Bitget will resume cryptocurrency withdrawals in a phased approach after a security breach compromised approximately $351.6 million from its hot and warm wallet infrastructure. The exchange announced a four-stage rollout beginning with Bitcoin on September 28 at 08:00 UTC, followed by Ethereum on September 29, USDT on September 30, and remaining tokens, fiat, and peer-to-peer services by October 2.
The exchange identified and patched the vulnerability behind the attack. Additional security checks and system testing are underway before each withdrawal phase resumes. Bitget emphasized that the temporary suspension was a precautionary measure and that customer balances remain unaffected despite the breach.
According to Bitget CEO Gracy Chen, the company's Protection Fund will cover the financial impact. The fund holds more than $464 million. Cold wallets were not compromised, and trading and deposits continue to operate normally.
Recovery Efforts Underway
Stablecoin issuers Circle and Tether have frozen addresses linked to the attacker, blocking approximately $318,000 in combined USDT and USDC holdings. Bitget has launched a Recovery Bounty Program offering a 5% discount for freezing attacker-controlled funds and a 5% asset recovery discount.
The stolen assets included approximately $157.5 million in XRP, the largest portion of the breach, along with significant Ethereum holdings. Attackers transferred funds across multiple networks and exchanged some holdings.
Mandiant and SlowMist are assisting with the investigation. Bitget stated that users need not take action before withdrawals resume, with availability reflected directly on the platform. The incident has been contained and no further unauthorized transfers are possible, according to the exchange.


