Cryptocurrency exchange Bitget resumed Bitcoin withdrawals on September 28, 2026, after pausing operations due to a security breach that compromised $387.5 million in assets. The reactivation followed the phased timeline outlined in the official withdrawal schedule published by the platform.
The incident, detected on September 24, 2026, affected parts of the company’s hot and warm wallet infrastructure. In contrast, reserves stored within cold wallet systems remained isolated and fully protected from the intrusion.
Incident Recap https://t.co/nPO1mWftpP
— Bitget (@bitget) September 28, 2026
Initial estimates released by the firm placed the loss at $351.6 million. However, the exchange revised the total after accounting for unauthorized transfers on Zcash and Tron, according to platform incident updates released during the investigation.
Despite the volume redirected by attackers, user account balances were not compromised. Spot trading and deposit functions remained operational while technical teams isolated the affected systems to prevent further unauthorized transfers.
Phased restoration across assets and networks
Bitget CEO Gracy Chen confirmed during a September 28, 2026 live session that Bitcoin withdrawals across the native Bitcoin network and BNB Smart Chain were restored first because their verification pipeline was completed ahead of other chains.
Withdrawals for Ether are scheduled to resume on September 29, 2026, covering Ethereum, BNB Smart Chain, Arbitrum, Base, and Optimism. Tether outflows in USDt will follow on September 30 across Ethereum, BNB Smart Chain, Solana, and Tron.
Bitget has begun the phased resumption of withdrawals following the security incident identified on September 24, with BTC withdrawals on the Bitcoin network started at 08:00 UTC on September 28 as scheduled.
— Bitget (@bitget) September 28, 2026
The resumption follows additional security work across Bitget's…
Restoration for remaining tokens, fiat rails, and peer-to-peer services is set for October 2, 2026. Chen confirmed in executive leadership statements that this rollout applies universally without preferential access for institutional clients, VIP users, or platform employees.
THORChain asset movements and governance debate
While Bitget reopens outgoing transfers, on-chain tracking from Lookonchain revealed that the attacker began swapping stolen Ether for Bitcoin via decentralized cross-chain protocol THORChain. Arkham Intelligence data confirmed stolen funds entering THORChain vaults across several transactions.
The illicit volume caused daily swap volume on THORChain to surge past $500 million between September 24 and September 26, 2026. Network fees generated during those two days exceeded $800,000 as capital moved across liquidity pools.
Chen formally requested that THORChain halt services to addresses linked to the breach. The executive argued that decentralization serves as a core architectural framework rather than a shield to facilitate the transfer of identifiable stolen digital assets.
THORChain responded on September 28, 2026, clarifying that its emergency network halt mechanism functions across the entire protocol. The protocol stated that its design cannot execute selective freezes targeting specific wallets or isolated swap transactions.
Industry author Anndy Lian noted that THORChain lacks native blacklisting capabilities. While validators can pause outbound transactions or halt connected chains, doing so impacts all protocol participants and runs contrary to the permissionless settlement structure governing its decentralized liquidity network.
Containment protocol and reserve guarantees
To protect customer balances against financial losses, Bitget stated that its platform protection fund will absorb the impact, with plans to restore the reserve to its $300 million baseline within one week.
The exchange previously partnered with external cybersecurity firms to establish technical security standards aimed at raising defense thresholds across centralized trading venues, focusing on operational transparency and custody verification.
Cybersecurity specialists Mandiant and SlowMist continue assisting the exchange with technical forensic reviews. Bitget confirmed that the access vulnerability was patched, ruling out the compromise of master private keys or ongoing unauthorized transaction activity.
The asset recovery process remains open in coordination with international law enforcement agencies and analytics teams. The next confirmed operational milestone will be the resumption of Ether withdrawals scheduled for 08:00 UTC on September 29, 2026.
This article is for informational purposes and does not constitute financial advice.

