Bitget experienced roughly $463 million in net outflows during the 24 hours leading into Tuesday, September 29, as it began restoring withdrawal services. This surge represents the largest single-day outflow since DefiLlama started monitoring proof-of-reserves four years ago. The exchange had previously suspended withdrawals after announcing that assets equivalent to about $387.5 million were stolen in an attack linked by cybersecurity experts to North Korea.
The company is reopening withdrawals in stages, starting with bitcoin on Monday, followed by Ether and Tether’s USDT stablecoin. Other tokens, fiat, and peer-to-peer services are scheduled to resume on October 2. Bitget CEO Gracy Chen stated that the user protection fund, initially cited at $464 million, has dropped below $200 million due to absorbing the incident's financial impact. Chen confirmed that Bitget will replenish the fund using its own capital, targeting a balance above $300 million within one week.
The immediate liquidity drain highlights the fragility of trust in centralized exchanges following high-profile security breaches. While Bitget characterized the staggered rollout as a security measure unrelated to asset sufficiency, the outflow exceeding 10% of reserves signals significant user concern regarding custody integrity. This event underscores how quickly confidence can evaporate when operational controls are perceived as reactive rather than preventive, particularly when linked to state-sponsored threats like those attributed to North Korea.
From a market structure perspective, this incident reinforces the limitations of traditional security audits in mitigating sophisticated attacks. Data from CoinGecko indicates that most thefts occur despite independent audits, often targeting areas outside standard check scopes. For institutional adoption, the reliance on internal capital to replenish protection funds introduces counterparty risk, as users depend on the exchange's solvency rather than segregated, insured assets. Regulators may scrutinize whether current proof-of-reserve mechanisms adequately capture real-time liability changes during crises.


