Bitget reopened Bitcoin withdrawals on Sunday, four days after its security systems flagged transfers the exchange had not authorised. Regulators and researchers blame North Korean hackers, and the loss is now put at $387.5 million. BleepingComputer reported the resumption and the staged schedule that follows it.
Withdrawals for other assets come back in tranches. Ethereum across Ethereum, BSC, Arbitrum, Base and Optimism returns on 29 September at 08:00 UTC. USDT across Ethereum, BSC, Solana and Tron follows on 30 September, with tokens, fiat and peer-to-peer assets due on 2 October. The exchange says the pause was a precaution and that no further unauthorised transfers are possible.
The exchange's own signing process moved the funds
Bitget CEO Gracy Chen said the intruders breached a backend system inside the exchange's wallet infrastructure and used it to spoof transaction data, which caused Bitget's authorization process to release funds. That ordering is the part worth reading twice. The signing path worked as designed, on instructions that were false. Nothing in the cryptography failed, because the attacker never asked it to.
The affected chains, by Chen's account, were Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC and Base, spread across ETH, XRP, BNB, AVAX, USDT and USDC. The wallets that emptied were hot and warm, the working balances an exchange keeps online to service customer withdrawals. Cold storage exists to stay out of reach like this, and it stayed out of reach.
A $36 million gap opened in two days
The first public number was $351.6 million. By Friday, after tracing and transaction classification, Bitget put the total at $387.5 million in a support article. A $36 million revision inside two days is not a rounding error. It is the normal shape of a live investigation, where the early figure is what was visible before anyone had traced the funds properly, and it is why exchanges should be read as reporting a floor at first contact.
This is a familiar category of loss. North Korean state-linked groups have been behind the largest crypto thefts on record, including the $1.5 billion taken from Bybit's ETH cold wallet. Elliptic has estimated that North Korean hackers have stolen more than $6 billion in crypto since 2017.
A recovery bounty is a confession about the money
Bitget also launched a Recovery Bounty Program, offering 5% for help freezing or recovering funds. The incentive is rational and the disclosure is useful: an exchange that will pay a cut to anyone who can freeze the proceeds is telling you it cannot retrieve them alone. On public chains, once value moves through mixers and bridges, the realistic outcome is that some gets frozen where it touches an identifiable service and the rest does not. The bounty is the price of widening the net.
What to watch as withdrawals reopen in stages
The exchange now has to prove two things at once. First, that the backend path the attacker abused is closed, because a staged resumption is a slow, observable test of exactly that. Second, that the protection fund absorbs the loss without touching customer balances, which is a claim best checked when withdrawals are fully live and not before.
There is a broader signal too. If a spoofed transaction can trigger an exchange's authorization flow, then the same class of bug is worth hunting elsewhere, and the exchanges that have not looked yet are the ones to worry about. The most expensive part of this incident may not be the $387.5 million. It is the others now wondering whether their own systems would have signed.