Bitget has restored withdrawals for Bitcoin, Ethereum and USDT as the crypto exchange continues recovering from a major security breach that resulted in approximately $387.5 million in unauthorized transfers.
The exchange is reopening services in stages, with peer-to-peer withdrawals, fiat withdrawals and support for remaining tokens scheduled to return on Oct. 2 at 08:00 UTC.
Bitget CEO Gracy Chen said on Sept. 30 that BTC, ETH and USDT withdrawals were already operating again and that the company was gradually returning to normal operations.
She also said Bitget’s Protection Fund had climbed back above $300 million following the incident.
Bitget withdrawals are returning in stages
Bitget began restoring withdrawals several days after the Sept. 24 security incident.
Bitcoin withdrawals were the first to return, reopening at 08:00 UTC on Sept. 28.
Ethereum withdrawals followed on Sept. 29 across multiple networks, including Ethereum, BNB Smart Chain, Arbitrum, Base and Optimism.
USDT withdrawals were restored on Sept. 30 across Ethereum, BNB Smart Chain, Solana and Tron.
The final stage of Bitget’s recovery plan is scheduled for Oct. 2, when the exchange expects to reopen P2P services, fiat withdrawals and withdrawals for remaining supported tokens.
Bitget said deposits and trading remained available while withdrawals were temporarily suspended.
The exchange has also maintained that customer account balances were not affected by the incident.
The hack resulted in $387.5 million in unauthorized transfers
Bitget first detected suspicious activity at 18:31 UTC on Sept. 24.
According to the exchange, attackers gained access to parts of its hot and warm wallet infrastructure and initiated unauthorized transfers.
The initial estimated loss was approximately $351.6 million.
Bitget later increased that figure to roughly $387.5 million after investigators identified additional transactions involving Zcash and Tron-related assets.
The exchange says its private keys and cold wallet infrastructure were not compromised.
According to Bitget’s investigation, attackers exploited a vulnerability in a third-party security product, obtained access credentials and used them to create withdrawal commands that bypassed some internal risk controls.
Bitget Protection Fund returns above $300 million
Chen said the exchange’s Protection Fund had recovered to more than $300 million by Sept. 30.
Bitget has previously committed to maintaining the fund at a minimum value of approximately $300 million.
The fund stood above $464 million when Bitget initially detailed its response to the attack.
Some assets were later moved from the fund as withdrawal services began reopening.
Before the breach, Bitget’s August Protection Fund report showed an average valuation of approximately $382 million.
The fund reached a monthly high of about $441.5 million on Aug. 27 and a low of roughly $345.3 million on Aug. 1.
Bitget said approximately 5,500 BTC backed the Protection Fund during August.
Protection Fund and proof of reserves serve different purposes
Bitget’s Protection Fund should not be confused with its proof-of-reserves system.
The Protection Fund is designed to act as a financial backstop in situations such as security incidents.
Proof of reserves, meanwhile, compares covered customer liabilities with assets the exchange reports holding against them.
Bitget has said the Protection Fund will absorb the financial losses associated with the recent breach.
Although approximately $387.5 million was transferred without authorization from Bitget-controlled wallet infrastructure, the exchange says customer balances remain unchanged in its accounting records.
Bitget reports a 131% reserve ratio after the hack
Bitget also released a new proof-of-reserves snapshot after the incident.
The snapshot, taken at 09:00 UTC on Sept. 29, showed an overall reserve ratio of approximately 131%.
According to Bitget’s 47th proof-of-reserves report, all 19 covered crypto assets remained above a 100% reserve ratio.
Bitcoin reportedly had a 142% reserve ratio.
Ethereum stood at approximately 110%.
USDT and XRP both had reserve ratios of around 107%, while USDC was reported at approximately 154%.
The snapshot was taken five days after the attack and after Bitcoin withdrawals had already resumed.
Proof of reserves is not the same as a full audit
Bitget says users can independently verify whether their balances are included in its proof-of-reserves system through a Merkle Tree-based verification process.
The company argues that this gives customers greater visibility into the assets backing covered liabilities.
However, proof of reserves remains a point-in-time snapshot.
It is not the same as a complete corporate financial audit.
A full audit would generally provide a broader view of liabilities, assets, obligations and other financial risks across the entire business.
This distinction remains important when evaluating the financial health of a centralized crypto exchange.
Bitget continues trying to recover stolen assets
Bitget’s operational recovery is separate from efforts to trace and recover the stolen funds.
The exchange published wallet addresses linked to the attackers and asked crypto exchanges, blockchain projects, stablecoin issuers and security researchers to assist with freezing or recovering assets.
One of the most visible disputes involved THORChain.
Chen asked the cross-chain protocol to prevent attacker-linked addresses from using its services.
