Sign up
Subscribe
Home / news / Bitget resumes Bitcoin withdrawals after $387.5 million breach as attacker moves ETH through THORChain
news

Bitget resumes Bitcoin withdrawals after $387.5 million breach as attacker moves ETH through THORChain

Bitget resumes Bitcoin withdrawals after $387.5 million breach as attacker moves ETH through THORChain

Bitget has started restoring withdrawals after a security incident that affected nearly $388 million in assets, with Bitcoin back online first and ETH, USDT and other services queued for the next few days. For high-risk operators and PSPs, the practical detail is simple: the exchange is restoring flows in stages, while the stolen assets are still being moved across chains.

  1. Bitget resumed Bitcoin (BTC) withdrawals on Monday after suspending them following last week’s security incident. The exchange said BTC withdrawals were restored first on the Bitcoin network and on BNB Smart Chain, because “the withdrawal pipeline is the first to be completed.”
  2. The Sept. 24 breach compromised part of Bitget’s hot and warm wallet infrastructure, while cold wallets remained secure, according to the exchange. Bitget later revised the stolen amount from $351.6 million to $387.5 million after accounting for additional transfers on Zcash and Tron.
  3. Chief executive Gracy Chen said Ether (ETH) and Tether’s USDt (USDT) would come back as security checks progress. Under the announced schedule, ETH withdrawals are set to resume Tuesday across Ethereum, BNB Smart Chain, Arbitrum, Base and Optimism, followed by USDT on Wednesday across Ethereum, BNB Smart Chain, Solana and Tron.
  4. Withdrawals for other assets and peer-to-peer services are scheduled to return Friday. Bitget said the timetable applies to all users, with no priority access for institutions, VIP customers or Bitget employees.
  5. Meanwhile, the attacker is still moving funds through THORChain. Lookonchain reported Monday that the attacker was swapping Ether for Bitcoin through the protocol, and Arkham data showed ETH linked to the attacker flowing into THORChain vaults. THORChain said its network halt is an emergency security mechanism that affects the protocol broadly and “is not a selective freeze of specific funds or an individual swap.”

Chen has called on THORChain to refuse services to addresses linked to the attack. But the protocol said it has no built-in address blacklist, which is the part that matters in practice: if you cannot selectively freeze an address, you are choosing between broad controls and no targeted control at all.

Weekly high-risk digest

Regulation, sanctions and payment news across your verticals — once a week, free.

Please check your inbox and click the link to confirm your subscription.

Please enter a valid email address!