Bitget’s $387.5M Breach: What Happened to Withdrawals?
Bitget is preparing to restore withdrawals after one of the largest confirmed crypto-exchange security incidents of 2026.
The exchange detected unauthorized transfers at 18:31 UTC on September 24. Its first assessment put the affected assets at approximately $351.6 million.
The figure subsequently increased.
After additional onchain tracing, Bitget said approximately $387.5 million had been transferred to attacker-controlled addresses. The increase did not represent another breach: the revised calculation added assets on Zcash and TRON that were missing from the initial estimate.
The more important development concerns how the attack reportedly worked.
Bitget says its private keys were not compromised. According to CEO Gracy Chen, attackers instead compromised a critical backend component of the exchange's wallet infrastructure, spoofed transaction data and caused the authorization system to approve transfers.
That distinction exposes a security problem that is easy to overlook: protecting cryptographic keys is essential, but an exchange also has to protect the software deciding what those keys are allowed to sign.
What happened?
Bitget initially reported unauthorized transfers involving portions of its hot and warm wallet infrastructure.
Hot wallets are connected to operational systems so exchanges can process withdrawals efficiently. That makes them more accessible than cold storage, where signing credentials and assets can be kept away from continuously connected infrastructure.
Bitget says its cold wallets remained secure.
By September 25, the exchange said its investigation had identified the attack path and the vulnerability used to bypass existing controls. The vulnerability had been remediated and the incident contained.
Independent reporting from The Block described the same core mechanism: a critical backend wallet system was compromised, allowing the attacker to spoof transaction data and invoke Bitget's authorization process.
That means the reported attack was not simply a case of someone stealing a private key and signing transactions directly.
Why did $351.6M become $387.5M?
Changing estimates during a security incident can look like continuing losses.
Bitget says that is not what happened here.
The original estimate was approximately $351.6 million. Subsequent tracing added affected assets on the Zcash and TRON networks, raising the total transferred to attacker-controlled addresses to approximately $387.5 million.
The company says there were no additional unauthorized transfers behind the increase.
The affected assets span multiple networks and include ETH, XRP, USDT, USDC, ZEC, USDT0, XAUt, BNB, AVAX and TRX.
There is another useful distinction: assets transferred to attacker-controlled addresses are not automatically identical to final net losses.
Investigations, freezes, recovery efforts and cooperation with other platforms can affect how much is ultimately recoverable.
At this stage, $387.5 million is the confirmed value Bitget says was transferred to attacker-controlled addresses.
How can private keys be safe if funds were stolen?
A private key is only one layer of an exchange wallet system.
Large centralized exchanges do not normally have an employee manually inspect and sign every customer withdrawal.
Backend systems construct transactions, apply risk rules, verify withdrawal requests and ultimately trigger signing infrastructure.
If an attacker can manipulate trusted information before it reaches that final authorization layer, the signing system can potentially approve a malicious transaction while the underlying key itself remains secret.
According to Bitget's account, that is the important distinction in this incident.
It is also why “our private keys were not stolen” should not be interpreted as “the wallet infrastructure was not compromised.”
It was.
The reported weakness existed elsewhere in the transaction-authorization chain.
Are customer funds safe?
Bitget says customer account balances remain unaffected and that its User Protection Fund covers the financial impact of the incident.
At the initial disclosure, the exchange said the fund held more than $464 million.
That is relevant, but it needs careful interpretation.
A protection fund is a financial buffer. It does not prove that an exchange's technical infrastructure is secure, nor does its stated value by itself demonstrate that every asset could be liquidated instantly without market impact.
What matters operationally is whether users can actually access their assets.
That makes withdrawal restoration a particularly important test.
When will Bitget withdrawals reopen?
Bitget has now published a phased schedule.
According to the exchange:
- September 28, 08:00 UTC: BTC withdrawals on Bitcoin;
- September 29, 08:00 UTC: ETH withdrawals across Ethereum, BSC, Arbitrum, Base and Optimism;
- September 30, 08:00 UTC: USDT withdrawals across Ethereum, BSC, Solana and Tron;
- October 2, 08:00 UTC: other tokens, fiat and P2P withdrawals.
Bitget says deposits and trading have remained operational during the withdrawal suspension.
The staged restart matters because an exchange account balance and an externally transferable asset are not the same operational condition.
Until a user can withdraw, custody remains dependent on the exchange.
Bitget Exchange and Bitget Wallet are not the same system
Another potential source of confusion is the Bitget name.
The incident affected custodial wallet infrastructure used by Bitget Exchange.
Bitget says its separate self-custodial Bitget Wallet product was not affected and operates on separate infrastructure.
The distinction matters because custody determines who controls transaction authorization.
On a centralized exchange, the exchange controls the infrastructure holding and moving customer assets.
With genuine self-custody, the user controls the relevant keys.
Neither model eliminates every security risk, but they create very different failure modes.
Protection funds are not a substitute for architecture
Bitget's Protection Fund can absorb financial losses if it functions as described.
But reimbursement capacity and prevention are separate security layers.
A strong exchange-security assessment therefore needs to ask more than whether losses are covered.
How was the backend compromised?
Why could manipulated transaction data reach the authorization process?
Which controls failed to detect the discrepancy before signing?
What new controls prevent the same class of attack?
Bitget says Mandiant and SlowMist are assisting the investigation and that the vulnerability has been remediated.
A detailed forensic explanation will provide more information than the headline loss figure.
What to watch next
- Withdrawal restoration: successful BTC, ETH and USDT withdrawals on the announced dates would provide direct evidence that the withdrawal infrastructure has passed enough validation to return to service.
- Full restoration by October 2: delays would indicate that remediation or validation is taking longer than currently planned.
- Final recovered amount: $387.5 million was transferred to attacker-controlled addresses, but recovery efforts may change the eventual net loss.
- Forensic root-cause disclosure: technical details should clarify how the authorization layer was bypassed and which controls were changed.
- Protection Fund after remediation: its composition and value after absorbing the incident will matter for assessing how much financial buffer remains.
Conclusion
The most important lesson from the Bitget incident is not simply that a hot wallet was breached.
According to the exchange, the private keys themselves were not stolen.
Instead, attackers compromised wallet backend infrastructure and manipulated the information reaching the transaction-authorization process.
That distinction matters because secure keys cannot protect assets if compromised systems can convince legitimate signing infrastructure to authorize illegitimate transactions.
Bitget says the vulnerability has been remediated, its cold wallets and separate self-custodial wallet were unaffected, and its Protection Fund covers the financial impact.
The next evidence is operational.
The phased withdrawal restart begins September 28. Whether those withdrawals resume as scheduled — followed by a sufficiently detailed forensic account of the failure — will tell users more about the recovery than reassurance alone.
Sources
Bitget — initial security notice:
https://www.bitget.com/support/articles/12560603896024
Bitget — withdrawal restoration announcement:
https://www.bitgetapp.com/support/articles/12560603896110
The Block — independent reporting and updated loss estimate:
CoinDesk — initial independent coverage:
TRM Labs — onchain analysis:
Disclaimer
This material is for informational and analytical purposes only and does not constitute financial, investment, legal or tax advice.