Cryptocurrency exchange Bitget has started restoring withdrawals after a massive cyberattack resulted in $387.5 million in digital assets being transferred to attacker-controlled wallets.
Bitcoin withdrawals are now operational again, marking the first major step toward restoring normal service after Bitget suspended withdrawals following the discovery of unauthorized transactions last week. The exchange says the vulnerability used in the attack has been addressed and that no further unauthorized transfers are possible. (BleepingComputer)
The incident is particularly significant because the attackers did not simply obtain a cryptocurrency private key. According to Bitget, they compromised a critical component of its wallet infrastructure and manipulated transaction data to trigger the exchange’s legitimate authorization process.
From $351 Million to $387.5 MillionBitget initially estimated losses at approximately $351.6 million. After additional blockchain tracing and transaction classification, the company increased that figure to $387.5 million.
The attack affected hot and warm wallets across several blockchain networks, including Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC and Base. Assets involved included ETH, XRP, BNB, AVAX, USDT and USDC. (BleepingComputer)
CEO Gracy Chen has attributed the attack to North Korean hackers, citing IP behavior and blockchain analysis. Bitget says the attackers breached a backend wallet system, spoofed transaction information and caused its authorization infrastructure to approve transfers into attacker-controlled wallets.
That mechanism is arguably the most important part of the incident. Rather than defeating cryptocurrency itself, the attackers appear to have compromised the infrastructure responsible for deciding when legitimate transactions should be signed.
Withdrawals Are Returning GraduallyBitget is taking a phased approach rather than immediately reopening every withdrawal channel.
Bitcoin withdrawals have resumed, while ETH withdrawals across Ethereum, BSC, Arbitrum, Base and Optimism are scheduled to return on September 29. USDT withdrawals across Ethereum, BSC, Solana and Tron are expected on September 30, with other tokens, fiat and P2P withdrawals beginning October 2. (BleepingComputer)
Deposits and trading continued during the withdrawal suspension.
The exchange says customer account balances remain intact and that its Protection Fund will absorb the financial impact of the breach.
Bitget Is Offering Bounties to Recover the FundsThe exchange has also launched a recovery bounty program as investigators attempt to trace and freeze the stolen cryptocurrency.
Bitget is offering rewards of 5% for assistance that leads to stolen funds being recovered or frozen. (BleepingComputer)
Blockchain transparency creates an unusual dynamic after cryptocurrency thefts. Attackers may successfully transfer enormous amounts of digital assets, but those transactions remain visible on public ledgers.
Exchanges, blockchain analytics companies and stablecoin issuers can monitor attacker-controlled addresses and potentially prevent portions of the stolen assets from being converted or moved through cooperating platforms.
Tracing the money, however, is very different from recovering it. Sophisticated attackers can use cross-chain transfers and other laundering techniques to make recovery considerably more difficult.
North Korean Hackers Remain a Major Crypto ThreatBitget’s attribution adds the incident to a growing collection of major cryptocurrency attacks linked to North Korean threat actors.
The most prominent recent example remains the approximately $1.5 billion Bybit theft, while blockchain analytics firm Elliptic estimated in 2025 that North Korean hackers had stolen more than $6 billion in cryptocurrency since 2017. (BleepingComputer)
Cryptocurrency exchanges are particularly attractive targets because successful access to wallet infrastructure can produce enormous financial returns from a single intrusion.
That makes the security architecture surrounding transaction signing just as important as protecting private keys themselves.
The Real Target Was the Trust Around the WalletThe Bitget breach illustrates a recurring pattern in major cryptocurrency attacks.
Cryptographic algorithms are rarely the weakest part of the system. The infrastructure surrounding them — backend services, transaction approval systems, administrator accounts, software supply chains and signing workflows — provides attackers with a much larger attack surface.
A signing key can remain cryptographically secure while the system instructing it to authorize transactions has already been compromised.
Bitget’s gradual restoration of withdrawals suggests the exchange believes that immediate threat has been contained. But the incident leaves the industry with a familiar security lesson:protecting cryptocurrency requires securing not only the keys, but every system trusted to tell those keys what to sign.