Bitget to resume withdrawals after $387.5m crypto hack

The exchange said its investigation with cybersecurity firms Mandiant and SlowMist remains under way.

Aninda Chakraborty September 28 2026

Crypto exchange Bitget will begin restoring withdrawal services today (28 September) following a security incident that resulted in the transfer of approximately $387.5m in digital assets to attacker-controlled addresses.

The Seychelles-based exchange suspended withdrawals after detecting unauthorised transfers on 24 September.

Bitget said it will restore services through a phased rollout, starting with Bitcoin (BTC) network withdrawals at 08:00 UTC on 28 September.

Ethereum (ETH) withdrawals are scheduled to resume on 29 September, followed by Tether (USDT) withdrawals on 30 September.

Bitget expects all remaining assets, including fiat services and peer-to-peer (P2P) trading, to return to normal by 2 October.

In a statement, the company said: “The phased rollout allows Bitget to resume withdrawal services in an orderly manner following the incident. The same approach applies consistently across users without preference.

“Our objective is to resume withdrawals across all supported assets and networks as quickly and safely as possible.”

Bitget CEO Gracy Chen previously said in a post on X that the exchange’s security systems had identified unauthorised transfers from “some of our hot wallets”.

“Our security team activated emergency response protocols immediately,” she added.

Initial estimates put the value of assets taken in the hack at approximately $351.6m. Bitget later revised the figure to $387.5m, citing the “latest onchain tracing and classification of transactions”.

The affected assets were held across Ethereum and several Ethereum Virtual Machine (EVM) networks, as well as XRP Ledger, Zcash, and TRON. Bitget identified XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX, and TRX among the affected assets.

The exchange said its investigation with cybersecurity firms Mandiant and SlowMist remains under way. It added that the incident had been contained and that no “further unauthorised transfers are possible”.

Bitget further claimed that customer funds remain unaffected. Trading and deposit services continued to operate during the withdrawal suspension.

CNBC reported that Bitget suspects North Korean hackers may be responsible for the breach. The exchange said that its User Protection Fund, which holds more than $464m, will cover the stolen assets.

Uncover your next opportunity with expert reports

Steer your business strategy with key data and insights from our latest market research reports and company profiles. Not ready to buy? Start small by downloading a sample report first.

Newsletters by sectors

close

Sign up to the newsletter: In Brief

Visit our Privacy Policy for more information about our services, how we may use, process and share your personal data, including information of your rights in respect of your personal data and how you can unsubscribe from future marketing communications. Our services are intended for corporate subscribers and you warrant that the email address submitted is your corporate email address.

Thank you for subscribing

View all newsletters from across the GlobalData Media network.

close