Bitget has successfully restored its emergency Protection Fund to more than $300 million, meeting its self-imposed deadline five days early after a $388 million security incident on Sept. 24. The fund, which absorbed the financial impact to ensure user account balances remained unaffected, now holds 3,705 Bitcoin valued at approximately $309 million across three publicly verifiable on-chain wallet addresses.
The exchange committed on Sept. 28 to return the reserve to its baseline of at least $300 million within seven days. On-chain records show the funds are distributed across three primary Bitcoin addresses holding 1,369.91 BTC, 1,199.81 BTC, and 1,134.99 BTC respectively. This replenishment coincides with the systematic restoration of withdrawal services, which began with Bitcoin on Sept. 28 and is scheduled to conclude fully on Oct. 2. Forensic firms Mandiant and SlowMist continue independent investigations into the stolen assets and infrastructure controls.
The rapid restoration of Bitget’s protection fund signals a strategic effort to stabilize market confidence following a significant security exploit. By deploying capital to cover losses and ensuring user balances remained accurate, the exchange prioritized immediate liquidity assurance over prolonged uncertainty. The public verification of the fund’s composition through on-chain data serves as a critical transparency mechanism, allowing users and regulators to independently validate the solvency claims rather than relying solely on internal reporting.
From an institutional adoption perspective, the coexistence of this event with the publication of the 47th monthly Proof of Reserves report highlights the growing expectation for continuous, verifiable compliance in crypto markets. While the reserve ratio of 131% indicates robust asset backing, the ongoing forensic investigations by Mandiant and SlowMist underscore that operational risk remains a persistent challenge. Stakeholders should monitor the finalization of these audits and the complete resumption of all service lines to assess whether the underlying infrastructure vulnerabilities have been adequately addressed.


