Cybersecurity & Privacy

Bitget Resumes Bitcoin Withdrawals Following Massive $387.5 Million North Korean-Linked Cyber Heist

Cryptocurrency exchange Bitget has officially initiated the phased restoration of withdrawal services, marking a critical step in the platform’s recovery following a sophisticated security breach that resulted in the loss of $387.5 million. The exchange, which suspended all outgoing transactions last Thursday after detecting unauthorized outflows from its hot and warm wallets, confirmed that it has successfully remediated the specific vulnerability exploited by the attackers. As the platform transitions back to normal operations, the crypto community remains focused on the exchange’s robust security response and the broader implications of this high-profile attack, which has been attributed to state-sponsored actors from North Korea.

The Sequence of Events: A Timeline of the Breach

The crisis unfolded rapidly last week when Bitget’s internal security monitoring systems flagged suspicious patterns across several of its hot and warm wallets. On-chain analytics revealed a series of unauthorized transactions involving multiple blockchain networks, including Ethereum, the XRP Ledger, Arbitrum, Avalanche, Optimism, Binance Smart Chain (BSC), and Base.

By Thursday morning, the exchange took the decisive step of halting all withdrawals to prevent further depletion of its reserves. CEO Gracy Chen confirmed that the attackers had managed to infiltrate a critical backend system within the platform’s wallet infrastructure. By spoofing transaction data, the hackers successfully bypassed standard authorization protocols, compelling the system to process the illicit transfers.

Initial assessments placed the stolen amount at approximately $351.6 million. However, subsequent on-chain forensic analysis, conducted by Bitget in coordination with blockchain security partners, revised the total upward to $387.5 million by Friday. The breach impacted a wide array of assets, including ETH, XRP, BNB, AVAX, USDT, and USDC, highlighting the breadth of the attackers’ target list.

Phased Restoration of Services

Bitget’s strategy for returning to full functionality is a carefully calibrated process designed to prioritize stability and security. According to the company’s official communication, the restoration is proceeding in three distinct stages:

  1. Bitcoin (BTC) Resumption: Effective immediately, users are once again able to withdraw Bitcoin, signifying that the most critical segment of the platform’s liquidity has been secured.
  2. Ethereum and Layer-2 Networks: Withdrawals for ETH and related assets across Ethereum, BSC, Arbitrum, Base, and Optimism networks are scheduled to resume on September 29 at 8:00 UTC.
  3. Stablecoins and Secondary Assets: Withdrawals for USDT across major networks, including Ethereum, BSC, Solana, and Tron, will follow on September 30 at 8:00 UTC.
  4. General Assets and Fiat/P2P: All remaining tokens, alongside Fiat and P2P services, are slated for restoration on October 2 at 8:00 UTC.

Bitget has emphasized that trading and deposit services remained fully operational throughout the incident, and the company maintains that the temporary withdrawal pause was purely a precautionary measure rather than a liquidity crisis.

Official Stance and Recovery Efforts

In the wake of the breach, Bitget’s leadership has been proactive in addressing user concerns. CEO Gracy Chen has been transparent about the origin of the attack, citing behavioral patterns and IP analysis that point directly to North Korean state-sponsored threat groups. The sophistication of the breach—specifically the manipulation of backend transaction data—suggests a high level of technical proficiency consistent with advanced persistent threat (APT) actors.

To incentivize the return of stolen funds, Bitget has launched a "Recovery Bounty Program." The exchange is offering a 5% reward to any party—including the attackers themselves—who can facilitate the recovery or freezing of the stolen assets. This approach, while controversial in some circles, is increasingly common in the decentralized finance space as a pragmatic tool for asset recovery.

Bitget resumes Bitcoin withdrawals after $387.5 million crypto heist

Furthermore, the exchange has moved to reassure its global user base that their individual account balances remain untouched. "User funds are unaffected throughout this process," the exchange stated in a formal announcement. "The Bitget Protection Fund covers the financial impact of this platform-wide incident." By leveraging this dedicated reserve, the exchange aims to absorb the loss internally, preventing a direct impact on customer equity.

The Shadow of North Korean Cyber Aggression

The involvement of North Korean hackers in this incident adds a significant geopolitical dimension to the story. This is not an isolated event but rather the latest in a long string of major crypto heists attributed to the hermit kingdom. According to British blockchain analytics firm Elliptic, North Korean actors have successfully siphoned over $6 billion in crypto assets since 2017.

The most notorious example of this activity remains the $1.5 billion theft from Bybit’s ETH cold wallet, an incident that was later confirmed by the FBI to be the work of the Lazarus Group, a notorious state-sponsored hacking collective. The recurring nature of these attacks underscores a systemic shift in how North Korea funds its state activities, moving away from traditional illicit trade toward the more lucrative and harder-to-track realm of digital asset theft.

Experts note that these attacks are characterized by long-term reconnaissance, the use of sophisticated social engineering, and the exploitation of vulnerabilities in third-party software or backend infrastructure. By focusing on "hot" or "warm" wallets—which are necessarily connected to the internet to facilitate high-frequency trading—attackers exploit the inherent tension between convenience and security.

Analysis of Implications for the Crypto Industry

The Bitget incident serves as a stark reminder of the persistent threats facing centralized cryptocurrency exchanges. As these platforms grow in scale, they become increasingly attractive targets for state-sponsored actors who view crypto as a high-value, relatively liquid target for funding national interests.

There are several key takeaways for the industry moving forward:

  • Backend Security Rigor: The breach highlights that perimeter defense is insufficient. Companies must adopt a "zero-trust" architecture, where even internal backend systems are isolated, heavily monitored, and require multi-signature approval for any movement of significant assets.
  • The Role of Protection Funds: Bitget’s ability to state that user assets are covered by a protection fund is a vital component of restoring market confidence. Exchanges that lack such buffers are likely to face existential threats following incidents of this magnitude.
  • Collaborative Forensics: The role of on-chain analysis firms in tracing the stolen funds has been instrumental. The ability to tag and track illicitly gained crypto assets has created a "digital dragnet" that makes it increasingly difficult for attackers to move or cash out their loot without detection by centralized exchanges and regulators.
  • The Evolution of Bounty Programs: The success of recovery programs depends on the willingness of the crypto community to act as watchdogs. As these programs become more standardized, they may serve as a critical deterrent against future attacks, as attackers realize that the digital footprint they leave behind is nearly impossible to scrub.

Looking Ahead

As Bitget works to finalize the restoration of its services, the focus will likely shift toward a comprehensive security audit. The industry expects a full disclosure report detailing the precise nature of the backend vulnerability and the steps taken to ensure that similar spoofing techniques cannot be employed in the future.

For the wider cryptocurrency market, this event highlights the "cat and mouse" game that defines modern digital security. While the resilience of the ecosystem is tested by such massive outflows, the rapid response from the exchange, the cooperation with security firms, and the clear communication strategy provide a blueprint for how platforms can weather the storm of a major cyberattack.

As of October 2026, the global crypto sector continues to grapple with the dual challenges of rapid innovation and the ever-present threat of sophisticated cyber-adversaries. While the financial loss at Bitget is substantial, the successful containment and planned recovery demonstrate that the industry is becoming better equipped to manage, mitigate, and respond to the actions of well-funded, state-sponsored hackers. The coming weeks will be crucial as the platform returns to full capacity and begins the long process of auditing its systems to prevent a recurrence of this high-stakes breach.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
Snapost
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.