- Withdrawals will return in stages rather than simultaneously across Bitget’s infrastructure.
- The exchange has raised the value transferred to attacker-controlled addresses to $387.5 million.
- Customer balances remain unaffected, according to Bitget, with its Protection Fund absorbing the financial impact.
Bitget will begin restoring withdrawals on September 28, but the exchange is deliberately avoiding an all-at-once reopening after its September 24 security breach.
Bitget will begin resuming withdrawals in orderly phases following the security incident identified on September 24.
The vulnerability involved in the incident has been identified and remediated.
Bitget’s security and technical teams have since been conducting additional… https://t.co/VZu59GnLAN
— Bitget (@bitget) September 26, 2026
Bitcoin comes first. Ethereum follows a day later, then USDT, while other tokens, fiat withdrawals and P2P services are scheduled for October 2.
The staggered approach gives Bitget several days to test withdrawal infrastructure before restoring its full range of services. The exchange says it has identified the attack path and fixed the underlying vulnerability, while Mandiant and SlowMist continue assisting with the investigation.
Bitcoin Gets the First Green Light
BTC withdrawals are scheduled to resume at 08:00 UTC on September 28.
ETH follows at the same time on September 29 and USDT on September 30. Bitget expects to restore withdrawals for other tokens, along with fiat withdrawals and P2P services, on October 2.
Trading and deposits have remained operational since the breach.
For users, the important part is the sequencing. Bitget is putting its withdrawal system back into production gradually rather than treating remediation as sufficient evidence that every service is ready.
That also makes Bitcoin the first real operational test of the repaired infrastructure.
Loss Estimate Rises to $387.5 Million
Bitget’s investigation has also expanded the accounting of the breach.
The exchange initially reported approximately $351.6 million in unauthorized transfers. It now puts the value transferred to attacker-controlled addresses at about $387.5 million.
According to Bitget, the additional $35.9 million reflects Zcash and TRON assets omitted from the initial estimate, rather than new unauthorized transfers after the incident was contained.
The identified assets now include XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX and TRX.
Bitget says no further unauthorized transfers are possible following remediation. That remains an exchange claim while the wider investigation continues.
The Protection Fund Buys Bitget Time
The financial response is separate from recovery of the stolen assets.
Bitget says customer account balances remain unaffected and its Protection Fund, valued at more than $464 million when the incident was disclosed, will cover the impact.
That puts the fund roughly $76.5 million above the exchange’s revised incident estimate.
Meanwhile, efforts to trace and recover the stolen assets continue. Bitget has announced a bounty equal to 5% of eligible funds successfully frozen or recovered through qualifying assistance.
Mandiant and SlowMist are also assisting with the investigation, although Bitget’s public update does not amount to an independent certification from either company that the repaired infrastructure is secure.
September 28 Puts the Fix Into Production
Bitget has already completed the first part of its response: identifying the vulnerability, containing the incident and deploying a fix, according to the exchange.
Now comes the part users can actually observe.
Starting September 28, withdrawal requests will begin moving through the repaired infrastructure. BTC will test it first, followed by ETH and USDT before Bitget attempts a broader reopening.
For an exchange recovering from a $387.5 million breach, successful withdrawals will provide a more tangible measure of operational recovery than the remediation announcement itself.






Be the first to comment