Crypto exchange Bitget has officially initiated a phased resumption of user withdrawals following a $388 million security exploit on September 24, 2026. The breach represents the first major security compromise affecting Bitget’s core exchange infrastructure in its eight-year operating history.
Bitget CEO Gracy Chen addressed the recovery efforts and next steps during a live AMA, confirming that the exploit was contained without affecting user account balances or compromising the exchange’s cold storage reserves.
Withdrawal Restoration Schedule
Withdrawals are reopening systematically across different tokens and networks to manage traffic and ensure system stability.
| Date / Time (UTC) | Supported Assets & Services | Network / Notes |
| Sept 28, 08:00 UTC | Bitcoin (BTC) | Resumed on Bitcoin and BSC networks |
| Sept 29 | Ethereum (ETH) | Scheduled resumption |
| Sept 30 | Tether (USDT) | Scheduled resumption |
| Oct 2 | Fiat, P2P, and all other tokens | Full operational restoration |
Within the first hour of resuming operations on September 28, Bitget processed 9,585 Bitcoin withdrawals totaling approximately 4,098 BTC.
Context Behind the September 24 Exploit
The security breach occurred on September 24, 2026, resulting in the unauthorized transfer of approximately $388 million in crypto assets.
According to Bitget’s preliminary findings, the attack vector did not originate from direct vault breaches or cryptographic failure:
- Attack Method: The attacker exploited a vulnerability in a third-party security software vendor to harvest high-level internal access credentials.
- Execution: These stolen credentials were used to push unauthorized, fraudulent withdrawal commands through the system, bypassing automated risk filters.
- Systems Affected: Private keys were not compromised, and cold wallets remained untouched throughout the incident.
Bitget stated that the underlying vulnerability has been completely patched, containment measures verified, and no additional unauthorized transfers have occurred since the initial breach.
Financial Backing and Incident Recovery
To reassure users regarding solvency and asset coverage, Bitget highlighted its existing risk management structure:
- User Protection Fund: Currently stands at over $464 million, serving as an additional layer of financial protection.
- Proof of Reserves: The exchange maintains a comprehensive reserve ratio of 127%.
Forensic investigation firms Mandiant and SlowMist are conducting independent audits to validate containment, trace stolen funds, and map out the attacker’s methodology. Bitget has published the attacker’s wallet addresses publicly and is coordinating with law enforcement, competing exchanges, and on-chain security specialists. A portion of the stolen funds has already been frozen via cross-industry collaboration. (Read More: Bitget Suspends Withdrawals Following $351.6 Million Hot Wallet Security Breach)
An official, comprehensive security report is expected to be published later this week.
Support and User Retention Initiatives
Alongside technical remediation, Bitget has launched targeted programs to retain liquidity and reward user loyalty:
- Bitget Alliance Program: Running from September 28 to October 30, 2026, offering rewards and terms for eligible retail users.
- Project Stand Together: Tailored for institutional accounts, market makers, and PRO clients, offering temporary fee discounts and extended PRO status protections.
This article is published on BitPinas: Bitget Begins Phased Withdrawal Resumption After $388 Million Security Incident
What else is happening in Crypto Philippines and beyond?



Be the first to comment