Bitget restarted Bitcoin withdrawals on the Bitcoin network at 08:00 UTC on 28 September, four days after an exploit drained roughly $388 million from its hot and warm wallets.
The reopening schedule
Bitget set out the timetable in its support notice: ETH withdrawals on Ethereum, BSC, Arbitrum, Base and Optimism open on 29 September at 08:00 UTC, and USDT on Ethereum, BSC, Solana and Tron follows on 30 September. All remaining assets, fiat withdrawals and P2P services are scheduled for 2 October at 08:00 UTC. XRP is not listed separately, so the timetable places it in that final group only by exclusion, and Bitget has not explicitly confirmed an XRP reopening date.
XRP withdrawals remained disabled as of 26 September while deposits were open, as stolen tokens moved on-chain. Bitquery, the on-chain analytics firm, measured 27.63 million of the roughly 103 million stolen XRP moving onward from attacker accounts by 02:54 UTC that day, with most of the traceable flow routed through THORChain and swapped toward Bitcoin. 75.35 million XRP remained in six tracked attacker accounts at the time of that measurement.
How the loss happened, and who pays
Bitget said the unauthorised transfers began around 18:31 UTC on 24 September across multiple networks. The exchange stated that an attacker exploited a vulnerability in a third-party security product to obtain high-level internal credentials and send fraudulent withdrawal commands that bypassed risk controls. Private keys were not compromised, user balances and cold wallets were unaffected, and the vulnerability has been patched, Bitget said. Trading and deposits have continued throughout.
Bitget revised its estimate of the loss to about $387.5 million on 25 September, from an initial $351.6 million, after adding Zcash and TRON assets, and confirmed $388 million on 28 September. That makes it the largest reported crypto theft of the year, ahead of the KelpDAO and Drift Protocol exploits. The company said the attackers were ‘sophisticated’ and ‘state-backed’, and it will not speculate on their identity until the investigation concludes. It earlier told media outlets it suspected North Korea, a suspicion rather than a finding.
The exchange said losses will be fully covered by its User Protection Fund, which holds 5,500 BTC. Whether that holding can cover a loss of roughly $388 million is an open question. Bitget has also launched a bounty programme paying 5% of any attacker funds successfully frozen or recovered, and Mandiant and SlowMist are assisting the investigation.
The next test of the schedule is ETH withdrawals at 08:00 UTC on 29 September, with the full restoration due on 2 October.