Four days without Bitcoin withdrawals feels longer when your coins are sitting on an exchange that just admitted hundreds of millions walked out the door. I kept refreshing the status page the way people check a delayed flight, half expecting another delay, half hoping the lights would come back on. At 08:00 UTC on September 28, they did. Bitcoin withdrawals on the Bitcoin network were live again, and that single switch flipped the whole story from freeze to cleanup.
What Changed When Bitget Turned Bitcoin Withdrawals Back On
The exchange had locked customer withdrawals on September 24 after unauthorized transfers ripped through parts of its hot and warm wallet stack. Early estimates sat near USD 351.6 million. Later tracing pushed the figure to about USD 387.5 million sent to attacker-controlled addresses. That is not a rounding error. That is a full operational shock.
Still, deposits and trading never stopped. Account balances, the company says, were not rewritten. The hole is supposed to be filled by a User Protection Fund that was valued above USD 464 million when the freeze began. In my experience, users hear “fund” and relax too quickly. A fund can cover a loss on paper and still leave people waiting on process, queues, and network-by-network checks.
Bitcoin coming back first was not a coincidence. It is the most watched asset, the loudest customer complaint line, and the simplest network to reopen after extra validation. Ether is slated for September 29. USDT is penciled in for September 30. Everything else, including fiat and peer-to-peer, is aimed at October 2. Each date is still “subject to security checks,” which is corporate language for: we will delay again if we have to.
How The September 24 Breach Actually Started
The first unauthorized transfers were spotted around 18:31 UTC on September 24. That timestamp matters because it tells you this was not a slow weekend drip. It was a live-fire event against backend wallet infrastructure.
According to the company’s own account, attackers exploited a vulnerability in a third-party security product, grabbed high-level internal network credentials, and then forged withdrawal commands. Those commands slipped past existing risk controls. No private keys were leaked, the firm says. Cold wallets were not touched. That last point is the one I keep coming back to. If cold storage really held, the blast radius was limited to the hot and warm layer. Limited, not small.
The attacker then used these credentials to send fraudulent withdrawal commands to the wallet system.
That sentence is dry on purpose. It also tells you the failure was not “someone guessed a seed phrase.” It was authorization logic. False transaction information was fed into a process that was supposed to stop exactly this kind of request. When that layer fails, the rest of the stack looks decorative.
Why A Third-Party Tool Became The Weak Link
Exchanges love to talk about in-house security theater. In practice, a lot of the boring work sits with vendors: monitoring agents, privileged access tools, session managers, the unglamorous software that sits between a human operator and a wallet service. Compromise that product and you do not need the keys. You need the right ticket in the right queue.
I’ve found that this is the part retail users skip. They ask whether an exchange is “safe.” Safer question: how many outside systems can issue a withdrawal-shaped command? How many people can approve it? How quickly does the system notice a burst that does not match normal flow?
- Credentials were obtained through a third-party product, not a leaked seed.
- Fraudulent withdrawal instructions were created after that access.
- Hot and warm wallets were the operational target, not cold storage.
- Trading and deposits continued while withdrawals were frozen.
- Customer balances were reported as unchanged on the ledger side.
None of that makes the loss pretty. It does change the recovery map. If cold wallets are intact, the firm can keep markets open and use reserves plus the protection fund to absorb the hit. If cold wallets had been emptied, you would be reading a different kind of article.
The Withdrawal Calendar And What It Really Signals
Bitcoin on the native network opened at 08:00 UTC on September 28. Bitcoin on BNB Smart Chain was also marked open the same day. That dual restart is easy to miss and useful to notice. It suggests the team was not only clearing one chain. They were clearing a family of Bitcoin-related rails.
| Asset | Planned Reopen | Networks Named |
| Bitcoin | September 28, 08:00 UTC | Bitcoin network, plus BNB Smart Chain |
| Ether | September 29, 08:00 UTC | Ethereum, BNB Smart Chain, Arbitrum, Base, Optimism |
| USDT | September 30, 08:00 UTC | Ethereum, BNB Smart Chain, Solana, Tron |
| Other tokens, fiat, P2P | October 2, 08:00 UTC | Subject to extra checks |
Look at Ether’s list. Five networks. Look at USDT. Four. That is more moving parts, more bridge logic, more places a forged command could have been replayed. Bitcoin first was the conservative choice. I would have done the same.
