Bitget has begun restoring cryptocurrency withdrawals following a security incident on September 24 that resulted in the theft of approximately $388 million. The exchange clarified that attackers exploited a vulnerability in a third-party security product to obtain high-level internal credentials, allowing them to issue fraudulent withdrawal commands across multiple blockchain networks including Ethereum, XRP Ledger, and Tron. By Monday morning, Bitget had processed 9,585 bitcoin withdrawals totaling 4,098 BTC, with plans to resume other asset withdrawals throughout the week.

The company emphasized that its private keys and cold wallets were never compromised, and customer balances remain intact, supported by a User Protection Fund exceeding $464 million and a comprehensive reserve ratio of 127%. Forensic specialists Mandiant and Slowmist are assisting with the investigation, while some affected assets have been frozen through industry coordination. CEO Gracy Chen noted that the attack methodology appeared consistent with North Korean-linked groups, though the official security report is expected later this week.