Cryptocurrency exchange Bitget reopened Tether (USDT) withdrawals at 08:00 UTC on Wednesday, September 30, six days after attackers moved approximately $387.5 million from its internet-connected wallets. The restart followed a single-day net customer withdrawal of $463 million, which data aggregator DeFiLlama identified as the largest one-day outflow for the platform in four years. Bitcoin and Ether withdrawals had previously resumed on September 28 and 29 respectively, with Bitget reporting a net inflow of roughly 651 ETH during the initial reopening window.
The exchange’s 47th Proof of Reserves report, dated September 30, indicates overall asset coverage stands at 131%, with all 19 listed assets maintaining ratios above 100%. This figure is four percentage points lower than the previous monthly report but confirms that liabilities are currently matched by held assets. However, the User Protection Fund, initially cited at over $464 million, has fallen below $200 million as it absorbs the financial impact of the breach. CEO Gracy Chen stated that customer funds were not touched, attributing the sustained reserve ratio to years of operational discipline.
The resumption of USDT withdrawals marks a critical test of institutional confidence following a significant security breach. While the 131% reserve ratio provides a quantitative buffer against immediate insolvency concerns, the sharp decline in the User Protection Fund highlights the tangible cost of absorbing such losses. The divergence between specific asset flows, such as the net ETH inflow, and the broader platform-wide outflow suggests that market participants are differentiating between stablecoin liquidity risks and volatile asset holdings. This behavior indicates a cautious approach to capital preservation rather than a wholesale exit from the exchange.
From an operational risk perspective, the incident underscores the vulnerabilities inherent in hot and warm wallet infrastructure when third-party security products fail. Although cold storage remained unaffected, the compromise of internal credentials allowed fraudulent commands to bypass standard controls. The reliance on Merkle Tree verification allows users to confirm balance inclusion but does not guarantee the fund's ability to withstand future shocks. Stakeholders should monitor the completion of the formal forensic report and the timeline for replenishing the protection fund, as these factors will determine long-term credibility and regulatory scrutiny.