Does a calendar mean the danger is over? No. It means the firm believes the original hole is patched and that extra validation is enough to let value leave the platform again. Those are two different claims. One is technical. The other is reputational.
User Balances, The Protection Fund, And The Math Problem
Here is the awkward arithmetic. The protection fund was described as holding more than USD 464 million when withdrawals stopped. The later theft figure is about USD 387.5 million. On a napkin, the fund still covers the hole. On a balance sheet, timing, asset mix, and frozen recoveries all matter.
Stablecoins linked to the attack were already being frozen by issuers. Reports around September 26 pointed to roughly 99,990 USDC and 218,023 USDT locked. That is helpful. It is also tiny next to the headline number. Most of the value is not sitting in two tidy stablecoin piles waiting for a polite freeze request.
Perhaps the most interesting aspect is how quickly the story moved from “we can cover this” to “we are still chasing the coins.” Both can be true. Coverage keeps users solvent. Tracing tries to shrink the bill. Users care about the first. Investigators live in the second.
Who Is Investigating And What Recovery Looks Like
Mandiant and SlowMist were brought in to work the case alongside internal teams. That pairing is familiar in this industry: one shop for enterprise incident response, one shop that lives in blockchain graphs. Bitget says it identified the attack path, patched the vulnerability, and added validation before turning withdrawals back on.
A bounty program is also in play. Separate 5% rewards were offered for work that leads to a qualifying freeze and for work that leads to a successful recovery. That structure is not charity. It is a market for information. People who sit near mixers, bridges, and over-the-counter desks sometimes see flow before a press note does.
- Contain the live path and stop new unauthorized transfers.
- Publish attacker addresses and open a tracing portal.
- Ask issuers and partners to freeze tagged balances where they can.
- Follow hops across chains, bridges, and privacy tools.
- Pay bounties only when a freeze or recovery actually lands.
That sequence sounds orderly. The chain activity has not been orderly. Some stolen value moved through THORChain, which set off a public argument about whether a permissionless protocol should, or even can, block individual addresses. The protocol side said it does not have a clean switch for that. The exchange side wanted action anyway. You can guess how that conversation ended.
The CoinJoin Detour And Why Four Bitcoin Still Matter
A compliance firm later followed about four BTC tied to the stolen pile into a Wasabi CoinJoin. The path was not simple. Funds moved from TRON through USDT0 and Ethereum, then converted through THORChain into Bitcoin, then into a mixing transaction. Four coins will not fix a USD 387.5 million hole. They do show intent. Someone is trying to break the graph.
On September 25, that same tracing work estimated about USD 343 million still sitting quiet across 13 attacker wallets. The split was ugly in a useful way: eight Ethereum wallets holding around 68,300 ETH, four XRP addresses with about 83 million XRP, and another wallet holding close to 18,900 ZEC. Dormant does not mean safe. Dormant means the next move has not happened yet.
Rough snapshot from mid-investigation: ~68,300 ETH across eight wallets ~83 million XRP across four addresses ~18,900 ZEC in another wallet Plus mixed and bridged fragments still in motion
If you hold any of those assets on an exchange, this is why the reopen order looks the way it does. Bitcoin first. Then Ether across several rollups and side networks. Then the stablecoin that lives on almost every rail that matters. The team is not just reopening a button. It is reopening surfaces that attackers already proved they could abuse.
What Users Should Do While Services Come Back Online
I am not going to pretend a checklist makes a hack feel smaller. It does keep people from making a second mistake on top of the first scare.
First, treat official status notes as the only timetable that counts. Group chats fill with fake “urgent withdrawal” pages faster than you can type a ticker. Second, if you plan to move coins off the platform, test a small amount on each network before you send the stack. A queue and a phishing site can look similar when you are tired. Third, write down which networks you actually use. Bitcoin on the base chain is not the same as Bitcoin wrapped somewhere else.
- Confirm the asset and the exact network before you hit send.
- Use a tiny test withdrawal, then wait for a full confirmation.
- Ignore unsolicited “recovery agents” offering to unlock funds.
