Bitget Restores Usdt Withdrawals After 387 Million Hack

15 min read
4 views
Sep 30, 2026

Bitget just brought USDT withdrawals back after a $387.5 million breach. Reserves look solvent on paper. The stolen coins are still moving, and one network refused to freeze them.

Financial market analysis from 30/09/2026. Market conditions may have changed since publication.

Six days is a long time to stare at a withdrawal button that will not move. Anyone who has ever parked coins on an exchange knows that feeling. You can trade. You can deposit. You just cannot leave. That is the awkward middle ground Bitget users sat in after a late-September breach that investigators now put at $387.5 million. On September 30, the exchange said the three assets people care about most were moving again: Bitcoin, Ether, and USDT.

What Changed When Withdrawals Came Back

I have covered enough exchange incidents to know the first question is never “who did it.” The first question is simpler. Can I get my money? Bitget’s answer, delivered by CEO Gracy Chen, was that BTC, ETH, and USDT rails were live again and that the rest of the stack would follow on Friday, October 2 at 08:00 UTC. P2P, fiat, and the leftover token list sit in that last bucket.

That staged return matters more than a single press line. Bitcoin opened first on September 28. Ether came back a day later across Ethereum, BNB Smart Chain, Arbitrum, Base, and Optimism. USDT followed on the 30th across Ethereum, BNB Smart Chain, Solana, and Tron. If you hold a thinner altcoin, you wait. If you need cash out through a bank rail, you wait. If you live in peer-to-peer markets, you wait until Friday morning UTC.

The business is gradually back to usual.

– Gracy Chen

That sentence is doing a lot of work. “Gradually” is the honest word. Trading never stopped, according to the firm. Deposits stayed open. Customer ledger balances were not written down. The halt was framed as a systems check after unauthorized transfers left hot and warm wallets. Cold storage and private keys, the company says, were never touched. I tend to treat that claim as a starting point, not a closing argument. You verify later. You do not clap first.

A Timeline That Still Feels Tight

The clock started at 18:31 UTC on September 24. Bitget flagged irregular outbound transfers from parts of its hot and warm wallet layer. Early loss estimates sat near $351.6 million. That number climbed to $387.5 million once extra Zcash and Tron-linked movements were folded in. Small revisions like that are common. They also tell you the first public figure is almost never the last one.

Four days later, Bitcoin withdrawals returned. Five days later, Ether. Six days later, USDT. Eight days after the first alert, if the plan holds, everything else reopens. That is fast by exchange-incident standards. It is also the kind of speed that makes security people nervous, because speed and certainty rarely travel together.

  • September 24, 18:31 UTC: unauthorized transfers detected
  • September 26: issuers had already frozen a thin slice of stablecoins
  • September 28, 08:00 UTC: BTC withdrawals resume
  • September 29: ETH withdrawals resume on several networks
  • September 29, 09:00 UTC: fresh proof-of-reserves snapshot
  • September 30: USDT withdrawals resume
  • October 2, 08:00 UTC: planned reopening for remaining tokens, fiat, and P2P

In my experience, the public timeline is the clean version. Forensic work keeps running in the background long after the “resume” banner goes up. Mandiant and SlowMist are still in the room, according to Bitget. That is the part users cannot see, and it is usually the part that decides whether a story ends or just pauses.

How The Attack Was Described

Bitget’s working theory is not a classic key theft. Investigators say attackers abused a weakness in a third-party security product, grabbed access credentials, and forged withdrawal instructions that slipped past risk checks. That distinction is easy to miss and worth keeping in view. Compromised vendor tooling can look, from the outside, a lot like an inside job. It is neither as simple as a leaked seed phrase nor as theatrical as a smashed vault.

Hot and warm wallets are the operational layer. They exist because customers expect withdrawals in minutes, not days. Cold wallets exist because that speed is expensive in risk terms. If the firm’s account is accurate, the attackers never reached the deep storage. They hit the pipes that move money in ordinary hours. That is still a serious failure. It is a different failure from “the keys are gone.”

Perhaps the most interesting aspect is how ordinary the method sounds once you strip the dollar sign off it. Credential access. Forged commands. Checks that did not fire. You could paste that plot into a dozen other industries and it would still read true. Crypto just makes the damage visible on a public ledger before lunch.


The Protection Fund And Why The Number Moved

Bitget has long advertised a Protection Fund as a backstop separate from customer reserves. Before the breach, August figures put the average fund value around $382 million, with a high near $441.5 million on August 27 and a low near $345.3 million on August 1. Roughly 5,500 BTC sat under that umbrella during the month. When the attack landed, the fund was described as sitting above $464 million.

