Bitget Resumes BTC Withdrawals After $388M Exploit
The phased reopening follows the largest reported crypto theft of the year, with Bitget saying its 5,500 BTC User Protection Fund will cover losses.
The phased reopening follows the largest reported crypto theft of the year, with Bitget saying its 5,500 BTC User Protection Fund will cover losses.
The phased restart marks a step toward normal service, but the incident keeps exchange security and withdrawal access in focus.
Swapping ETH for BTC changes the stolen funds’ asset exposure while keeping the cross-chain movement in focus.
The phased restart follows a reported vulnerability fix, while Bitget's promised return of its Protection Fund to a $300M baseline remains a key confidence marker.
The dispute puts THORChain’s permissionless design against calls for targeted intervention after a major exchange breach.
The transfers do not confirm a sale, but native XRP cannot be frozen in attacker-controlled wallets. Exchange deposits or on-chain swaps would sharpen the risk.
The exchange's Oct. 2 reopening schedule lumps XRP into the final phase, while Bitquery traced 27.63M of the stolen 102.98M XRP flowing toward THORChain and swaps into Bitcoin.
The route crossed TRON, Ethereum and THORChain before CoinJoin, showing how roughly 4 BTC moved across chains and services after the theft.
GoPlus says the attackers forged transaction data inside a compromised wallet backend, making Bitget's own authorized signing system generate valid signatures for $387.5M in unauthorized transfers.
The dispute puts a focus on whether decentralized protocols should intervene when publicly flagged addresses move funds linked to a major exploit.
The roundup also flags an NFT theft at Magic Eden and Ethena’s move into stock perpetuals, putting security and regulatory exposure alongside product expansion.
The freeze covers only a small share of the stolen assets; more than 63,000 ETH remain in attacker-linked addresses beyond stablecoin issuers’ reach.
The transfers expose a recovery gap in the XRP Ledger: exchanges can restrict deposits they receive, but XRP itself has no issuer freeze control.
The incident puts Bitget’s security controls under scrutiny as Gracy Chen says a major breach would undermine the exchange’s planned public listing.
The transfer combines ETH withdrawn directly with ETH bought using USDT, consolidating $1.23M in value at the wallet identified as belonging to the hacker.
The phased reopening keeps withdrawals offline until security checks are complete, while Mandiant and SlowMist continue investigating the Sept. 24 incident.
Sygnum’s off-exchange custody can separate eligible institutional collateral from Bitget wallets, but it does not remove reliance on the exchange’s trading and settlement systems.
The revised loss estimate includes Zcash and TRON assets missed in the initial accounting, while withdrawals remain suspended pending security checks.
The reported $350M Bitget breach would make the latest incident a major addition to a year already marked by more than $1B in crypto theft attributed to North Korean hackers.
The increase from $351.6M reflects additional Zcash and TRON assets found during tracing, not new theft; Bitget has set a deadline for its withdrawal plan.