Tuesday, September 29, 2026
AI desk
/
/
Bitget Sets Phased Withdrawal Restart After $387.5 Million Security Breach

Bitget Sets Phased Withdrawal Restart After $387.5 Million Security Breach

Bitget plans phased withdrawal restarts through October 2 after unauthorized hot-wallet transfers totaled about $387.5 million.
Last updated
September 28, 2026
8 min read
Fact-checked

Photo: TechJournal

Share

Quick Answer

Bitget plans to restart withdrawals in phases after unauthorized hot-wallet transfers were revised to about $387.5 million. Bitcoin withdrawals are scheduled to restart at 08:00 UTC on September 28, followed by ETH, USDT, and remaining services through October 2. Customers should verify their account security, avoid unsolicited recovery offers, and use Bitget’s published schedule rather than social-media claims.

Key Takeaways

  • Bitget detected unauthorized transfers from some hot wallets at 18:31 UTC on September 24.
  • Bitget revised the total sent to attacker-controlled addresses to about $387.5 million on September 25.
  • Bitcoin withdrawals are scheduled to restart at 08:00 UTC on September 28.
  • ETH, USDT, and other services have later scheduled restart dates through October 2.
  • Customers should treat recovery messages and withdrawal links as high-risk until access is restored.

What happened in the Bitget hack?

The Bitget hack involved unauthorized transfers from some of the exchange’s hot wallets, which Bitget says it detected at 18:31 UTC on September 24, 2026. Hot wallets are internet-connected wallets used to support deposits, withdrawals, and other operational activity, so an incident affecting them can temporarily limit customers’ ability to move assets off an exchange.

Bitget initially estimated affected funds at approximately $351.6 million, then revised the total transferred to attacker-controlled addresses to approximately $387.5 million on September 25. The exchange said the higher figure included Zcash and TRON assets omitted from its first accounting and did not represent additional transfers. Bitget’s incident update also says the affected assets covered Ethereum and other EVM networks, XRP Ledger, Zcash, and TRON.

The affected asset list named XRP, ETH, USDT, ZEC, USDC, XAUt, BNB, AVAX, and TRX. The practical concern for customers is not limited to the specific token they hold, because a withdrawal pause can affect the ability to transfer assets even while trading and deposits remain available.

Bitget says its cold wallets remained secure and that its User Protection Fund held more than $464 million at the time of its initial public update. Customers should still avoid assuming that a reserve statement means withdrawals are immediately available, because the timing depends on the exchange’s phased restart schedule.

When will Bitget withdrawals restart?

Bitget withdrawal restarts are scheduled in 4 phases from September 28 through October 2. Bitcoin withdrawals are scheduled to resume at 08:00 UTC on September 28, while ETH withdrawals are scheduled for September 29, USDT withdrawals for September 30, and other tokens, fiat, and P2P services for October 2.

Bitget’s withdrawal-restart schedule sets out the planned order. The phased approach matters because customers with different assets do not have the same expected withdrawal date, and a customer holding USDT should not rely on the Bitcoin restart time as proof that every network is available.

Service or assetScheduled restart dateWhat customers should do
Bitcoin withdrawalsSeptember 28, 2026, at 08:00 UTCConfirm the withdrawal option is available in the official Bitget app or website before submitting a transfer.
ETH withdrawalsSeptember 29, 2026Check the selected network and destination address before confirming a withdrawal.
USDT withdrawalsSeptember 30, 2026Verify the token network matches the receiving wallet or exchange.
Other tokens, fiat, and P2P servicesOctober 2, 2026Review the official status notice for asset-specific availability.

Bitget says customers did not need to take action before the rollout. The sensible response is to wait for the service relevant to your account, then make a small verification transfer first if you are moving funds to a new destination address.

Which assets and services did the Bitget breach affect?

The Bitget breach affected assets across Ethereum and other EVM networks, XRP Ledger, Zcash, and TRON, according to Bitget’s September 25 update. The named assets include XRP, ETH, USDT, ZEC, USDC, XAUt, BNB, AVAX, and TRX, which means the incident covered more than one blockchain ecosystem.

Bitget says trading and deposits continued during the withdrawal pause. That distinction matters because an account can still show a balance and permit trading while the customer cannot withdraw the underlying asset to a private wallet or another platform.

Customers should distinguish between an asset’s market status and its withdrawal status. A token can remain tradable on an exchange while withdrawals are temporarily unavailable, so users considering a trade should account for the possibility that they cannot immediately move the resulting balance elsewhere.

Independent coverage also described the movement of cryptocurrency from Bitget wallets into unidentified addresses during the incident. The Block’s report on the early transfers provides additional context on the initial public discovery of the wallet movements.

What has Bitget said about the security vulnerability?

Bitget says it identified and remediated the underlying vulnerability and that no further unauthorized transfers were possible as of its September 25 update. Bitget also says it engaged Mandiant and SlowMist in response to the incident, which indicates that the exchange brought in external cybersecurity and blockchain-security specialists.

The company’s statement is important, but it is still an exchange-provided assessment rather than a complete public technical report. Customers should therefore treat the remediation claim as a status update, not as a reason to lower normal account-security protections or trust unsolicited messages that claim to offer special access to funds.

Crypto-exchange incidents also create favorable conditions for impersonation attempts. Users who receive messages directing them to a recovery page, a new wallet address, or an urgent support chat should open the official Bitget app or manually enter the official website address instead of following links in emails, social posts, or direct messages.