She argued that decentralized infrastructure should not become a tool for laundering assets that are known to have been stolen.
THORChain rejected the request.
THORChain refuses to block attacker addresses
THORChain said its network is designed to operate in a permissionless manner and does not have a mechanism intended to selectively block one wallet or individual transaction.
The protocol said its emergency controls are designed to protect the network itself rather than enforce address-level blacklists.
This position created a broader debate over the responsibilities of decentralized protocols when stolen assets move through their infrastructure.
Bitget and some security researchers argued that THORChain’s validator-controlled vault architecture may provide more opportunities for intervention than the protocol acknowledges.
THORChain, however, maintained that selective censorship would represent a different type of network control.
Stolen funds continued moving through THORChain
Blockchain tracking showed that attacker-linked assets continued moving after Bitget requested assistance.
CoinDesk identified 27 successful swaps that converted roughly 2,390 ETH linked to the attacker into approximately 75.2 BTC.
The Bitcoin was worth about $6.3 million at the time.
These transactions demonstrated the difficulty exchanges face when stolen assets are moved through cross-chain protocols and converted into different cryptocurrencies.
Once assets pass through several networks, exchanges and privacy tools, tracing and recovering them can become increasingly difficult.
THORChain previously halted after its own exploit
The Bitget dispute has also drawn attention to THORChain’s response to a separate exploit affecting its own infrastructure earlier in 2026.
THORChain reported that a newly joined node operator exploited a vulnerability in its GG20 Threshold Signature Scheme on May 15.
The attacker drained approximately $10.7 million from one of the protocol’s vaults.
Automatic solvency controls began restricting signing and trading on affected chains shortly after the incident.
Node operators later brought the network to a complete stop.
THORChain remained offline for roughly five weeks before restarting on June 22 with patched signing code and a staged recovery process.
THORChain says network halts and wallet blacklisting are different
THORChain has argued that its response to the May exploit does not prove that it can selectively block individual addresses.
The protocol says emergency controls are intended to pause the network when the protocol itself is threatened.
Blocking a specific wallet because its assets are believed to be stolen would require a different type of intervention.
Security firm GoPlus challenged that argument.
The firm pointed to THORChain’s threshold-signature vault architecture and validator-controlled pause mechanisms, arguing that the protocol’s validators have different powers from validators on networks such as Bitcoin and Ethereum.
The debate remains unresolved.
Security firms continue investigating the Bitget hack
Bitget says Mandiant and SlowMist remain involved in forensic analysis and asset tracing.
The exchange says its investigation indicates that attackers exploited a third-party security product rather than compromising Bitget’s cold wallets or private keys directly.
Recovery efforts have also involved cooperation with stablecoin issuers.
Circle and Tether had frozen approximately $318,000 worth of USDC and USDT linked to the incident by Sept. 26.
However, this represents only a small fraction of the estimated $387.5 million loss.
Some stolen funds reached privacy tools
Security researchers have also tracked some attacker-linked assets into privacy-focused services.
AMLBot identified approximately four BTC connected with the breach that eventually entered a Wasabi CoinJoin transaction.
Before reaching Wasabi, the funds reportedly moved from Tron through USDT0, Ethereum and THORChain.
CoinJoin transactions combine Bitcoin from multiple users in an effort to make transaction histories more difficult to follow.
The use of such tools can significantly complicate recovery efforts.
Other attacker-linked assets remained in separate wallets at the time of the analysis.
Bitget offers rewards for asset recovery
Bitget has introduced incentives for individuals and organizations that help recover stolen funds.
The exchange is offering a 5% bounty for qualifying assistance that results in assets being successfully frozen.
It has also offered a separate 5% reward for successful asset recoveries.
The investigation remains active as security firms, blockchain projects and centralized exchanges continue attempting to track the stolen assets.
What happens next for Bitget?
The most immediate milestone is the scheduled reopening of Bitget’s remaining withdrawal services on Oct. 2 at 08:00 UTC.
If the rollout proceeds as planned, P2P, fiat and remaining token withdrawals will return alongside the BTC, ETH and USDT services that have already been restored.
The exchange will also face continued scrutiny over its proof of reserves, Protection Fund and recovery efforts following one of the largest crypto security incidents of 2026.
Bitget’s ability to restore withdrawals shows that its operational recovery is progressing.
However, the investigation into the $387.5 million in unauthorized transfers remains far from complete.
The next phase will depend on how much of the stolen crypto can be traced, frozen or recovered and whether Bitget introduces additional security measures following the breach.








































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































