Bitget has initiated a phased restoration of customer withdrawal services following a significant security breach that transferred about $387.5 million to attacker-controlled wallets. The exchange reopened Bitcoin withdrawals on September 28, with Ethereum and stablecoin services scheduled to return by September 30 and other tokens by October 2. Bitget stated it identified and remediated the vulnerability, confirming that trading and deposits remained operational throughout the incident.
The initial loss estimate was revised upward from $351.6 million after additional affected transactions involving Zcash and TRON were discovered. Onchain investigators tracked the movement of stolen funds, noting that the attacker moved $83 million in XRP and began converting ETH into Bitcoin via THORCHAIN. Circle and Tether froze $318,000 linked to the hack, while Bitget CEO Gracy Chen publicly requested THORChain refuse service to addresses associated with the attacker.
The staged reopening of withdrawal functions signals an attempt to balance immediate liquidity needs with ongoing forensic verification. By prioritizing Bitcoin before other assets, Bitget is likely managing risk exposure while ensuring that remediation efforts are effective across different blockchain infrastructures. This approach highlights the operational complexity exchanges face when recovering from multi-chain breaches, where vulnerabilities may manifest differently across various networks and asset types.
From a market structure perspective, the incident underscores the persistent tension between decentralized protocols and centralized compliance expectations. While stablecoin issuers like Circle and Tether demonstrated coordinated freezing capabilities, THORChain’s response highlighted technical limitations in selectively blocking individual addresses without halting broader network operations. This divergence suggests that institutional adoption requires more robust interoperability standards for crisis management, as reliance on voluntary cooperation from decentralized entities remains inconsistent.


