Bitget will begin restoring cryptocurrency withdrawals on Sept. 28, four days after a security breach moved approximately $387.5 million in assets to attacker-controlled addresses and forced the exchange to suspend customer withdrawals.
Bitcoin withdrawals will reopen first at 08:00 UTC on Sept. 28, according to Bitget. Ether withdrawals will follow at 08:00 UTC on Sept. 29 across Ethereum, BNB Smart Chain, Arbitrum, Base and Optimism.
USDT withdrawals are scheduled to return at 08:00 UTC on Sept. 30 across Ethereum, BNB Smart Chain, Solana and Tron. Bitget plans to restore withdrawals for other cryptocurrencies, along with fiat withdrawals and peer-to-peer services, at 08:00 UTC on Oct. 2.
The timetable marks the first concrete path back to normal customer withdrawals since Bitget confirmed the security breach and paused withdrawals on Sept. 24.
Trading and deposits remain operational throughout the suspension. Bitget says customer account balances have not been affected and that its User Protection Fund will absorb the financial impact of the incident.
The exchange also says the vulnerability used in the attack has now been identified and remediated. Independent cybersecurity firms Mandiant and SlowMist are assisting with the investigation while Bitget conducts additional checks across its withdrawal infrastructure before reopening each service.
Bitget Raises the Incident Total to $387.5 Million
The restoration announcement follows a significant revision to the scale of the attack.
Bitget initially estimated that approximately $351.6 million had been affected after unauthorized transfers were detected at 18:31 UTC on Sept. 24. Subsequent on-chain tracing and transaction classification increased that figure to approximately $387.5 million.
The exchange said the higher number includes Zcash and Tron assets that were not captured in its initial accounting. Crucially, Bitget says the increase does not represent additional theft after the incident was contained. It reflects a more complete tally of transfers that occurred during the original breach.
The affected assets span Ethereum and other EVM networks, XRP Ledger, Zcash and Tron and include XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX and TRX.
Bitget has also provided more detail about the attack path. CEO Gracy Chen said the company’s private keys were not stolen. Instead, the investigation points toward a compromise of Bitget’s backend wallet infrastructure, allowing the attacker to manipulate transaction information before it reached the authorization process.
That distinction matters. Secure private-key storage does not necessarily stop an attack if another compromised system can feed fraudulent transaction instructions into a legitimate signing workflow.
Bitget says the underlying vulnerability has now been fixed and that no additional unauthorized transfers are possible. A more detailed technical account will still be important for establishing exactly how the attacker entered the backend environment and what controls have changed since the breach.
Recovery Efforts Continue While Withdrawals Remain Paused
Reopening customer withdrawals does not mean the recovery of stolen assets is complete.
Bitget says some affected funds have already been frozen through cooperation with exchanges, blockchain projects and security firms. The company has launched a recovery bounty offering eligible participants 5% of funds they directly help freeze and another 5% of assets they help successfully recover.
Bitget is also using Bybit’s LazarusBounty initiative as one channel in the recovery effort and has published attacker addresses and live tracking data for exchanges, stablecoin issuers, custodians and security teams.
The mix of stolen assets matters for recovery. Centralized stablecoins provide issuers with tools unavailable for native assets such as Bitcoin or Ether. As previous cases involving Tether freezing specified USDT wallets have demonstrated, an issuer can block tokens at identified addresses under certain circumstances.
Assets such as ETH are harder to immobilize directly once an attacker controls the private keys. Investigators instead have to trace subsequent transfers and coordinate with exchanges, bridges or other centralized points where the funds may eventually pass.
That helps explain why fund recovery and technical restoration are separate processes. Bitget can potentially reopen customer services before every stolen asset has been recovered, provided it has replenished the operational infrastructure and can honor customer balances from its own resources.
The Protection Fund Is Now Facing Its First Major Stress Test
Bitget’s claim that customer funds are unaffected requires an important distinction.
The platform itself has suffered a large financial loss. Approximately $387.5 million in assets were transferred to attacker-controlled addresses. What Bitget means by customer funds being unaffected is that users’ recorded balances remain intact and the company says its Protection Fund will absorb the loss rather than passing it on to customers.
Before the updated loss calculation, Bitget said the fund was worth more than $464 million. The stated fund value therefore remains above the revised incident estimate, although both crypto asset values and the final recovery amount can change.
This is where reserve disclosures and practical access to funds need to be kept separate. The crypto industry has repeatedly shown that asset transparency and actual withdrawal access answer different questions.
