()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.
()
$0.

Bitget to resume withdrawals in stages starting Sep. 28 after security incident

Lawrence Mondal
Edited by
News
Bitget to resume withdrawals in stages starting Sep. 28 after security incident - 1

Bitget has set a Sep. 28 restart for Bitcoin withdrawals after a Sep. 24 security incident, with Ether, USDT, and other withdrawal services scheduled to follow through Oct. 2.

Summary
  • Bitcoin withdrawals are scheduled to reopen at 08:00 UTC on Sep. 28.
  • ETH and USDT withdrawals are set to return on selected networks over the following two days.
  • Bitget says it has fixed the vulnerabilities and is carrying out further security checks.
  • A later account of the incident put transfers to attacker-controlled addresses at about $387.5 million.

Bitget said in an update that its technical team had identified and fixed the vulnerabilities tied to the incident. The exchange is checking its withdrawal systems before reopening them and said Mandiant, a cybersecurity firm owned by Google, and blockchain security company SlowMist are helping investigate the attack.

The dates are part of a planned reopening schedule. Bitget told users to rely on notices from the platform and its official channels for confirmation that each service is available. Customers do not need to take any action before withdrawals resume, it said.

Bitget withdrawals are scheduled to return in four stages

Under the schedule, BTC withdrawals on the Bitcoin network are due to resume at 08:00 UTC on Sep. 28. ETH withdrawals are set for the same time on Sep. 29 across Ethereum, BNB Smart Chain, Arbitrum, Base and Optimism.

USDT withdrawals are scheduled for 08:00 UTC on Sep. 30 across Ethereum, BNB Smart Chain, Solana and Tron. Bitget placed withdrawals for other tokens, fiat currency services and peer-to-peer transactions in the final stage, scheduled for 08:00 UTC on Oct. 2.

The network lists matter for customers holding ETH or USDT: a token’s scheduled return does not mean withdrawals on every network will reopen at once. Bitget named five networks for the first ETH stage and four for USDT. It did not give a network-by-network list for the remaining tokens in the schedule shared with users.

Trading and deposits have continued during the withdrawal pause, according to the exchange. Bitget described the suspension as a temporary security measure and said customer account balances had not changed. Its statement that user assets are unaffected refers to customer balances; the exchange has separately reported unauthorized transfers from its own wallet infrastructure.

The reported loss has risen from Bitget’s first estimate

Bitget detected unauthorized transfers from some of its wallets on Sep. 24 and halted withdrawals while it investigated. As crypto.news reported Friday, the exchange initially estimated that about $351.6 million in assets were affected. It said its cold wallets were secure and that its early investigation had found no evidence of a private-key leak.

In a subsequent account cited by Outlook Money on Sep. 26, Bitget put the value transferred to attacker-controlled addresses at approximately $387.5 million. The later figure included Zcash and TRON assets that were absent from the first estimate. Bitget said its tracing work was continuing, so the figure may change as investigators classify additional transactions.

The earlier investigation pointed to a possible breach of a backend wallet service, according to Bitget’s statements covered by crypto.news. The exchange had not established a final entry point in that account. Its latest statement says the vulnerabilities have been fixed, while Mandiant and SlowMist continue to assist with the investigation.

Bitget has said its protection fund will cover the financial impact of the incident. During the withdrawal pause, the exchange reported that the fund held more than $464 million and said customer balances remained accurate. The fund statement is Bitget’s account of how it intends to absorb the loss; it does not mean the unauthorized transfers did not occur.

Chief Executive Gracy Chen also raised a possible North Korean connection during an earlier public discussion, citing similarities involving IP addresses and VPN services. She did not confirm who carried out the attack. No public attribution by a government agency was identified in the earlier crypto.news investigation report.

Stolen USDC transfers drew attention in the U.S.

While withdrawals were suspended, security researcher Taylor Monahan identified USDC movements she linked to the attacker, including transfers and conversions into ETH. Her findings, reported by crypto.news on Sep. 25, raised questions about whether Circle could block the movement of stolen USDC. The public account did not establish whether Circle had received a legal order concerning the addresses.

The question has a direct U.S. connection because Circle is the U.S.-based issuer of USDC. Circle has said it freezes tokens when legally compelled. In a separate U.S. federal lawsuit filed after the Drift Protocol exploit, a claimant alleged that Circle failed to stop stolen USDC moving through its cross-chain transfer system. The allegation is part of that lawsuit, not a court finding against Circle or a determination about Circle’s response to the Bitget incident.

For Bitget customers, the next operational step remains the Bitcoin withdrawal window scheduled for Sep. 28 at 08:00 UTC. The exchange said it would confirm each reopening through its official notices as the security checks are completed.