Crypto Exchange Bitget Hit with $387.5 Million Heist, Withdrawals Resume After Security Measures Implemented
Bitget, a cryptocurrency exchange, has confirmed that it has resumed Bitcoin withdrawals after a devastating heist in which hackers made off with over $350 million. The company suspended all withdrawals last week after its security systems flagged suspicious activity and discovered the breach.
The incident is believed to have been carried out by North Korean hackers, who exploited a vulnerability in Bitget’s backend system to spoof transaction data and trick the exchange into transferring funds from compromised hot and warm wallets. The attackers were able to steal $387.5 million, making it one of the largest crypto heists ever recorded.
Bitget CEO Gracy Chen attributed the breach to North Korean hackers, citing on-chain analysis and IP behavior patterns as evidence. This is not an isolated incident – North Korean state-sponsored threat groups have been linked to numerous major crypto thefts in recent years, including a 2022 attack on Bybit that saw $1.5 billion stolen from the exchange’s ETH cold wallet.
The severity of this incident highlights the importance of robust security measures for cryptocurrency exchanges. Bitget has acknowledged that it has addressed the security vulnerability exploited by the hackers and is working to restore withdrawal services for all supported assets and networks as soon as possible.
In a statement, Bitget noted that user account balances remain unaffected, and the company’s Protection Fund covers the financial impact of this platform-wide incident. The temporary withdrawal pause remains in place as a security measure, but trading and deposits continue uninterrupted.
As the crypto market continues to grow, it is clear that exchanges must prioritize security above all else. Bitget’s experience serves as a reminder that even with robust security measures in place, attacks can still occur – and that swift action and transparency are crucial in minimizing the damage.
For users of Bitget and other cryptocurrency exchanges, this incident underscores the importance of keeping software up to date, using strong passwords, and being cautious when interacting with unfamiliar websites or services. While the specific details of this attack may be complex, one thing is clear: security must be a top priority for all players in the crypto ecosystem.
Bitget has announced an estimated withdrawal resumption schedule, with ETH (Ethereum) withdrawals set to resume on September 29 at 8:00 UTC, followed by USDT (Ethereum) on September 30 at 8:00 UTC. Other tokens and fiat/P2P assets will be available starting October 2 at 8:00 UTC.
In light of this incident, it’s essential for users to remain vigilant and report any suspicious activity to their exchange providers immediately. Additionally, Bitget has launched a Recovery Bounty Program, offering bounties of up to 5% for helping to recover or freeze frozen funds – a clear indication that the company is committed to making things right.
As we continue to navigate the rapidly evolving world of cryptocurrency, it’s more crucial than ever for users and exchanges alike to prioritize security and transparency. By doing so, we can work together to build a safer and more secure ecosystem for all.
Source: Bleeping Computer — 2026-09-28