HomeSecurityBitget: Bitcoin withdrawals resume after millions of dollars stolen

Bitget: Bitcoin withdrawals resume after millions of dollars stolen

Cryptocurrency exchange Bitget has begun restoring Bitcoin withdrawalsafter they were temporarily suspended due to a serious security incident that allegedly led to the theft of hundreds of millions of dollars. The company announced that it has identified and addressed the security gap exploited by the attackers, while it is gradually restoring services for the remaining cryptocurrencies and networks.

Bitget: Bitcoin withdrawals resume after millions of dollars stolen

The case has caused concern in the digital asset market as reports of financial losses have changed during the investigation, while suspicions that hacking groups linked to North Korea have brought the risk of targeted operations against major cryptocurrency platforms back to the fore.

Gradual restoration of withdrawals

Bitget announced that the temporary suspension of withdrawals was implemented as a precautionary measure to limit the risk of new unauthorized transfers. According to the company, the incident has been brought under control and additional unauthorized transfers are no longer possible through the compromised mechanism.

See also: Contagious Interview: 30,000 devices breached & crypto stolen

The exchange also announced a tentative timeline for the reinstatement of withdrawals . For Ethereum (ETH), on the Ethereum, BSC, Arbitrum, Base, and Optimism networks , the resumption was scheduled for September 29 at 08:00 UTC. For Tether (USDT), on the Ethereum, BSC, Solana, and Tron networks , the corresponding date was September 30 at 08:00 UTC.

For the remaining tokens, fiat currencies and assets traded through peer-to-peer (P2P) services, Bitget cited October 2nd at 08:00 UTC as an indicative date.

The specific dates constitute the timeline announced by the company and do not in themselves constitute confirmation that each service was fully restored within the expected time.

Bitget also claimed that user balances were not affected by the suspension and that transactions and deposits were still operating normally. It added that its Protection Fund would cover the financial impact of the incident, without the temporary suspension of withdrawals being linked, according to it, to a lack of available assets.

How Bitget's infrastructure was breached

Bitget suspended withdrawals on Thursday after its security systems detected multiple unauthorized transfers from a number of cryptocurrency wallets. The company initially estimated that the perpetrators had removed assets worth about $351.6 million, which were held in so-called hot and warm wallets.

Bitget: Bitcoin withdrawals resume after millions of dollars stolen

Hot wallets are wallets connected to the internet, which facilitate everyday transactions and withdrawals. Warm wallets combine instant access features with additional protection mechanisms. While these categories serve different business needs, their connection to systems that communicate with the internet can create risks when critical infrastructure elements are compromised.

Bitget CEO Gracy Chensaid the attack affected multiple blockchain networks, including Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base. Assets reportedly affected include ETH, XRP, BNB, AVAX, USDT, and USDC.

According to Chen’s description, the attackers gained access to a critical backend system that supported the operation of the wallets. They then allegedly tampered with transaction data, misleading the platform’s transfer approval process. In this way, they were able to move funds from compromised wallets.

See also: CISA KEV: 7 new vulnerabilities with reverse shells and crypto miners

The incident highlights that an attack on an exchange does not necessarily have to rely on directly compromising the blockchain. Instead, exploiting a vulnerable internal system can allow attackers to manipulate processes that normally protect transactions.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Why the estimate of stolen funds increased

On Friday, Bitget revised upwards its estimate of the funds transferred to addresses controlled by the perpetrators. Based on the latest blockchain transaction tracking and classification, the amount reached $387.5 million.

The difference between the initial and subsequent estimates shows how difficult it can be to value a large cryptocurrency heist. Investigators must track transfers across different networks, value assets, and distinguish movements linked to the attack from other transactions.

To help track down and recover the funds, Bitget announced a recovery reward program, offering 5% of the funds recovered or frozen with the help of third parties. Such initiatives can mobilize blockchain analysis firms and security experts, but do not guarantee that the funds will be returned.

Suspicions about North Korea

Chen attributed the attack to hackers allegedly linked to North Korea, citing findings from blockchain transaction analysis and IP address behavior patterns. The attribution of responsibility, however, is based on the company's assessment and should not be confused with independent, definitive confirmation of the perpetrators' identities.

Groups linked to North Korea have been accused of a series of large-scale thefts of cryptocurrency, which are considered a significant source of revenue for the regime. In a previous incident, the breach of exchange Bybit led to the theft of approximately $1.5 billion in ETH, according to reports on the case.

Bitget: Bitcoin withdrawals resume after millions of dollars stolen

Meanwhile, blockchain analytics firm Elliptic estimated in February 2025 that North Korean hackers had stolen more than $6 billion worth of cryptocurrencies since 2017.

See also: Chrome & Edge extensions steal crypto and user data

What the attack means for exchange security

The Bitget case highlights the need for stricter controls on internal transaction approval processes, segregation of access rights, independent verification of transfers, and ongoing monitoring of suspicious activity. At the same time, the use of withdrawal limits, multiple approvals, and immediate suspension mechanisms can limit losses when a breach is detected.

For users, the resumption of withdrawals is an important development, but it does not negate the need to carefully assess the risks that accompany the storage of digital assets on centralized platforms. Transparency about the incident, an independent investigation and clear communication about the coverage of losses will be crucial to restoring trust.

source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS