Crypto exchange Bitget will begin restoring withdrawal services today (28 September) following a security incident that resulted in the transfer of approximately $387.5m in digital assets to attacker-controlled addresses.

The Seychelles-based exchange suspended withdrawals after detecting unauthorised transfers on 24 September.

Access deeper industry intelligence

Experience unmatched clarity with a single platform that combines unique data, AI, and human expertise.

Find out more

Bitget said it will restore services through a phased rollout, starting with Bitcoin (BTC) network withdrawals at 08:00 UTC on 28 September.

Ethereum (ETH) withdrawals are scheduled to resume on 29 September, followed by Tether (USDT) withdrawals on 30 September.

Bitget expects all remaining assets, including fiat services and peer-to-peer (P2P) trading, to return to normal by 2 October.

In a statement, the company said: “The phased rollout allows Bitget to resume withdrawal services in an orderly manner following the incident. The same approach applies consistently across users without preference.

“Our objective is to resume withdrawals across all supported assets and networks as quickly and safely as possible.”

Bitget CEO Gracy Chen previously said in a post on X that the exchange’s security systems had identified unauthorised transfers from “some of our hot wallets”.

“Our security team activated emergency response protocols immediately,” she added.

Initial estimates put the value of assets taken in the hack at approximately $351.6m. Bitget later revised the figure to $387.5m, citing the “latest onchain tracing and classification of transactions”.

The affected assets were held across Ethereum and several Ethereum Virtual Machine (EVM) networks, as well as XRP Ledger, Zcash, and TRON. Bitget identified XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX, and TRX among the affected assets.

The exchange said its investigation with cybersecurity firms Mandiant and SlowMist remains under way. It added that the incident had been contained and that no “further unauthorised transfers are possible”.

Bitget further claimed that customer funds remain unaffected. Trading and deposit services continued to operate during the withdrawal suspension.

CNBC reported that Bitget suspects North Korean hackers may be responsible for the breach. The exchange said that its User Protection Fund, which holds more than $464m, will cover the stolen assets.