Bitget reopened Ethereum withdrawals at 08:00 UTC on Tuesday, marking the second phase of restoring access after a breach that drained $387.5 million from the exchange. CEO Gracy Chen reported a net inflow of approximately 651 ETH in the first hour, interpreting this as user confidence, though independent verification remains pending. The attack exploited a vulnerability in a third-party security product to obtain internal credentials, allowing attackers to spoof transaction data and trigger fraudulent withdrawal commands without compromising private keys.

Recovery efforts have yielded minimal results, with only roughly $503,000 frozen by NEAR Intents out of more than $50 million intercepted in laundering flows. Cross-chain protocol THORChain declined to block attacker-linked addresses, citing neutrality policies. On-chain investigators Elliptic and ZachXBT linked the incident to North Korea’s state-affiliated hacking apparatus, noting similarities to previous operations like the Bybit breach. Bitget’s Protection Fund, initially holding over $464 million in Bitcoin, is being replenished to above $300 million from company capital to cover losses, while USDT withdrawals are scheduled to resume on September 30.