Account security deserves the same careful treatment as other platform risks. Readers reviewing privacy settings and sensitive data limits can apply a similar principle here: do not provide credentials, recovery codes, identification documents, or wallet seed phrases through an unsolicited contact channel.

What should Bitget customers do before withdrawals resume?

Bitget customers should secure account access and wait for the official withdrawal phase that applies to their asset. Bitget says customers did not need to take action before the phased rollout, so users should not pay anyone who claims they can speed up access, recover a balance, or unlock withdrawals.

  1. Open the official Bitget app or manually type the official Bitget website address into your browser.
  2. Review your account activity and confirm that the email address and phone number associated with the account remain correct.
  3. Change your password if you reused it on another service or if you see account activity you do not recognize.
  4. Enable the strongest account protections offered in the official account-security settings.
  5. Wait for the scheduled withdrawal date for your asset, then verify the destination address before confirming a transfer.

Bitget customers should preserve screenshots and transaction records if they see an unfamiliar withdrawal, login alert, or account change. The records can help explain the issue to official support, but customers should not post full transaction histories, balances, recovery codes, or identity documents publicly while seeking help.

The practical stop line is clear: contact Bitget through its official support channel if account access changes without your approval or if an unauthorized transfer appears in account history. Do not attempt to resolve an account-compromise concern through a person who contacts you first.

How does Bitget’s recovery bounty work?

Bitget’s recovery-bounty program offers eligible voluntary contributors 5% of funds successfully frozen and 5% of funds successfully recovered, according to the exchange’s September 25 incident update. The program is tied to successful results, not simply to reporting a suspected address or sending an unverified tip.

The recovery program may encourage cooperation from parties able to help identify, freeze, or recover assets. At the same time, ordinary customers should not interpret the bounty as a reason to investigate suspicious addresses independently, contact suspected attackers, or send transactions in an attempt to trace funds.

Customers should leave technical tracing and recovery work to the exchange, its named security partners, law enforcement, and qualified investigators. A person offering paid recovery services through social media or private messaging may be attempting a second scam, especially if the person requests an upfront crypto payment, account login, or seed phrase.

Similar follow-on risks appear after many security incidents, including cases involving phishing emails sent to wallet users. The safest response is to verify any claim through the company’s official channels rather than trusting a message because it uses breach-related details.

Why should customers watch for phishing after the Bitget breach?

Bitget customers should expect phishing attempts after a widely publicized security incident because criminals can use the withdrawal pause and recovery process as believable pretexts. A message can appear urgent, promise early access, or ask a customer to confirm a wallet address, but those requests can lead to stolen credentials or redirected funds.

The most important warning is that no legitimate support process requires customers to disclose a wallet seed phrase or send crypto to “verify” an account. Customers should also avoid browser pop-ups and search advertisements that imitate exchange support pages, a tactic also used in fake technical-support alerts.

Bitget customers should verify the domain, use a bookmarked official site, and start support requests from inside the official account interface. The limitation is that visual branding alone is not proof of legitimacy, because scam pages can copy colors, layouts, and support language with little effort.

The practical response is to pause before acting on any urgent request. Customers who believe their account has been accessed without permission should secure the account through official channels and stop communicating with any unverified contact.

What does the Bitget withdrawal schedule mean for customers?

The Bitget withdrawal schedule means customers regain withdrawal access according to asset type rather than all at once. Bitcoin has the earliest scheduled restart at 08:00 UTC on September 28, while ETH, USDT, and the remaining services follow on later dates through October 2.

The phased process gives Bitget time to restore services in stages after it says it remediated the vulnerability. That approach may reduce operational pressure, but it also means customers need to plan around the availability date for their specific asset and should not make time-sensitive transfers until the relevant withdrawal function is confirmed active.

Customers holding assets on an exchange should also remember the difference between account access and custody control. An account balance represents a claim within the exchange system, while a completed withdrawal moves assets to an external address that the customer controls or to another service selected by the customer.

For most users, the sensible approach is to use Bitget’s official status information, protect account credentials, and verify each transfer carefully after withdrawals reopen. Customers with an urgent issue should use official support rather than relying on social media replies or third-party recovery offers.

FAQ

Did Bitget lose $387.5 million in the hack?

Yes, Bitget revised the total transferred to attacker-controlled addresses to approximately $387.5 million on September 25, 2026. Bitget says the revision added Zcash and TRON assets omitted from its initial accounting rather than identifying new transfers.

When do Bitcoin withdrawals restart on Bitget?

Bitget scheduled Bitcoin withdrawals to restart at 08:00 UTC on September 28, 2026. Customers should confirm the official withdrawal option is active before submitting a transfer.

Are ETH and USDT withdrawals restarting at the same time?

No, Bitget scheduled ETH withdrawals for September 29 and USDT withdrawals for September 30. Other tokens, fiat, and P2P services are scheduled to restart on October 2.

Do Bitget customers need to take action before withdrawals reopen?

No, Bitget says customers do not need to take action before the phased withdrawal rollout. Customers should still secure their accounts and avoid links or messages claiming to provide early recovery access.

Are Bitget cold wallets affected by the breach?

No, Bitget says its cold wallets remained secure during the incident. The exchange says the unauthorized transfers came from some hot wallets, which are used for online operational activity.

Share this guide
Facebook
X
LinkedIn
Written by
Priya Sharma is a cybersecurity analyst and tech writer who covers digital privacy, online safety, and creative technology tools. She holds a CompTIA Security+ certification and writes about making security accessible for non-technical audiences. She’s passionate about the intersection of AI and creative work.

In this article

The AI Brief

Guides like this, every Friday.

One email. No hype cycle.

Keep reading