Bitget brings back USDT withdrawals after $387M hack
Bitget has restored BTC, ETH and USDT withdrawals after its $387.5 million security breach, while P2P, fiat and remaining token withdrawals are scheduled to return Friday.
- Bitget restored BTC, ETH and USDT withdrawals, with remaining services scheduled Friday at 08:00 UTC.
- Bitget’s latest proof-of-reserves snapshot shows a 131% overall reserve ratio across nineteen covered crypto assets.
- Gracy Chen says the Protection Fund has returned above $300 million after the security incident.
- THORChain rejected Bitget’s request to block attacker addresses, citing its permissionless network design after hack.
- Bitget says investigators traced $387.5 million in unauthorized transfers from hot and warm wallet infrastructure.
Bitget CEO Gracy Chen said on Sept. 30 that withdrawals for the three major assets were already operating and that the exchange’s Protection Fund had returned above $300 million. She described the business as “gradually back to usual” following the Sept. 24 attack.
In a separate post, Chen confirmed that P2P withdrawals will reopen Friday, Oct. 2 at 08:00 UTC alongside the remaining services covered by Bitget’s staged recovery plan.
Bitget withdrawals are almost fully restored
Bitcoin withdrawals became the first to return at 08:00 UTC on Sept. 28, four days after Bitget halted withdrawals across the exchange. Ether followed on Sept. 29 across Ethereum, BNB Smart Chain, Arbitrum, Base and Optimism.
USDT withdrawals reopened Sept. 30 across Ethereum, BNB Smart Chain, Solana and Tron, according to Chen’s latest update. Bitget’s published timetable places other tokens, fiat withdrawals and P2P in the final stage at 08:00 UTC on Oct. 2.
The current rollout advances the phased Bitget withdrawal reopening previously reported by crypto.news, when BTC became available while security teams continued checking the exchange’s withdrawal infrastructure.
Bitget says deposits and trading remained available while withdrawals were suspended. The exchange maintains that customer account balances were unaffected and that the temporary halt was introduced while its technical teams validated the affected systems.
The incident began at 18:31 UTC on Sept. 24 when Bitget detected unauthorized transfers from portions of its hot and warm wallet infrastructure. Its estimate later rose from $351.6 million to $387.5 million after investigators included additional Zcash and Tron-related transfers.
Protection Fund returns above $300 million
Chen said Wednesday that Bitget’s Protection Fund was again worth more than $300 million, returning it above the minimum level the exchange has committed to maintaining.
The fund had stood above $464 million when Bitget first detailed its response to the attack. Bitget later moved assets from the fund as withdrawal services began returning, while Chen had said the company intended to replenish it back to its $300 million baseline.
Before the breach, Bitget’s August Protection Fund report showed an average valuation of $382 million. It reached a monthly high of $441.5 million on Aug. 27 and a low of $345.3 million on Aug. 1. Bitget reported that roughly 5,500 BTC supported the fund during August.
The Protection Fund is separate from the assets included in Bitget’s proof of reserves. The fund is an exchange-maintained financial backstop, while proof of reserves compares covered customer balances with assets held against them.
Bitget has said the Protection Fund will absorb the financial loss from the security incident. Customer balances remain unchanged under the exchange’s accounting, although the $387.5 million in unauthorized transfers occurred from its wallet infrastructure.
Bitget reports a 131% reserve ratio after the hack
A fresh reserve snapshot taken at 09:00 UTC on Sept. 29 showed an overall proof-of-reserves ratio of 131%, according to Bitget’s 47th report.
Bitget reported that all 19 covered assets remained above 100%. Bitcoin had a 142% reserve ratio, ETH stood at 110%, USDT at 107%, XRP at 107% and USDC at 154%.
The snapshot was taken five days after the security breach and after BTC withdrawals had restarted. Bitget said the report gives users an updated view of covered reserves following the incident.
“Proof of Reserves matters most when users want to see the numbers for themselves,” Chen said in the company release. She added that users can independently verify whether their assets were included through Bitget’s Merkle Tree-based system.
Proof of reserves remains a point-in-time measure of covered exchange assets and user balances. It is distinct from a full corporate financial audit, a distinction examined in crypto.news coverage of proof-of-reserves reporting across major exchanges.
THORChain dispute continues as stolen funds move
Asset recovery has continued separately from Bitget’s operational reopening. The exchange published attacker addresses and asked exchanges, stablecoin issuers, blockchain projects and security researchers to help freeze or recover funds.
Chen specifically asked THORChain to refuse service to the listed attacker addresses after stolen assets began moving through the cross-chain protocol. She argued that “decentralization is a design principle, not a shield for facilitating known stolen funds.”
THORChain rejected the request for selective blocking. The protocol said an emergency halt exists to protect the network itself and is not designed to freeze one address or individual transaction.
The disagreement was detailed in crypto.news coverage of the Bitget hack and THORChain’s permissionless design. THORChain compared its role with permissionless blockchain networks, while Bitget and security researchers questioned whether its validator-controlled vault structure creates different options for intervention.
On-chain transactions continued after the dispute emerged. CoinDesk identified 27 successful swaps that converted roughly 2,390 ETH linked to the attacker into 75.2 BTC, worth approximately $6.3 million at the time.
A separate crypto.news report on funds converted through THORChain tracked continued movement into Bitcoin after Bitget sought help stopping the listed addresses.
THORChain previously halted after its own $10.7M exploit
The disagreement has drawn attention to THORChain’s response to a separate May attack on its own infrastructure.
THORChain reported that a newly joined node operator exploited a vulnerability in its GG20 Threshold Signature Scheme on May 15 and drained approximately $10.7 million from one vault. Automatic solvency controls began halting signing and trading on affected chains within minutes.
Its Q2 report later said node operators brought the network to a full stop after the automated response. THORChain remained offline for roughly five weeks before restarting on June 22 with patched signing code and a staged recovery process.
THORChain has argued that the May halt does not establish an address-blacklisting function. Its position is that emergency controls pause protocol activity when network security is threatened, while selectively denying a specific wallet would require a different form of intervention.
GoPlus Security disputed THORChain’s comparison with Bitcoin and Ethereum, pointing to its threshold-signature vaults and validator-controlled pause mechanisms. The security firm argued that THORChain’s architecture gives its node set powers that differ from validators on base-layer networks.
Recovery efforts continue after the $387.5M breach
Bitget says Mandiant and SlowMist remain involved in forensic work and asset tracing. Its investigation found that attackers exploited a vulnerability in a third-party security product to obtain access credentials and forge withdrawal commands that bypassed risk checks. The company says private keys and cold wallets were not compromised.
Recovery attempts have included cooperation with token issuers. Circle and Tether had frozen around $318,000 in USDC and USDT linked to the incident by Sept. 26, according to earlier reporting.
Some assets have taken more complicated routes. AMLBot traced roughly four BTC connected with the breach into a Wasabi CoinJoin transaction after funds moved from Tron through USDT0, Ethereum and THORChain. The movement of Bitget hack funds into Wasabi CoinJoin left much of the remaining tracked balance in separate attacker wallets at the time of the analysis.
Bitget has offered a 5% bounty for qualifying assistance that results in stolen funds being frozen and a separate 5% reward for successful recoveries. The exchange’s investigation and asset-recovery work remain active while its final group of withdrawal services is scheduled to reopen Oct. 2.