its stated minimum.

It is what that number actually consists of.

If the Protection Fund is supposed to function as an immediately deployable emergency reserve, investors should care about its asset composition, where those assets are held and how quickly they could be used if another platform-level incident occurred.

A fund holding more than $300 million of highly liquid Bitcoin in segregated, publicly visible wallets provides a different type of protection from a figure that depends partly on internal transfers, less-liquid assets or capital that has not yet reached designated reserve addresses.

Bitget says the fund is on-chain, transparent and traceable. That makes the next step unusually measurable.

The exchange has now told users that the reserve is back above $300 million. On-chain observers can watch whether designated Protection Fund wallets reflect that rebuilding and whether additional capital continues moving into them.

The stale $464 million figure on the incident page is probably a documentation issue, not evidence that Bitget is simultaneously claiming two current fund balances.

Still, after a breach of this size, precision matters.

The strongest follow-up disclosure would be simple: publish the exact post-incident drawdown, identify the assets and amounts used for replenishment, update the incident hub with the current figure and clearly separate money still held in the Protection Fund from capital moved into operational wallets.

Bitget has already restored the headline safety buffer. Now the more important test is whether outsiders can independently reconcile how it got there.

Financial Markets Analyst and Journalist at  |  More Posts

Johan Shamshad is a financial markets writer at Dave Finances covering cryptocurrencies, trading platforms, brokers, fintech, financial regulation, and developments across global markets. He previously worked at Gulf News, adding newsroom experience to his coverage of fast-moving financial and digital-asset markets.

His work focuses on identifying market-moving events, company developments, regulatory changes, product launches, and shifts in trading and financial infrastructure.

Johan contributes news and analysis designed to help readers understand not only what happened, but why a development matters and how it may affect the wider financial landscape.

Leave a Reply

Your email address will not be published. Required fields are marked *