Bitget revised its estimate of the assets transferred to attacker-controlled addresses in its September 24 breach to about $387.5 million, from an initial $351.6 million. The exchange says its User Protection Fund will cover customer losses; meanwhile, tracing reports describe funds moving through THORChain and other services. The precise attack mechanics remain subject to an important caveat: outside reporting has described a compromised backend wallet system, but the available sources do not include a completed technical account confirming that sequence.
6
33
42
What happened in the breach?
Bitget said it detected unauthorized transfers from some hot wallets at 18:31 UTC on September 24. Its initial notice said parts of the hot and warm wallet layers were affected and that cold wallets remained secure. The later estimate of approximately $387.5 million reflects further tracing and classification of assets sent to attacker-controlled addresses.
21
6
One report said attackers hijacked a backend wallet system and fed forged transfers into Bitget’s signing process.
33 Other coverage said the attack vector was not yet fully established pending a fuller account.
42 Bitget said it identified and fixed the underlying vulnerability, but that does not by itself confirm every detail of the reported method.
6
18
Withdrawal and service-restoration timeline
Bitget published a phased withdrawal schedule, all times UTC. It was a timetable for reopening services, not a guarantee that every withdrawal would be available at the stated time. Bitcoin withdrawals were reported to have resumed on September 28 at 08:00 UTC.
4
20
| Scheduled time |
Withdrawal services |
| September 28, 08:00 |
BTC on Bitcoin and BSC |
| September 29, 08:00 |
ETH on Ethereum, BSC, Arbitrum, Base and Optimism |
| September 30, 08:00 |
USDT on Ethereum, BSC, Solana and Tron |
| October 2, 08:00 |
Other tokens, fiat and P2P withdrawals |
Bitget said it was conducting additional security checks on the withdrawal infrastructure before restoring services. Separately, the exchange’s Onchain trading service was temporarily unavailable during a security review, with no specific restart time given in the cited notice.
18
20
17
How Bitget says it will cover customer losses
Bitget said the loss falls within the coverage of its User Protection Fund, which reports put at about $464 million at the time. This is the exchange’s stated coverage commitment; the available sources do not establish that customer compensation has already been completed.
4
6
Where the stolen funds went
Reports said the attacker swapped stolen ETH into bitcoin through THORChain. Bitget asked the cross-chain protocol to deny service to addresses linked to the breach, but THORChain declined; reports said funds continued moving through the protocol afterward. The episode raised a dispute between efforts to interrupt the movement of suspected stolen assets and THORChain’s permissionless operating model.
5
8
Circle and Tether reportedly froze some stablecoins connected to the incident. Reports put the amount at roughly $318,000, while another account cited about $339,000; the provided sources do not reconcile the difference, so the figures should be treated as estimates rather than a settled total.
2
3
Bitget also launched a recovery bounty offering separate 5% rewards for eligible help freezing funds and recovering them.
1
9 A separate report said 4 BTC linked to the attacker was routed through Wasabi CoinJoin, a privacy tool.
10 These reports describe parts of the tracing effort, not the recovery of the full amount.
What remains uncertain
Bitget says the vulnerability has been remediated and that security validation and fund tracing continue, with Mandiant and SlowMist supporting the investigation.
6
18 The available reporting does not establish a confirmed attribution for the attack. It also does not show that the full amount has been recovered or that all customer compensation has been completed.