After $387.5M Breach, Bitget Maps Four-Phase Withdrawal Return
Bitget withdrawals resume in phases from September 28 after a $387.5 million wallet breach, with final services planned for October 2.
Bitget will begin restoring customer withdrawals on September 28 at 08:00 UTC, starting with Bitcoin, four days after an attacker moved roughly $387.5 million from parts of the exchange’s wallet infrastructure. The Seychelles-based exchange has laid out a staged return of Ether, Tether and remaining services through October 2, giving traders a fixed timetable after a breach the company says it has since patched.
Bitget published the schedule on its support center at 03:55 UTC on September 26, meeting a self-imposed deadline of 04:00 UTC with five minutes to spare. The exchange says its security and technical teams are still running validation checks across withdrawal infrastructure, and that the pause has been a security step rather than a sign of missing user funds.

Bitget Withdrawal Resumption Schedule
Each phase is set to open at 08:00 UTC. Bitcoin withdrawals on the Bitcoin network are scheduled for September 28, followed by Ether withdrawals on September 29 across Ethereum, BNB Smart Chain, Arbitrum, Base and Optimism. Tether withdrawals follow on September 30 across Ethereum, BNB Smart Chain, Solana and TRON, with all remaining tokens, fiat services and peer-to-peer transactions grouped into a final October 2 batch for which Bitget has not specified networks.
Assets caught up in the attack but absent from the first three phases, including XRP, Zcash, TRON and Avalanche, fall under that October 2 window. Bitget says the rollout applies to all users on identical terms, that customers do not need to take any action, and that withdrawal availability will simply appear on the platform once each phase goes live. Trading and deposits have continued without interruption throughout the pause.
The exchange maintains that the flaw behind the breach has been fixed and that customer account balances remain unaffected, while Mandiant, the Google-owned cybersecurity firm, and blockchain security company SlowMist continue supporting the investigation. Whether each phase actually opens on schedule is not yet confirmed, and the dates represent Bitget’s stated plan rather than completed reopenings. The situation echoes other recent exchange disruptions, including an exchange halting withdrawals after a custody and security shortfall and a staged withdrawal deadline set for affected customers elsewhere in the industry, both of which offer comparison points for how exchanges structure recovery timelines.
Fund Coverage and Recovery Efforts
Bitget’s security systems first flagged unauthorized transfers from some of its hot wallets at 18:31 UTC on September 24, with the exchange saying the breach was confined to portions of its hot and warm wallet layers while cold wallets stayed secure. The initial estimate put affected funds at about $351.6 million; on September 25, Bitget revised that figure upward to roughly $387.5 million after further on-chain tracing turned up Zcash and TRON transfers left out of the first count. The exchange says the revision reflected reclassification, not new unauthorized movement.
Bitget says the loss falls within its User Protection Fund, which held more than $464 million at the time of the incident, and that the fund covers the financial impact. At $387.5 million, the confirmed figure equates to roughly 84% of that reported balance, a ratio drawn directly from Bitget’s own numbers rather than an independent audit.
To support recovery, Bitget has published a live fund-tracing dashboard, a portal for submitting recovery information and a real-time API tracking attacker-controlled addresses. Its RecoveryBounty Program offers 5% of any funds successfully frozen and 5% of funds successfully recovered to whoever’s voluntary efforts produce that result, though actions taken under court order or law-enforcement request are excluded and Bitget retains final say over eligibility. The exchange also plans to use LazarusBounty, a recovery initiative run by rival exchange Bybit, which lost about $1.5 billion in a February 2025 theft the FBI attributed to North Korea.
What Comes Next
CEO Gracy Chen is scheduled to host a live AMA at 07:30 UTC on September 28, thirty minutes ahead of the planned Bitcoin reopening, to address the incident and the restoration process directly. Chen has separately said patterns in the attack were consistent with groups previously linked to North Korea, describing a breach of a backend system with spoofed transaction data rather than stolen private keys – but attribution has not been confirmed and the investigation remains open.
Bitget has not yet published a full incident report with root-cause analysis, and forensic work with Mandiant and SlowMist continues. The identity of the attacker, the total value frozen through industry coordination, and whether each of the four withdrawal phases opens exactly on schedule all remain unconfirmed. Bitget has asked users to rely only on its official channels for updates as the September 28 AMA approaches as the next scheduled public briefing.
Follow The Crypto Times on X and Telegram for continuing coverage of the Bitget recovery and other exchange-security developments.