Bitget hacked for $387.5M: Stolen crypto nearly gone as ETH withdrawals resume

Bitget reopened Ethereum withdrawals at 08:00 UTC on Tuesday morning, completing the second stage of a phased withdrawal restoration schedule following one of the largest centralized exchange hacks of 2026. In the first hour, the exchange reported a net inflow — more ETH arrived than left. That number, offered by CEO Gracy Chen as a vote of user confidence, matters less than the number she hasn’t repeated: of the $387.5 million drained from the exchange five days ago, less than $503,000 has been frozen anywhere in the world. The rest is almost certainly gone.

AA2ddyhJ

The recovery picture is defined by a single data point from NEAR Intents, a cross-chain bridge that stated it intercepted more than $50 million in laundering flows tied to the Bitget hack. Of that intercepted total, roughly $503,000 was actually frozen — meaning more than 99 percent of what passed through that single chokepoint escaped. Cross-chain swap protocol THORChain, which has become the default laundering rail for large state-sponsored crypto heists, declined to block attacker-linked addresses, citing its neutrality policy. Blockchain analytics firm TRM Labs has documented that THORChain has consistently refused to block illicit activity tied to prior major hacks, including the $1.5 billion Bybit breach in February 2025 and the $300 million KelpDAO hack in April 2026.

On-chain investigators including ZachXBT and Elliptic have linked the attack to North Korea’s state-affiliated hacking apparatus. Blockchain analytics firm Elliptic assessed the Bitget attack as “highly likely” tied to North Korea based on on-chain connections between XRP taken from Bitget and ether from an earlier DPRK-attributed theft. Bitget CEO Chen stated in a live Q&A on X that IP addresses traced to the hack matched VPN infrastructure previously used by North Korean-linked groups, and that the attack pattern resembled prior operations. Bitget has not independently published its technical attribution evidence, and no FBI statement attributing the Bitget breach to Lazarus Group has been issued as of this writing.

This is what the ETH net inflow figure cannot tell you: whether the exchange’s user base is returning out of genuine confidence in its Protection Fund or simply because moving funds elsewhere requires functional withdrawals, and ETH withdrawals only just opened.

ETH Withdrawals Open — USDT Is What To Watch

The 9,674 ETH deposited and 9,023 ETH withdrawn in the first hour of Tuesday’s reopening produced a net gain of roughly 651 ETH. At ETH’s prevailing price on the morning of September 29, that represents approximately $1.2 million in net user deposits — exchange-reported data, not an independent audit.

Chen posted the figures to X just before 11:00 UTC, writing that users had extended their trust by choosing to deposit rather than flee. On-chain analyst Ai Yi separately tracked a wallet address believed to be Bitget’s ETH withdrawal wallet and reported broadly similar directional movement, though Bitget has not confirmed the wallet’s identity.

The more consequential test arrives Wednesday morning (08:00 UTC, September 30), when USDT withdrawal restoration schedule opens across Ethereum, BNB Smart Chain, Solana, and Tron. Tether (USDT) is the dominant stablecoin for active trading and typically the first asset holders convert to when exiting a platform under stress. If USDT outflows on Wednesday significantly exceed inflows, the solvency pressure on Bitget’s Protection Fund will intensify beyond what ETH data suggests.

All remaining tokens, fiat withdrawals, and peer-to-peer transfers are scheduled for 08:00 UTC on October 2. Trading and deposits remained open throughout the five-day freeze.

How Attackers Drained $387.5 Million Without Stealing a Single Private Key

Bitget disclosed the attack vector following its security review. The breach did not involve private-key theft — the cryptographic secrets that directly authorize movement of funds from wallets. That distinction matters technically, and it matters for users.

Private-key compromise would have given attackers control of Bitget’s cold wallets, which hold the majority of user assets offline. Those were untouched. Instead, the attacker exploited a vulnerability in a third-party security product to obtain high-level internal credentials — the equivalent of stealing an administrator’s badge rather than picking a vault lock. Those credentials were then used to spoof transaction data and trigger Bitget’s own authorization process to issue fraudulent withdrawal commands, as if a legitimate operator were moving funds. The system believed the requests were real because they came through a credentialed, trusted channel.

