Six days following a hot wallet attack on September 24, Bitget has fully resumed withdrawals for Bitcoin, Ether, and USDT. The exchange confirmed that customer balances were unaffected, with the estimated $388 million loss absorbed entirely by its internal Protection Fund rather than user accounts. CEO Gracy Chen stated the fund was designed specifically for such incidents and successfully refilled to above $300 million by September 30, two days ahead of the promised one-week deadline.
Recent data indicates a rapid return of confidence, with $231 million in deposits recorded within a single 24-hour period, approaching August’s daily average of $245 million. Bitget also published its 47th proof of reserves, showing overall coverage at 131 percent across 19 audited coins, with every asset exceeding 100 percent backing. While NEAR Intents blocked around $50 million from the stolen funds, security firms Mandiant and SlowMist continue supporting the investigation into the flaw in a third-party security product that enabled the breach.
The swift restoration of liquidity and reserve metrics suggests Bitget prioritized operational continuity and transparency to mitigate reputational damage. By absorbing the loss through its dedicated fund and publishing verifiable on-chain proofs, the exchange attempted to decouple the incident from customer solvency. The return of deposit volumes to near-normal levels indicates that institutional and retail users may be accepting the risk profile, provided the technical root cause is contained and future-proofed against similar third-party vulnerabilities.
However, reliance on proprietary insurance mechanisms like the Protection Fund introduces counterparty risk if the fund's composition or valuation methods are not independently audited beyond self-reported snapshots. Market structure implications remain significant as exchanges compete on trust; while Bitget met its short-term targets, the long-term credibility of its security infrastructure depends on the final forensic report regarding the third-party product flaw. Investors should monitor whether this incident triggers broader regulatory scrutiny on hot wallet management and third-party vendor integration standards across centralized platforms.


