Bitcoin withdrawals have reopened first as the crypto exchange begins a phased restoration of withdrawal services following last week’s security breach.
Crypto exchange Bitget has begun restoring withdrawal services following a security breach that resulted in approximately $387.5 million in cryptocurrency being transferred to attacker-controlled addresses.
The exchange reopened Bitcoin withdrawals at 8:00 a.m. UTC on September 28, marking the first stage of a planned phased return of withdrawal services. Bitget initially estimated the incident at $351.6 million before revising the figure after further on-chain analysis identified additional affected assets on the Zcash and TRON networks.
The company said the revised figure does not represent additional unauthorized transfers. Instead, it reflects a more complete accounting of transactions connected to the September 24 incident.
Bitget Restores Withdrawals in Phases
Bitget is not reopening all withdrawal services simultaneously. The company said each asset and blockchain network must undergo additional security checks before withdrawals are restored.
Under the published schedule, BTC withdrawals on the Bitcoin network reopened on September 28.
ETH withdrawals are scheduled to resume on September 29 at 8:00 a.m. UTC across Ethereum, BNB Smart Chain, Arbitrum, Base and Optimism.
USDT withdrawals are scheduled to follow on September 30 at 8:00 a.m. UTC across Ethereum, BNB Smart Chain, Solana and Tron.
Bitget expects withdrawals for other tokens, along with fiat withdrawals and peer-to-peer transactions, to return by October 2 at 8:00 a.m. UTC, subject to the completion of security checks.
The phased approach is intended to allow Bitget to validate each part of its withdrawal infrastructure before putting it back into operation.
What Happened to Bitget?
The security incident was detected on September 24, 2026, at 18:31 UTC.
According to Bitget's investigation, unauthorized transfers were made from some of its hot and warm wallets. The exchange initially reported approximately $351.6 million in affected assets before its subsequent on-chain analysis increased the figure to approximately $387.5 million.
The affected assets included XRP, Ethereum, USDT, Zcash, USDC, USDT0, XAUt, BNB, AVAX and TRX across several blockchain networks.
Bitget said its cold wallets were not affected, while its separate self-custodial Bitget Wallet product was also not involved in the incident. The exchange has also said private keys were not compromised.
The company has been working with cybersecurity firms Mandiant and SlowMist as it investigates how the attacker bypassed its security controls.
User Balances Remain Unaffected, Bitget Says
Bitget has repeatedly said that the security incident did not reduce the balances displayed in users' accounts.
The company said the withdrawal suspension was a security measure designed to allow its technical teams to investigate the incident, remediate the vulnerability and conduct additional checks before restoring withdrawals.
Bitget has also said its User Protection Fund will cover the financial impact of the incident. The fund reportedly holds more than 5,500 BTC, with Bitget saying it is sufficient to cover the affected assets.
Trading and deposits have remained available while withdrawals were temporarily suspended.
Bitget Launches Recovery Bounty
Beyond securing its infrastructure, Bitget has begun efforts to trace and recover the stolen cryptocurrency.
The exchange launched a Recovery Bounty Program offering rewards for efforts that directly result in affected funds being frozen or recovered.
Under the programme, a bounty equivalent to 5% of successfully frozen funds may be available to eligible parties whose voluntary actions directly lead to the freeze. A similar 5% bounty applies to successfully recovered funds.
Bitget said some affected assets have already been frozen through cooperation with exchanges, blockchain projects and other industry participants.
The company has also made fund-tracing information available to security teams and blockchain organisations to assist the recovery effort.
Investigation Into the Attack Continues
The investigation into the exact method used in the breach is continuing.
Bitget has said its security team identified the attack path and the vulnerability that allowed the incident to occur, and that the underlying vulnerability has since been remediated.
The exchange said no further unauthorised transfers are possible following containment of the incident.
The revised $387.5 million figure represents assets that were transferred to attacker-controlled addresses during the original incident, rather than a subsequent increase in the amount stolen.
The incident has nevertheless become one of the largest cryptocurrency thefts reported in 2026, underscoring the security risks faced by centralised exchanges that manage large pools of customer assets.
What Happens Next?
For Bitget users, the immediate focus is the completion of the withdrawal restoration process.
Bitcoin users are now able to withdraw through the Bitcoin network, while ETH, USDT and other assets are scheduled to return progressively through October 2.
Bitget has advised users to rely on the withdrawal status displayed on its platform and its official announcements as each network is restored.
The exchange's ability to complete the phased reopening without another security incident will be closely watched as it continues its investigation and attempts to recover the stolen assets.
For now, Bitget says the incident is contained, its underlying vulnerability has been addressed, and its protection fund will cover the financial impact on users.