Aneirin Flynn, chief executive of cybersecurity firm FailSafe, noted after the breach was disclosed that the significance of the hack is that it destroys the illusion that major exchanges have solved hot-wallet security. The attack falls into the category of third-party supply chain credential compromise — the same category that produced the SolarWinds breach and related incidents in other industries. A centralized exchange’s operational security is only as strong as its weakest third-party integration, regardless of how well the private keys themselves are managed.

Bitget said it isolated affected systems, revoked and reissued credentials, and disabled the compromised third-party function after detection. Security firms Mandiant and SlowMist are conducting independent forensic work and assisting with asset tracing. Bitget said it expects to release a formal security report this week.

The three-tier wallet architecture Bitget employs — hot wallets for frequent transactions, warm wallets as an intermediate layer, cold wallets held offline — confined the breach to the hot and warm layers. But the credential-based attack vector means that even exchanges with strong private-key hygiene face exposure if backend systems carry exploitable vulnerabilities.

Why Recovery of Most of the $387.5 Million Is Unlikely

The Bitget breach shares a structural feature with the February 2025 Bybit hack: both involved suspected North Korean state-sponsored actors who move stolen funds rapidly through cross-chain infrastructure designed to resist freezing. The FBI attributed Bybit theft to North Korean hacking group TraderTraitor (also known as Lazarus Group) within days of that incident. Bybit lost approximately $1.5 billion and, by most accounts, recovered very little of it.

The laundering picture at Bitget is already documented. Lookonchain blockchain analytics tracking showed approximately $183 million of the stolen funds being swapped for Ether shortly after the breach. The stolen funds were then distributed across multiple addresses and chains — the standard Lazarus Group playbook, which the FBI described after the Bybit breach as designed to “further launder and eventually convert to fiat currency.” THORChain, the preferred cross-chain rail for these operations, declined to act. NEAR Intents froze $503,000.

Esme Pau, head of capital markets and policy at blockchain security firm CertiK, put the scale in context. The CertiK head of capital markets stated that the scale of the drain at around three quarters of the exchange’s User Protection Fund transcends a security lapse and makes it a crisis event. Bitget has also launched a 5% recovery bounty program for any frozen or recovered funds. At the current trajectory, the bounty may prove largely symbolic.

Does Anyone Have Money on Deposit? The Protection Fund Math

The mechanism that distinguishes Bitget’s current position from FTX’s 2022 collapse is the Protection Fund — a reserve Bitget holds specifically to absorb platform-level losses so that individual customer balances are not written down. When the exchange detected the breach, the Protection Fund covers this loss and the fund held more than $464 million — enough to cover the revised $387.5 million loss in full.

The Protection Fund bitcoin denomination is a specific characteristic worth understanding: Bitget holds approximately 5,500 BTC in the fund. At a BTC price of roughly $84,000, that produces a fund balance above $460 million. But the fund’s USD coverage moves in real time with the Bitcoin price — meaning a sharp BTC decline at any point between now and when the fund is drawn upon reduces the available coverage, potentially at the worst possible moment.

Chen stated on September 28 that the fund’s balance would be replenished to above $300 million from company capital within a week. That replenishment target — $300 million, not the original $464 million — reflects a fund that will have been drawn upon significantly to cover losses. Users evaluating whether to remain on the platform should note that this committed reserve, once partially disbursed, covers the $387.5 million loss only if the Bitcoin price does not fall materially below its September 24 level during the replenishment window.

For comparison: when Bybit was hacked for $1.5 billion in February 2025, CEO Ben Zhou said his exchange would remain solvent even if nothing was recovered, and he covered losses from Bybit’s own reserves without suspending withdrawals for an extended period. The contrast with Bitget’s five-day withdrawal freeze is structural — Bybit’s liquidity position allowed immediate access; Bitget’s required a security review and staged reopening. Notably, when Bybit faced its crisis in 2025, Bitget transferred emergency ETH support — 40,000 ETH (approximately $105 million at the time) — from its own reserves to provide liquidity. Bybit CEO Ben Zhou acknowledged this in the days after the current hack, publicly offering Ben Zhou LazarusBounty help to include Bitget’s case in the LazarusBounty asset-tracing platform.

Does the Credential Attack Vector Change How You Should Think About Exchange Security?

Private-key security and exchange security are not the same thing. The Bitget breach demonstrates that an exchange can maintain strong cryptographic control of its cold wallets — and still lose $387.5 million through its operational backend. Private keys cannot protect against an attacker who uses stolen credentials to make fraudulent requests appear legitimate to the authorization system.

