+1.27%
+2.16%
+0.39%
-3.61%
-1.64%
+12.15%
Bitget initiated Bitcoin withdrawals on September 28 at 8 a.m. UTC, covering both the Bitcoin and BNB Smart Chain networks. The exchange says it completed security checks on each network before reactivating service. Ethereum withdrawals followed on September 29 at the same hour, resuming across Ethereum, BNB Smart Chain, Arbitrum, Base, and Optimism.
- Bitcoin withdrawals: resumed September 28
- Ethereum withdrawals: resumed September 29
- Tether withdrawals: scheduled September 30 across Ethereum, BNB Smart Chain, Solana, and Tron
- All remaining crypto, fiat, and peer-to-peer trading: targeted for October 2
How the Breach Happened
The breach surfaced on September 24, when abnormal fund transfers were detected moving out of Bitget’s hot and warm wallets across multiple networks. It stands as the largest reported cryptocurrency hack this year.
According to Bitget, attackers exploited a vulnerability in a third party security product, which gave them high level internal access. From there, they issued false withdrawal instructions that bypassed the exchange’s risk controls. Bitget confirmed $388 million in crypto assets were stolen, but maintains that private keys were never compromised and that customer account balances along with cold wallets remained untouched throughout.
Covering the Losses
Bitget has committed to covering all losses through its user protection fund, which holds 5,500 Bitcoin. The company says the vulnerability has since been fixed, with no further unauthorized transfers detected.
The exchange also launched a bounty program offering 5% of recovered funds to anyone who helps freeze or retrieve the stolen assets. Some funds have already been frozen through industry cooperation, though Bitget has not disclosed how much.
Who Investigators Suspect
Bitget is working with external security firms Mandiant, a Google Cloud company, and blockchain security firm SlowMist. An official security report is expected this week.
The exchange has floated the possibility that a sophisticated state backed hacking group, potentially linked to North Korea, was involved. The attacker’s identity remains unconfirmed. Pressure on crypto platforms to harden security has been building all year, a trend TechCrunch has tracked across similar incidents industry wide.
Hashlytics Take
“Third party security product vulnerability” is doing a lot of quiet work in this explanation. It’s specific enough to sound technical and vague enough to avoid naming a vendor, a product, or exactly how internal access controls failed to catch false withdrawal instructions moving $388 million. Covering losses and launching a bounty program are the right moves for user trust, but they don’t answer the actual question the promised security report needs to: was this a flaw Bitget could have caught, or a genuinely novel attack. Until that report lands, “vulnerability fixed” is a claim worth treating as provisional.
Follow Hashlytics on Bluesky, Facebook, LinkedIn , Telegram and X to Get Instant Updates


