Bitget Hack Loss Rises to $387M, Withdrawals Resume Sep 28
Bitget raised its hack loss to about $387.5 million after finding more affected assets on Zcash and TRON, and will restart withdrawals in stages from 28 Sep.
Crypto exchange Bitget has raised its estimate of the 24 September hack to about $387.5 million, up from the $351.6 million first reported. The exchange says the extra $35.9 million comes from affected assets it found later on the Zcash and TRON networks. It is a fuller count of the same breach, not a second attack. Bitget has also published a schedule to restart withdrawals in stages from 28 September.
Key takeaways
- Total loss revised to about $387.5 million across Ethereum and other EVM chains, the XRP Ledger, Zcash and TRON. No Bitcoin was taken.
- Bitget says user balances are unaffected and its User Protection Fund, worth more than $464 million, covers the loss.
- Withdrawals reopen in four steps between 28 September and 2 October, starting with BTC.
- Investigators suspect a North Korea linked group, but this has not been formally confirmed.
Withdrawal restart schedule
All times are 08:00 UTC, which is 1:30 pm in India.
| Date | What reopens |
|---|---|
| Mon, 28 Sep | BTC on the Bitcoin network |
| Tue, 29 Sep | ETH on Ethereum, BSC, Arbitrum, Base and Optimism |
| Wed, 30 Sep | USDT on Ethereum, BSC, Solana and Tron |
| Fri, 2 Oct | All other tokens (including XRP, BNB and AVAX), plus fiat and P2P |
Deposits and trading have stayed open throughout.
What was stolen and how
On-chain trackers tallied the first $351.6 million as mostly XRP (about 102.9 million tokens, worth roughly $157 million) and ETH (about 31,890 ETH, worth roughly $86 million). The rest was USDT, USDC, USDT0, BNB, AVAX, TRX and the gold token XAUt. Most of the stolen stablecoins were swapped into ETH quickly. Only about $318,000 of USDT and USDC was frozen by the issuers in time.
CEO Gracy Chen says attackers did not steal private keys. They broke into a backend part of the wallet system and fed it forged transaction data, which the exchange's own signing process then approved. Only hot and warm wallets were hit, and cold storage is safe. Bitget says the flaw is fixed. Security firms Mandiant and SlowMist are running the forensic review, and a full incident report is still to come.
Chen said investigators found IP addresses tied to VPN services used before by a North Korean hacking group, and that the attack pattern matches earlier operations by that group. Bitget is offering a bounty of up to 10%: 5% of any funds frozen plus 5% of any funds recovered.
What it means for Indian users
Bitget has a large base of Indian traders. If you hold funds there, your balance should be intact, but expect queues when withdrawals reopen and move funds only through the official app or website. Ignore anyone on Telegram or X offering "early withdrawal" or "recovery" help: fake support is the most common scam after any hack.
The episode is also a reminder of why it pays to check whether an exchange is registered with India's Financial Intelligence Unit (FIU-IND). Earlier in September, FIU-IND sent notices to 15 offshore platforms seeking to block their apps and websites. See our list of FIU-registered crypto exchanges, and for long-term holdings consider self-custody, explained in our guide to hot and cold wallets.
FAQ
How much was lost in the Bitget hack?
Bitget's latest estimate is about $387.5 million, revised on 26 September from $351.6 million.
When will Bitget withdrawals resume?
BTC withdrawals reopen on 28 September at 08:00 UTC (1:30 pm IST), ETH on 29 September, USDT on 30 September and everything else on 2 October.
Are Bitget user funds safe?
Bitget says account balances are unaffected and the loss is covered by its User Protection Fund. As with any exchange, keep only what you trade there and hold the rest in a wallet you control.
This article is AI-assisted, educational and general in nature. It is not financial advice and never a guarantee of profit. Every trade is at your own risk on your own exchange. See our risk disclosure and editorial policy.