Bitget Restores Withdrawals After $388 Million Exploit as Hacker Moves Funds

Exchange resumes services in phases while stolen assets are converted through THORChain
TL;DR
- Bitget began restoring withdrawals after containing a breach tied to a third-party security product.
- Bitcoin withdrawals returned first, with Ethereum, USDT and other services scheduled to follow.
- ZachXBT said Chinese illicit actors are laundering funds from the attack for alleged DPRK-linked attackers using bridges and mixing services.
Trade smarter on Jupiter, Solana’s leading DEX built for fast execution and deep liquidity.
Swap tokens at competitive rates, route across multiple liquidity sources automatically, and access perpetuals, DCA, and advanced trading tools — all in one place!
Bitget began restoring withdrawals on September 28, 2026, four days after a security breach triggered unauthorized transfers from its hot and warm wallets. The exchange said about $388 million in assets were stolen after attackers exploited a third-party security product, obtained high-level internal credentials and bypassed withdrawal risk controls without stealing private keys.

Unauthorized activity began at about 6:31 p.m. UTC on September 24. Bitget said the attacker used compromised credentials to send fraudulent withdrawal instructions across multiple networks. “The attacker then used these credentials to send fraudulent withdrawal commands to the wallet system, causing it to execute abnormal transfers that bypassed risk controls,” Bitget said.
Assets affected included ETH, USDT, USDC, BNB, AVAX, XRP and Tron-based tokens. About $185 million was moved within a single minute. Bitget said user balances, cold wallets and its separate self-custodial wallet service were not affected.
Loss estimates increased as tracing continued. The initial estimate was $351.6 million before later tracing raised the confirmed total to about $387.5 million. Bitget subsequently confirmed the roughly $388 million figure. The theft was identified as the largest reported crypto theft of 2026 to that point, surpassing incidents involving KelpDAO and Drift Protocol.
Bitget said it patched the vulnerability, contained the incident and detected no further unauthorized transfers. Losses would be covered by the Bitget User Protection Fund, which held 5,500 BTC.
Withdrawals Return Chain by Chain
Bitget CEO Gracy Chen said during a September 28 livestream that the incident affected withdrawal infrastructure across multiple chains and assets, requiring separate security checks before each withdrawal route could reopen. Chen said the suspension was a security measure rather than a result of insufficient user assets.
Bitcoin withdrawals resumed first because the BTC withdrawal pipeline had not been affected by the attack and was the first to complete preparations. Bitget said 4,098 BTC withdrawal transactions had been processed after service resumed.
Chen said ETH and USDT restoration depended on security-check progress and user demand. She also said the Protection Fund would be restored above $300 million within one week.
Mandiant and SlowMist were assisting Bitget with the investigation. Bitget said it expected an official security report during the week of September 28 and planned a full technical postmortem after the investigation concludes. The exchange also said it would change how it assesses and deploys third-party security products.
Attacker Begins Converting Stolen Assets
Attacker-linked wallets began their first major post-exploit fund movements on September 28. Blockchain data showed ETH moving into THORChain vaults, often in batches of 100 ETH, before being converted into BTC.

Earlier movements involving XRP, BNB and TRX also passed through THORChain and similar bridging services before conversion into Bitcoin, contributing to a temporary increase in THORChain trading volume and network fees. A substantial portion of the stolen assets had already been converted into bitcoin, while remaining ETH continued moving through the same route.
Some Bitcoin was processed using transaction-obfuscation techniques. Bitget published attacker-linked addresses and asked industry participants to freeze and recover stolen assets. THORChain said its permissionless network cannot selectively block individual addresses.
Bitget offered a recovery bounty equal to 5% of any attacker funds successfully frozen through a participant’s actions and said some assets had already been frozen through industry coordination.
Bitget said it would not identify the attackers before reaching a firm conclusion, while calling them “sophisticated” and “state-backed.” The exchange had previously said it suspected North Korea was behind the attack.
ZachXBT Tracks Laundering Network Behind Stolen Funds
Blockchain investigator ZachXBT said Chinese illicit actors are laundering funds from the Bitget exploit on behalf of the alleged DPRK attackers, with participants openly seeking help processing orders through public Discord servers and Telegram channels used by the services involved.
ZachXBT said the funds are being chain-hopped through bridges before being deposited into mixing services including Wasabi. He identified five aliases tied to the activity: Cc, jack, Melon, lolo/Marin and HELP ME, along with associated Discord or Telegram accounts and transaction hashes.
One of the identified actors, Alias 4, was also observed laundering funds from the $292 million Kelp DAO exploit earlier this year, according to ZachXBT. He said he had seen the same pattern following multiple TraderTraitor-attributed exploits and had closely tracked the groups, adding that he plans to publish more of his data in the coming weeks.
This article has been refined and enhanced by ChatGPT.