Bitget Resumes Bitcoin Withdrawals Following Massive $387.5 Million Security Breach Linked to North Korean Hackers

Cryptocurrency exchange Bitget has officially commenced the phased restoration of withdrawal services for Bitcoin, marking a critical step in its recovery efforts following a devastating security breach last week. The incident, which saw unauthorized actors siphon approximately $387.5 million from the exchange’s hot and warm wallets, prompted an immediate, platform-wide suspension of all outgoing transactions as a protective measure. By addressing the specific vulnerabilities that allowed the hackers to spoof transaction data, Bitget is now moving toward a full operational state, though the path to total recovery remains complex.
Chronology of the Security Incident
The breach, which ranks among the most significant in recent cryptocurrency history, unfolded rapidly late last week. On Thursday, Bitget’s internal monitoring systems detected a series of anomalous, unauthorized transfers originating from a limited number of the exchange’s digital wallets. Upon discovery, the firm’s security team initiated an emergency shutdown of all withdrawal functions to prevent further depletion of user funds.
Initial reports from the exchange indicated that the attackers had managed to bypass authorization protocols by breaching a critical backend system within the Bitget wallet infrastructure. By successfully spoofing transaction data, the perpetrators convinced the exchange’s automated authorization processes to release assets from hot and warm wallets. By Friday, as on-chain tracing continued, the exchange adjusted its initial loss estimates upward from $351.6 million to $387.5 million.
The attack targeted a wide array of blockchain networks, including Ethereum, the XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base. The stolen assets comprised a diverse portfolio of major cryptocurrencies, including ETH, XRP, BNB, AVAX, USDT, and USDC, among other tokens.
Phased Restoration Schedule
In an effort to stabilize its operations while ensuring continued security, Bitget has outlined a rigorous timeline for the reactivation of withdrawal services. Following the restoration of Bitcoin withdrawals, the exchange has provided the following schedule for other assets:
- September 29, 08:00 UTC: Resumption of withdrawals for Ethereum (ETH) across the Ethereum, BSC, Arbitrum, Base, and Optimism networks.
- September 30, 08:00 UTC: Restoration of withdrawals for Tether (USDT) on the Ethereum, BSC, Solana, and Tron networks.
- October 2, 08:00 UTC: Resumption of withdrawals for all remaining tokens, as well as Fiat and P2P assets.
Bitget has emphasized that trading and deposits were never halted, and the platform remains fully functional in those capacities. The exchange maintains that the temporary pause on withdrawals was purely a defensive security measure and that user account balances remain entirely unaffected by the theft.
Official Responses and Mitigation Efforts
Bitget CEO Gracy Chen has been transparent regarding the nature of the attack. In public statements, she attributed the breach to state-sponsored actors from North Korea, citing detailed on-chain analysis and identifiable IP behavior patterns consistent with known threat groups.
"The incident remains contained, and no further unauthorized transfers are possible," Chen stated in an official communication to users. "User funds are unaffected throughout this process. Bitget’s Protection Fund is active and covers the financial impact of this platform-wide incident, ensuring that our customers are not forced to bear the cost of this criminal activity."
To aid in the potential recovery of the stolen funds, Bitget has launched a "Recovery Bounty Program." This initiative offers a 5% bounty to parties who can assist in the freezing or recovery of the illicitly transferred assets. This move reflects a growing trend in the crypto sector, where exchanges leverage the collective intelligence of the blockchain security community to track and pressure hackers into returning stolen funds.

The Growing Threat of North Korean Cyber-Operations
The attribution of this heist to North Korean hackers aligns with a broader, well-documented pattern of state-sponsored cyber-criminality. North Korean groups—most notably the Lazarus Group—have become increasingly sophisticated in their targeting of cryptocurrency exchanges, which they utilize as a primary mechanism to bypass international sanctions and fund state activities.
The scale of this attack is particularly alarming when viewed against the backdrop of historical data. According to British blockchain analytics firm Elliptic, North Korean actors have successfully stolen over $6 billion in cryptocurrency assets since 2017. One of the most notorious incidents in this timeline occurred previously when hackers siphoned a record $1.5 billion from Bybit’s ETH cold wallet, an event that drew significant attention from the FBI and international intelligence agencies.
The sophistication of these groups has evolved from simple phishing and social engineering to high-level backend infrastructure breaches. By targeting the backend systems that manage transaction authorization, these hackers effectively turn the exchanges’ own security protocols against them, making detection significantly more difficult.
Broader Implications for the Crypto Exchange Sector
The Bitget breach serves as a stark reminder of the persistent vulnerabilities inherent in centralized crypto exchanges. Despite massive investments in security infrastructure, the centralization of "hot" and "warm" wallets—which are necessarily connected to the internet to facilitate rapid trading—remains a lucrative target for advanced persistent threats (APTs).
Analysts point to several key implications arising from this event:
- Heightened Security Audits: Exchanges are likely to face increased pressure from both regulators and their user base to conduct more frequent, rigorous audits of their backend wallet infrastructure.
- The "Protection Fund" Model: Bitget’s reliance on a pre-funded insurance or protection fund to mitigate the impact of the hack demonstrates a move toward a more mature financial framework. Exchanges that lack such buffers are likely to be viewed as higher-risk moving forward.
- Cross-Chain Vulnerabilities: As exchanges increasingly support a wide variety of chains (as seen in the diverse list of affected networks in this hack), the complexity of securing those bridges and cross-chain transaction nodes increases. Each new network integration potentially introduces a new attack vector.
- Regulatory Scrutiny: With North Korean involvement becoming a recurring theme in major heists, international regulatory bodies are likely to demand more stringent KYC (Know Your Customer) and AML (Anti-Money Laundering) requirements, as well as mandatory reporting timelines for when an exchange suspects it has been compromised.
Strengthening Defensive Blueprints
As the industry grapples with the fallout of the Bitget incident, the conversation among security leaders has shifted toward "AI-speed" defense. The reality of modern cyber-attacks is that they occur at machine speed, often leaving human defenders reacting hours or days after the breach has already been executed.
Industry experts advocate for a multi-layered security strategy that includes not only better firewalls and endpoint protection but also real-time, automated anomaly detection that can trigger automatic "circuit breakers" on wallets before a full-scale withdrawal occurs. The incident at Bitget highlights that while recovery mechanisms like protection funds are vital, the industry must move toward a paradigm where automated systems can identify and isolate compromised segments of the network before hundreds of millions of dollars are transferred to attacker-controlled addresses.
As the crypto market continues to integrate with traditional finance, the ability of exchanges to maintain the integrity of their systems will be the primary determinant of long-term viability. For Bitget, the next few weeks will be critical as they restore full service and attempt to restore user confidence. Whether this breach will lead to a broader industry-wide hardening of protocols remains to be seen, but it is clear that the status quo of exchange security is being tested as never before.
Conclusion
The incident at Bitget is a sobering chapter in the ongoing history of digital asset security. While the exchange has taken responsible steps by pausing withdrawals, transparently communicating with users, and initiating recovery efforts, the $387.5 million loss highlights the immense challenges of defending against state-sponsored actors. As the exchange works toward the final phase of its withdrawal restoration on October 2, the global crypto community will be watching closely to see if Bitget can successfully navigate this crisis and set a new standard for how major platforms handle large-scale security failures. The event underscores the necessity for constant vigilance, the importance of robust insurance funds, and the persistent, evolving threat posed by actors seeking to exploit the digital economy.






