"The temporary withdrawal pause remains a security measure and is not related to the availability of user assets," Bitget said, as the exchange moved to restore services after attackers took control of hundreds of millions in crypto.
Bitget's withdrawal pause and the resumption schedule
Bitget suspended all withdrawals after its security systems flagged multiple unauthorized transfers and discovered attackers had taken assets from hot and warm wallets. The exchange has since resumed Bitcoin withdrawals and published a timetable for bringing other rails back online. According to Bitget, ETH withdrawals (Ethereum, BSC, Arbitrum, Base, Optimism) will restart on September 29 at 08:00 UTC, USDT withdrawals (Ethereum, BSC, Solana, Tron) will restart on September 30 at 08:00 UTC, and "other tokens / Fiat / P2P assets" will resume starting October 2 at 08:00 UTC.
Bitget emphasized that trading and deposits continue to operate during the outage, and reiterated that user account balances remain unaffected.
Financial scope: from an initial $351.6 million to $387.5 million
When Bitget first halted withdrawals, its security systems reported $351.6 million had been stolen from compromised hot and warm wallets. By the following day the company updated that figure: $387.5 million had been transferred to attacker-controlled addresses, according to the latest on-chain tracing and transaction classification cited by Bitget.
Bitget also stated that its Protection Fund will cover the financial impact of the platform-wide incident.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadHow Bitget describes the attack mechanics and attribution
Bitget CEO Gracy Chen said the incident involved multiple chains — including Ethereum, the XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base — and affected assets such as ETH, XRP, BNB, AVAX, USDT, USDC and other tokens. Chen said the attackers breached "a critical backend system within Bitget wallet infrastructure" and used it to spoof transaction data, which in turn triggered the exchange's authorization process to move funds out of the compromised wallets.
Chen attributed the operation to North Korean hackers, saying that attribution was based on "on‑chain analysis and IP behavior patterns."
Recovery Bounty Program and user protections
Bitget launched a Recovery Bounty Program aimed at helping to recover or freeze frozen funds, offering a bounty of 5% for successful assistance. The company stressed that the temporary withdrawal pause was a security measure and reiterated that "User account balances remain unaffected, and Bitget's Protection Fund covers the financial impact of this platform‑wide incident."
What this means for technologists, end users, and adversaries
- Technologists and security teams: attention will focus on backend wallet infrastructure and authorization flows — the vector Bitget described as exploited — and on-chain tracing and transaction classification methods used to follow stolen funds.
- End users of Bitget: balances are, per the exchange, unaffected and trading and deposits continue; withdrawals for many assets are being phased back in on the schedule Bitget published.
- Adversaries and attribution analysts: Bitget named North Korean hackers as responsible, citing technical indicators; the company placed this theft alongside a pattern of large, state‑linked incidents, noting that North Korean groups have been linked to other major crypto thefts, including the largest recorded theft — a $1.5 billion loss from Bybit's ETH cold wallet — and that Elliptic estimated in February 2025 that North Korean hackers "stolen over $6 billion in crypto assets since 2017."
Bitget presents the incident as contained and covered: it says no further unauthorized transfers are possible, user funds are protected by its balance sheet and Protection Fund, and it has a public timetable to restore withdrawals. The concrete next test will be whether on‑chain tracing and the new Recovery Bounty Program can freeze or recover the $387.5 million already shifted to attacker‑controlled addresses.