Then withdrawals started coming back, and assets left the fund. Chen had already said the company intended to refill it to a $300 million floor. On September 30 she said that floor had been recrossed. The fund was “back to more than $300 million,” which is both a promise kept and a reminder that the cushion shrank in public view.

This is where language gets slippery. A protection fund is not proof of reserves. One is a corporate rainy-day pile. The other is a snapshot that tries to show covered customer balances against assets held for those balances. Mixing the two is how people talk themselves into false comfort. I’ve found that users do it constantly, and exchanges rarely slow them down.

ItemWhat it measuresWhat it does not measure
Protection FundExchange-held backstop capitalEveryday customer solvency line by line
Proof of reservesCovered balances versus held assets at one momentFull corporate books or off-balance liabilities
Customer ledgerAccount balances shown in the appWhether hot wallets can actually pay today

Bitget says the fund will eat the financial hit. Customer balances stay the same on the books even though $387.5 million left the wallet stack. That is an accounting statement. It can be true and still leave the firm poorer. Shareholders, treasury, and that fund absorb pain so the app balances do not. Fine. Just do not confuse “balances unchanged” with “nothing expensive happened.”

A 131 Percent Reserve Snapshot After The Breach

On September 29 at 09:00 UTC, Bitget published its 47th proof-of-reserves report. Overall coverage sat at 131 percent across nineteen assets. Every listed coin stayed above 100 percent. Bitcoin printed 142 percent. Ether printed 110 percent. USDT printed 107 percent. XRP printed 107 percent. USDC printed 154 percent.

Those are healthy-looking ratios for a report taken five days after a major incident and one day after Bitcoin withdrawals restarted. Chen leaned on the usual line: users can check whether their own assets sit inside the Merkle tree. That is useful. It is also a point-in-time photo, not a year-long film. Proof of reserves does not replace an audit of the whole company. It does not capture every liability. It does not tell you what happens if withdrawals spike for three days straight.

Still, posting the numbers quickly was the correct political move. Silence would have been worse. A late snapshot after BTC rails reopened at least answers the cheap version of the solvency question. Are the covered coins still there? On that morning, the firm said yes, with room to spare.

Covered snapshot, Sept. 29, 09:00 UTC
Overall: 131%
BTC: 142%
ETH: 110%
USDT: 107%
XRP: 107%
USDC: 154%
All 19 listed assets: above 100%

I would rather see this kind of table the week after a hack than a vague “we remain fully reserved” sentence with no dates. Dates keep people honest. Yesterday’s 131 percent does not guarantee next Tuesday’s 131 percent. It does tell you the firm was willing to put a stamp on a specific hour.

Who Can Freeze Stolen Coins, And Who Will Not

Operational recovery and asset recovery are not the same project. Bitget published attacker addresses and asked exchanges, stablecoin issuers, chain teams, and researchers to help freeze or claw back funds. Circle and Tether had already locked about $318,000 in USDC and USDT by September 26. That is real. It is also a rounding error against $387.5 million.

The louder fight sat with THORChain. Chen asked the protocol to refuse service to listed attacker wallets after stolen value started crossing through it. Her argument was blunt. Decentralization, she said, is a design principle, not a shield for moving known stolen funds. THORChain said no. An emergency halt exists to protect the network itself, not to blacklist one address or one swap.

Decentralization is a design principle, not a shield for facilitating known stolen funds.

– Gracy Chen

On-chain activity did not pause for the argument. Analysts flagged 27 successful swaps that turned about 2,390 ETH tied to the attacker into 75.2 BTC, worth roughly $6.3 million at the time. Other flows kept grinding toward Bitcoin after the freeze request was declined. If you were hoping for a neat moral ending, this is not it. Permissionless rails do what they were built to do. They also create a public argument every time a large theft hits the mempool.

THORChain’s own May incident sits in the background of that argument. A newly joined node operator exploited a GG20 threshold-signature weakness on May 15 and drained about $10.7 million from one vault. Automated solvency controls started pausing signing and trading on affected chains within minutes. Node operators then took the network to a full stop. It stayed dark for about five weeks and came back on June 22 with patched signing code and a staged restart.

The protocol’s position is that the May halt does not equal an address blacklist. Emergency brakes fire when the network itself is at risk. Denying one wallet is a different kind of politics. Security researchers have pushed back, arguing that threshold-signature vaults and validator-controlled pauses are not the same animal as base-layer Bitcoin or Ethereum validation. I think both sides are talking past each other. One is defending a product thesis. The other is staring at a moving pile of stolen ETH.

