Crypto exchange Bitget has resumed Bitcoin withdrawals following a security incident that resulted in the theft of approximately $387.5 million in digital assets. The breach, which occurred on September 24, compromised part of the exchange’s hot and warm wallet infrastructure, though cold wallets remained secure. Initially reporting losses at $351.6 million, Bitget revised the figure upward after accounting for additional transfers involving Zcash and Tron. CEO Gracy Chen announced during a Monday session that Bitcoin withdrawals on the Bitcoin network and BNB Smart Chain were restored first because the withdrawal pipeline was completed earliest. Ether and Tether withdrawals are scheduled to resume Tuesday and Wednesday respectively across multiple networks, with other assets returning by Friday. Chen emphasized that the restoration schedule applies uniformly to all users, without priority access for institutions or VIP customers.
Concurrently, the attacker is actively laundering stolen funds through decentralized protocols. On-chain data from Lookonchain and Arkham indicated that the hacker swapped Ether for Bitcoin using THORChain, a cross-chain liquidity protocol. In response, Bitget called on THORChain to refuse services to addresses linked to the attack. However, THORChain stated that its network halt mechanism is an emergency security feature affecting the entire protocol broadly, rather than a selective freeze of specific funds. Crypto author Anndy Lian noted that THORChain lacks built-in address blacklisting capabilities, limiting its ability to block individual malicious actors without disrupting legitimate user activity.
The phased restoration of withdrawals highlights the operational complexity exchanges face when balancing immediate liquidity needs against forensic integrity. By prioritizing Bitcoin due to pipeline completion, Bitget demonstrated a pragmatic approach to mitigating user panic while acknowledging that different asset classes require distinct security validation timelines. The uniform application of this schedule, devoid of institutional privileges, serves as a critical trust-building measure, signaling that the exchange is not favoring large capital holders over retail users during a crisis. This transparency is essential for maintaining market confidence, particularly when the total loss amount was revised significantly upward, indicating that initial assessments may have underestimated the scope of the compromise across various blockchain networks.
The interaction between centralized exchanges and decentralized protocols like THORChain exposes a structural gap in current crypto regulatory frameworks. While Bitget requested THORChain to blacklist attacker addresses, the protocol’s inability to selectively freeze funds underscores the tension between decentralization principles and crime prevention. THORChain’s reliance on broad network halts as a security mechanism suggests that decentralized finance infrastructure currently lacks granular control tools necessary to isolate illicit flows without collateral damage to legitimate users. This limitation creates a persistent risk vector for centralized entities, as stolen assets can be rapidly converted across chains before law enforcement or exchange compliance teams can intervene, potentially forcing regulators to consider stricter oversight of cross-chain interoperability protocols.


