Skip to content
Security & HacksLatest

Bitget Resumes Withdrawals in Phases After $388 Million Security Breach; User Losses to Be Fully Compensated

MissedBlock Desk · Sep 28, 2026 · 3 min read

Updated Sep 28, 2026

Bitget Resumes Withdrawals in Phases After $388 Million Security Breach; User Losses to Be Fully Compensated

Bitget is gradually restoring its withdrawal functions following a significant security incident on September 24th, during which approximately $388 million in assets were stolen. The cryptocurrency exchange anticipates the full resumption of all services, including fiat withdrawals and P2P trading, by October 2nd. Bitget has stated that its User Protection Fund will cover all user losses resulting from the breach.

Phased withdrawal resumption began on September 26th, with Bitcoin (BTC) withdrawals being the first to be reinstated at 8 AM UTC. According to Bitget, the vulnerability that coincided with the security incident has been fixed, and unauthorized transfers have ceased. The platform’s private keys were not compromised, and user balances and cold wallets remained unaffected.

The security breach involved unauthorized transfers from Bitget’s hot and warm wallet infrastructure, reportedly exploiting a vulnerability in a third-party security product to gain access to high-level internal credentials. This incident, involving the theft of assets including ETH, USDT, USDC, AVAX, and BNB, marks the largest crypto theft case of 2023 to date.

Bitget has outlined a schedule for the resumption of other major cryptocurrency withdrawals. Ethereum (ETH) withdrawals are slated to resume on September 29th at 8 AM UTC, covering the Ethereum, BSC, Arbitrum, Base, and Optimism networks. Following this, USDT withdrawals are scheduled to restart on September 30th at 8 AM UTC, supporting the Ethereum, BSC, Solana, and Tron networks.

To aid in the recovery of the stolen funds, Bitget has launched a bounty program, offering 5% of any frozen or recovered assets, potentially amounting to approximately $19.4 million if the full $388 million is recovered. Mandiant and SlowMist are reportedly assisting Bitget in the ongoing investigation.

Bitget’s User Protection Fund, which reportedly holds 5,500 BTC, is designated to fully compensate users for any losses incurred due to the security incident. The exchange is also re-evaluating its processes for assessing and deploying third-party security products, highlighting the supply chain risks inherent in cybersecurity.

Several uncertainties remain regarding the incident, including the exact identity of the attackers and the specific third-party security product exploited. The success and timeline of the bounty program in recovering funds are also yet to be determined. Despite these unknowns, Bitget stated its commitment to full restoration and compensation, aiming to restore user confidence following the significant breach.

Why This Matters

The materials describe a narrow update: Bitget is gradually restoring its withdrawal functions following a security incident on September 24th where $388 million in assets were stolen. The exact identity of the attackers.

Broader Context

Source materials place the factual news in this context: This incident is the largest crypto theft case of 2023 to date, surpassing previous major hacks.

Bitget Resumes Withdrawals in Phases After $388 Million Security Breach; User Losses to Be Fully Compensated · MissedBlock