Skip to content
RESEARCH INDEX BREACHROAD / INTELLIGENCE NOTE

Bitget says $387.5 million reached attacker addresses as withdrawals return in phases

Bitget raised its estimate of transfers after the incident and published a withdrawal schedule. Here is what is known and how users can avoid follow-on scams.

PUBLIC RESEARCH
AUTHOR
/ CEO Breachroad · OSCP · PNPT
PUBLISHED
26 September 2026
READING TIME
10 min read
TOPIC
Threats and Incidents
Bitget says $387.5 million reached attacker addresses as withdrawals return in phases

Bitget says assets worth approximately $387.5 million were transferred to attacker-controlled addresses in the incident detected on 24 September. That is higher than the initial estimate of $351.6 million. The exchange says the increase comes from a more complete accounting of transfers, including assets on Zcash and TRON, rather than additional unauthorised activity.

On 26 September, the platform published a schedule for restoring withdrawals in phases. This is an important update for users, but it also creates a period of particular risk: criminals frequently exploit a real incident and people’s desire to regain access to funds by sending fake “verification,” “wallet migration” or expedited-unlocking instructions.

What Bitget confirms and what remains unknown

According to the company’s 25 September update, it identified the attack path and an underlying vulnerability, which it has remediated. Bitget says the incident is contained and no further unauthorised transfers are possible. External teams from Mandiant and SlowMist are supporting the investigation.

The confirmed value includes XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX and TRX across several networks. The company has also launched a bounty programme for actions that lead to funds being frozen or recovered and shared information for tracking the relevant addresses.

The public updates do not yet provide a complete root-cause report that would allow independent assessment of every security layer and the precise sequence of events. A particular threat group should not be blamed merely on the basis of social-media speculation.

Withdrawal schedule as of 26 September

Bitget says withdrawals will return in phases:

  • BTC on Bitcoin — 28 September at 08:00 UTC,
  • ETH on Ethereum, BSC, Arbitrum, Base and Optimism — 29 September at 08:00 UTC,
  • USDT on Ethereum, BSC, Solana and Tron — 30 September at 08:00 UTC,
  • other tokens and fiat and P2P channels — 2 October at 08:00 UTC.

The company says user balances remain unaffected and its Protection Fund covers the financial impact of the incident. Those are Bitget’s statements, not an independent Breachroad guarantee. Users should check availability after signing in through the official app or a manually entered domain because the schedule may be updated.

What users should not do

Do not move assets to an address received through a direct message, comment or advertisement. A genuine notice about phased withdrawals does not require a “technical safety wallet,” an unlocking deposit or disclosure of a seed phrase.

Do not install remote-support software or share your screen with someone claiming to represent support. Do not follow a link to a “priority withdrawal queue.” Open the app yourself and check its notification centre. If you use a bookmark, ensure it predates the incident and points to the correct domain.

Do not make a series of panicked security changes without a plan. If the account shows no unknown activity, begin by reviewing sign-in history, API keys, devices, withdrawal addresses and authentication settings. Change credentials where exposure is possible, but never enter the new password on a page reached through a message.

A sensible checklist before the first withdrawal

Sign in through the official app or a domain you opened yourself. Verify the balance, transaction history and notices shown inside the account. Review active sessions and devices, remove anything unrecognised, and check that no unknown API key or trusted address has been added.

Where available, multi-factor authentication should use a method resistant to phone-number takeover. Keep recovery codes outside the mailbox and do not store them with the password.

Before a large withdrawal, make a small test transfer and verify both the network and full address on a trusted device. A small test does not protect against clipboard replacement during the next transaction, so check the address every time. Do not rush merely because withdrawals have just reopened.

What businesses using the exchange should review

An organisation should identify every account, wallet and API key connected to Bitget, who can authorise withdrawals and which automated processes have stopped. If the schedule affects liquidity, obligations or hedging, the decision needs a business owner rather than being left solely to an account administrator.

Separate three questions: was the organisation’s account taken over, were platform assets involved in the incident and does the business have enough access to funds when required? A correct displayed balance does not solve an availability problem, while a temporary withdrawal pause does not prove that the customer’s account was compromised.

After services return, review permissions, address restrictions, API keys, the approval workflow and compliance with the asset-custody policy. The incident is also a reason to reconsider how much must remain continuously on a trading platform.

Source facts and Breachroad’s conclusions

In its 25 September update, Bitget confirms the approximately $387.5 million figure, remediation of the identified vulnerability, work with Mandiant and SlowMist, and asset-tracing measures. Its 26 September notice provides the phased withdrawal schedule and statements about balances and the Protection Fund. The investigation and tracing remain in progress, and the figures may change.

The safe-action checklist, separation of account risk from platform risk, and business recommendations are Breachroad’s conclusions. They are not investment advice or a guarantee of recovery. Our analysis of the Bybit heist gives context from a similar event, while our guide to recovery scams warns about people promising to recover lost funds. Staff with access to financial systems and wallets should be included in cybersecurity awareness training.

SHARE / COPY