Where Some Of The Money Went Next

Not every route was a clean swap. Tracing teams followed about four BTC into a Wasabi CoinJoin after funds hopped from Tron through USDT0, Ethereum, and THORChain. Mixers do not make coins vanish. They make attribution expensive. At the time of that analysis, a large share of the tracked remainder still sat in separate attacker wallets. That is the unglamorous middle of most theft stories. Some coins freeze. Some coins mix. Most coins wait.

Bitget posted a bounty structure that is easy to remember and hard to collect: 5 percent for help that leads to a freeze, and another 5 percent for successful recovery. Those percentages look generous until you remember how much operational work sits between a screenshot and a seized wallet. Still, bounties change incentives. Researchers who might otherwise publish and walk away now have a reason to stay on the thread.

  1. Publish attacker addresses and ask counterparties to cooperate
  2. Lean on issuers that can freeze centralized stablecoins
  3. Pressure cross-chain venues that can, in theory, pause flow
  4. Pay researchers when freezes or recoveries actually land
  5. Keep forensic partners on the original access path

Only the first two steps are reliably available in 2026. The third depends on a network’s politics. The fourth depends on luck and timing. The fifth is slow, quiet, and usually more important than the social-media argument.


What Users Should Actually Do This Week

Advice after a hack tends to arrive in two flavors: panic and marketing. Try a third. Treat the reopening as a liquidity event, not a vibe check. If you needed coins off the platform last week, the BTC, ETH, and USDT windows are the ones that matter first. If your stack is a long tail of tokens, Friday is the date on the calendar, not a guarantee that every chain will feel normal at 08:01.

I would not read a 131 percent ratio as a reason to increase size. I also would not treat a six-day halt as proof the venue is finished. Both reactions are lazy. The useful questions are smaller.

  • Which networks are actually live for the asset you hold?
  • Are fiat and P2P still gated until October 2?
  • Have you verified your own leaf in the Merkle proof, or only the headline ratio?
  • Is any part of your stack sitting in a token the firm has not cleared yet?
  • Do you have a withdrawal destination that is ready, tested, and not a brand-new wallet you created in a rush?

Rush withdrawals create their own losses. Wrong network. Wrong memo. Wrong address copied from an old screenshot. After a scare, people do sloppy things with perfect sincerity. Slow down for ten minutes. Then move what you intended to move.

If you plan to stay, separate “the app still works” from “the vendor stack got patched.” Bitget says the hole sat in a third-party security product. That means the next test is whether similar tooling, at this firm or any other, gets the same review. Users cannot audit that. They can decide how much operational risk they want to rent.

Why Hot Wallets Keep Showing Up In These Stories

Every large venue lives with a contradiction. Customers want instant outflows. Risk teams want almost nothing hot. The compromise is a layered treasury: cold storage for the bulk, warm wallets for planned flow, hot wallets for the last mile. Attackers do not need the bulk if the last mile is fat enough.

That is why “private keys were not compromised” can be technically true and still leave a nine-figure hole. The keys that matter for daily operations are not always the keys on the poster. They sit behind vendor dashboards, policy engines, and allow lists that someone believed were boring enough to trust.

There is a temptation to treat this as a Bitget-only lesson. It is not. Any exchange that promises fast withdrawals is running some version of the same machine. The brand changes. The tension does not. If a third-party control plane can mint a withdrawal command, that control plane is part of the vault, whether the marketing deck says so or not.

I’ve found that the market has a short memory for this point. Prices recover. Timelines slide down the page. The next venue repeats the same architecture with a new logo. Then we act surprised when the same class of failure returns with a different dollar figure.

The Double Standard Nobody Wants To Own

When a centralized exchange is robbed, the industry expects other centralized actors to help. Issuers freeze. Rival platforms block deposits from dirty addresses. Banks, when they are in the story at all, file the usual reports. When a permissionless router is asked to do the same thing, the answer often comes back as a lecture about design principles.

Both instincts are coherent on their own terms. They collide in public because stolen coins do not respect the org chart. They move toward whatever venue will take them. If that venue is a threshold-signature network with a pause button, people will ask why the button cannot be pressed for this wallet, this week, this theft. If the venue says the button is only for existential network risk, people will call that a double standard. They are not entirely wrong. They are not entirely right either.

The cleaner frame is incentives. Issuers can freeze because their product is a list in a database. Base-layer chains generally cannot freeze without a political event that looks like a hard fork. Cross-chain vaults sit in the messy middle. They have more discretion than Bitcoin and less discretion than a bank. That middle is where the shouting happens.

What The Remaining Open Questions Still Are

A restored withdrawal button does not close the file. Several questions are still live, and pretending otherwise is how these write-ups age badly.