A platform may show substantial assets while customers still face operational restrictions. Conversely, temporarily stopping withdrawals after an active attack can be a legitimate containment measure rather than evidence of a liquidity shortfall.
For Bitget, the phased reopening should provide much more useful evidence than another assurance about balances. If BTC withdrawals restart on schedule, followed by ETH, USDT and the remaining assets without further disruption, users will begin to see whether the exchange has successfully rebuilt a functioning withdrawal environment around the remediated infrastructure.
Why Bitcoin, Ether and USDT Are Returning Separately
The staggered timetable is notable because Bitget is not simply switching withdrawals back on across the entire exchange at once.
Bitcoin returns first, followed by Ether across five networks and then USDT across four networks. Other tokens, fiat withdrawals and P2P transfers do not return until Oct. 2.
Bitget says the phased structure allows security validation to continue while services are restored in an orderly manner. It also says the rollout applies equally across users rather than prioritizing individual customers.
The approach reflects how complicated a large exchange’s withdrawal system actually is. Supporting a cryptocurrency means more than maintaining an account balance. Exchanges operate wallet systems, signing infrastructure, blockchain nodes, transaction monitoring, reconciliation systems and network-specific controls.
This is also why trading can continue while withdrawals are unavailable. Internal exchange trades primarily change balances inside the platform’s ledger. A blockchain withdrawal requires the exchange to create and authorize an external transaction.
That separation has appeared in other recent incidents where trading remained available while blockchain transfers were restricted. Bitget’s situation is considerably more serious because the restriction followed an actual security breach rather than a routine gateway problem, but the operational distinction is the same.
Restoring Withdrawals Is the First Credibility Test, Not the Last
The Sept. 28 reopening will be an important milestone because withdrawal access is one of the simplest ways customers judge whether a centralized exchange is functioning normally.
But it is not the end of the story.
Bitget still needs to publish enough technical detail to show how the backend compromise occurred, why existing controls failed to reject malicious transactions and what architectural changes were made to prevent the same attack path from being reused.
There is precedent for separating these stages. When Blink restored services following a custodial-account breach, reopening the platform demonstrated operational recovery, while questions about the precise intrusion and affected funds remained a separate part of the security assessment.
Bitget faces that challenge on a vastly larger financial scale.
The exchange must also demonstrate how the Protection Fund is being used. A fund valued above the reported loss is reassuring on paper, but investors will want to know whether covering the incident changes its size or composition, how quickly the fund is replenished and whether recovered stolen assets eventually flow back into the protection structure.
The recovery operation itself could also materially change the final economic loss. Frozen or returned funds reduce what Bitget ultimately has to absorb, while unrecovered assets keep the burden on the exchange.
The Sept. 28 AMA Could Shift Attention From Recovery to Accountability
CEO Gracy Chen is scheduled to hold a live AMA at 07:30 UTC on Sept. 28, just 30 minutes before Bitcoin withdrawals are due to resume.
The timing makes the session unusually significant.
Until now, the central questions have been whether the attack was contained, whether customer balances remained protected and when withdrawals would return. Bitget has now provided answers to all three: it says the vulnerability is fixed, the Protection Fund covers the financial impact and a reopening schedule has been established.
The next questions are more difficult.
Investors and customers will want greater detail on how a backend wallet system controlling hundreds of millions of dollars was compromised, why the attack bypassed existing safeguards, whether the affected wallet architecture has been redesigned and how much of the $387.5 million has actually been frozen or recovered.
A successful withdrawal restart would materially reduce the immediate operational risk surrounding the incident. If BTC, ETH and USDT reopen according to schedule and the wider platform follows on Oct. 2, Bitget will have moved from emergency containment into recovery relatively quickly.
But the scale of the breach means normal withdrawals alone cannot close the case.
The lasting assessment will depend on whether Bitget can show that the vulnerability was not merely patched, but that the transaction-authorization architecture surrounding it is substantially harder to compromise the next time an attacker reaches the systems sitting between a withdrawal request and the private key that signs it.
Johan Shamshad is a financial markets writer at Dave Finances covering cryptocurrencies, trading platforms, brokers, fintech, financial regulation, and developments across global markets. He previously worked at Gulf News, adding newsroom experience to his coverage of fast-moving financial and digital-asset markets.
His work focuses on identifying market-moving events, company developments, regulatory changes, product launches, and shifts in trading and financial infrastructure.
Johan contributes news and analysis designed to help readers understand not only what happened, but why a development matters and how it may affect the wider financial landscape.