For users evaluating any centralized exchange, this incident highlights a specific category of risk that standard proof-of-reserve audits do not capture: the security of the third-party integrations that touch operational credentials. Merkle-tree proof-of-reserves reports confirm that an exchange holds the assets it claims — they say nothing about whether the systems authorizing withdrawals of those assets are themselves secure. Bitget published monthly Merkle-tree proof-of-reserves reports showing reserve ratios well above one-to-one, and the hack still happened.

Gracy Chen US regulatory advocacy has included noting that the US Clarity Act could reduce fragmentation between state and federal compliance requirements, and she stated Bitget plans to launch a US-facing website by the end of 2026 or the first half of 2027. The breach arrives as that regulatory push is underway and raises a question for any framework: whether exchange security standards — particularly for third-party backend systems — should be a licensed requirement, not just a market-driven best practice.

What Happens Next

As of 16:00 ET on September 29, Bitget’s remaining schedule was as follows:

Date (UTC) Assets Status

Sep 28, 08:00

BTC (Bitcoin, BSC)

Open

Sep 29, 08:00

ETH (Ethereum, BSC, Arbitrum, Base, Optimism)

Open

Sep 30, 08:00

USDT (Ethereum, BSC, Solana, Tron)

Scheduled

Oct 2, 08:00

Other tokens, fiat, P2P

Scheduled

The 651 ETH net inflow in the first hour of today’s reopening is a data point, not a verdict. The larger questions — whether the Protection Fund replenishment to $300 million holds, whether USDT outflows on Wednesday remain manageable, and whether the Mandiant and SlowMist forensic report surfaces any additional information about what was compromised — will determine how this episode is ultimately judged. For now, one conclusion is clear: the $387.5 million is almost certainly not coming back, and everything else depends on whether Bitget’s company capital can sustain a reserve that users are willing to trust.

Users holding ETH can withdraw now. Users holding USDT should know that option opens at 08:00 UTC on Wednesday (September 30). Users holding any other asset have until October 2. All Bitget accounts remain active for trading and deposits.

Frequently Asked Questions

Is Bitget solvent after the $387.5 million hack?

Bitget says yes, citing a Protection Fund that held more than $464 million at the time of the breach — enough to cover the loss in full. The fund is denominated in Bitcoin, so its exact US dollar value fluctuates with the BTC price. CEO Gracy Chen pledged on September 28 to replenish the fund to above $300 million from company capital within a week. Formal solvency verification depends on the forthcoming Mandiant and SlowMist forensic report, which Bitget said it expects to release this week. No customer account balances have been written down.

Why is so little of the $387.5 million frozen if investigators know who the attackers are?

The stolen funds moved through cross-chain swap protocols — primarily THORChain — that are designed to resist censorship and have explicitly declined to freeze attacker-linked addresses. NEAR Intents, a different bridge, intercepted over $50 million in flow but was only able to freeze roughly $503,000 of it. The suspected attackers, linked to North Korea’s Lazarus Group (also tracked as TraderTraitor), employ a well-documented post-theft playbook: convert stolen assets rapidly to ETH, distribute across thousands of addresses on multiple chains, and route through protocols resistant to freeze requests. The FBI confirmed this same group was behind the $1.5 billion Bybit hack in February 2025, where recovery was also minimal.

What was different about this hack compared to most exchange breaches?

The attacker did not steal private keys — the cryptographic credentials that directly control wallet addresses. Instead, they exploited a vulnerability in a third-party security product integrated into Bitget’s backend to obtain high-level operational credentials. Those credentials were used to spoof transaction data and trigger Bitget’s own authorization system, making fraudulent withdrawals appear legitimate. This attack category — third-party supply chain credential compromise — means an exchange can maintain strong private-key security and still be vulnerable if its operational systems have external dependencies with exploitable access points.

When should Bitget users expect full access to all their assets?

Ethereum withdrawals reopened on September 29 at 08:00 UTC. USDT withdrawals across Ethereum, BNB Smart Chain, Solana, and Tron are scheduled for September 30 at 08:00 UTC. All remaining tokens, fiat withdrawals, and peer-to-peer transfers are scheduled for October 2 at 08:00 UTC. Trading and deposits remained open throughout the withdrawal freeze. If the published schedule holds, all users should have full withdrawal access by October 2.

Leave a comment

error: Content is protected !!