- Review API keys and disable anything you do not need.
- Keep records of balances from the freeze window.
Should everyone empty the account today? That depends on your own risk budget. Some traders will leave funds in place because markets stayed open and the protection fund is being waved around as a backstop. Others will treat any hot-wallet incident as a standing eviction notice. Both reactions are rational. The sloppy reaction is clicking a random link because a stranger said withdrawals were “priority processed” for a fee.
The Broader Lesson For Exchange Security
Hot wallets exist because customers want speed. Speed is a feature until it is the hole. Warm wallets sit in the middle, which sounds balanced until an attacker learns how approval is granted. Cold storage is the adult in the room, and in this case it appears to have stayed offline. Good. That should be table stakes, not a victory lap.
The harder lesson sits with vendors. A third-party product with enough privilege to mint a withdrawal command is not a side character. It is part of the wallet. If that product can be abused, your internal “risk engine” is only as strong as the last integration you did not audit this quarter.
If a tool can speak in the voice of your withdrawal system, it is no longer a vendor. It is infrastructure.
I keep seeing the same pattern after large incidents. Firms patch the specific bug, publish a timeline, reopen the most popular asset, and promise a post-mortem. The post-mortem is useful only if it names the control that failed in plain language. “Fraudulent withdrawal commands” is close. The industry still needs the next sentence: which check should have refused those commands, and why it did not.
Why This Incident Hit Confidence Harder Than The Dollar Figure
USD 387.5 million is a lot of money. Confidence is messier. People can live with a hack that is explained. They struggle with a hack that sounds like a forged internal memo. Credentials plus a vendor flaw plus bypassed controls is a story about process, not about a lone genius in a hoodie.
That is why the livestream from CEO Gracy Chen mattered more than another dashboard screenshot. Users wanted a person to say the path was found, the product was fixed, and the fund would eat the loss. They also wanted dates. Dates create a scoreboard. Miss one, and the whole reopen looks shaky even if the chain work is fine.
Is the market being fair? Not always. Exchanges get blamed for protocol design they do not control, and protocols get blamed for refusing to become unpaid police. In the middle sit users who just want their Bitcoin to leave when they press withdraw. Fair or not, that is the product promise.
What Happens After Ether And USDT Return
If Ether opens on time across Ethereum, BNB Smart Chain, Arbitrum, Base, and Optimism, the firm will look competent. If one of those rails slips, the whole calendar becomes a rumor mill again. USDT is the real stress test. It touches Ethereum, BNB Smart Chain, Solana, and Tron. That is four cultures of confirmation speed, three different issuer relationships, and a lot of customer volume.
October 2 is the kitchen-sink date: remaining tokens, fiat, peer-to-peer. Fiat is where banking partners quietly set the tempo. Peer-to-peer is where social engineering loves to hide. I would not be shocked if that last bucket moves even if Bitcoin and Ether stay green.
Recovery will run longer than the reopen. Frozen stablecoins can come back in pieces. Mixed Bitcoin may never come back clean. Large dormant ETH and XRP piles can sit for months, then move in one ugly hour. The bounty program is built for that long tail. So is public address tracing. Neither is a guarantee.
A Practical Way To Read The Next Few Days
Watch three things, not twenty. One: do unauthorized transfers stay at zero after each asset class returns. Two: does the published theft total stop climbing. Three: do frozen and recovered amounts grow in public, even if the growth is small. Everything else is noise dressed up as analysis.
I’ve covered enough of these messes to know the quiet period after a restart is when people get sloppy. The button works, the chart looks normal, and the phishing kit arrives with better grammar than last week. If you take one habit from this episode, make it this: slow down the first withdrawal more than the last one.
Bitget is trying to prove that a large hot-wallet failure does not have to become a customer-balance failure. That is the right goal. The proof will not be a single Tuesday morning at 08:00 UTC. The proof will be a boring week where Bitcoin leaves, Ether leaves, USDT leaves, and nothing else leaves with them.
Until that week is over, treat the reopen as progress, not closure. Progress is useful. Closure is what you call it after the last tagged wallet stops moving and the fund no longer has to explain the gap. We are not there yet. We are only back to the part where a withdrawal request is allowed to exist again, which, after four locked days, already feels like a different market.