  • How much of the $387.5 million can realistically be frozen rather than chased?
  • Did the third-party product failure stay contained, or does the same pattern exist elsewhere?
  • Will Friday’s full reopening arrive on time for fiat and long-tail tokens?
  • How quickly can the Protection Fund climb back toward its pre-incident range?
  • Does the 131 percent snapshot hold after a few days of heavier outflows?

None of those questions require a speech about the future of finance. They require dates, addresses, and follow-up snapshots. If the firm keeps publishing those, users can do their own math. If the firm slides back into adjectives, treat that as a signal too.

There is also a quieter operational question. Withdrawal infrastructure was the thing under review. Reopening the popular coins first is rational. It is also a way to reduce pressure while thinner rails stay in the shop. That is not a scandal. It is a queue. Just call it a queue.

A Plain Reading Of Solvency Versus Trust

Solvency is a spreadsheet idea. Trust is a habit. Bitget is trying to rebuild the second by waving the first. Covered assets above 100 percent. Fund back over $300 million. Major-asset withdrawals live. Customer balances uncut. Those are the pillars of the current story. They are not nothing. They are also not the same as “the vendor path cannot be forged again.”

Trust after a hack is built in boring increments. Another reserve report next week. A Friday reopening that does not slip. A freeze here and there that actually sticks. A technical post-mortem that names the control that failed without turning into theater. Miss those and the 131 percent figure becomes trivia. Hit them and the incident starts to look like an expensive, ugly, survivable event.

I do not know which version we will get. That uncertainty is the honest ending, even if it is not the tidy one. Coins are moving again for BTC, ETH, and USDT. The rest of the menu is marked for October 2. The stolen stack is still being chased across swaps, mixers, and quiet wallets. Everything else is commentary.

Practical Notes If You Hold Through Friday

Keep the window times in UTC, not in whatever clock your phone prefers when you travel. 08:00 UTC on October 2 is the published slot for leftover tokens, fiat, and P2P. If your banking corridor is slow on weekends, plan the cash leg before you celebrate the on-chain leg. People mix those two calendars and then blame the exchange for a delay that started in their own bank.

Watch network selection on USDT. Ethereum, BNB Smart Chain, Solana, and Tron are the rails named in the latest update. Sending the right ticker on the wrong chain is still the fastest way to turn a recovery story into a support ticket. Copy the address twice. Send a dust test if the size is large enough to justify the fee. Then send the rest.

If you use P2P, remember that counterparties have their own risk switches. An exchange can open the gate and still leave you dealing with a buyer who got spooked by headlines. Liquidity comes back in layers. The button is only one of them.

Proof of reserves matters most when users want to see the numbers for themselves.

– Gracy Chen

That line only works if people actually look. Open the proof. Check the leaf. Do not outsource the whole job to a screenshot in a group chat. Group chats are where ratios go to become myths.

The Wider Market Lesson Sitting Under The Headlines

Large exchange hacks used to be existential by default. Sometimes they still are. More often now they are a stress test of treasury design, communications speed, and whether a venue can pay customers while it hunts a thief. Bitget is trying to sit in that second category. The Protection Fund exists for exactly this plot. The reserve report exists to keep the plot from turning into a run. The staged withdrawal map exists to stop a run from becoming a stampede across every token at once.

Does that architecture make the industry safer? Only if other venues copy the boring parts: separate backstops, dated snapshots, honest staging, and a clear split between customer ledgers and operating wallets. Fancy language about being fully reserved does not do that job. Process does.

There is a cost to that process. Capital sitting in a protection fund is capital that is not earning a flashier return. Extra confirmation steps slow down withdrawals on quiet days. Vendor reviews delay product launches. Users say they want all of that until the quiet days last for months. Then they want speed again. Exchanges hear that. Attackers hear it too.

So here we are. A $387.5 million hole in the hot and warm layer. A fund pulled down and then restocked above $300 million. A reserve photo at 131 percent. Three major assets moving. A cross-chain venue that would not blacklist. A Friday appointment for everything else. That is the story as it stands on September 30. It is unfinished, which is the most human thing about it.

If you take one habit from this week, take this one. When an exchange says it is “back to usual,” ask which usual they mean. Trading usual? Withdrawal usual? Vendor-control usual? Those are three different rooms. Only one of them has a button you can press today.

❝
The rich invest in time, the poor invest in money.
— Warren Buffett
Author

Steven Soarez passionately shares his financial expertise to help everyone better understand and master investing. Contact us for collaboration opportunities or sponsored article inquiries.

Related Articles

?>