Bitget Resumes Bitcoin Withdrawals After $387.5 Million Heist, North Korean Hackers Suspected
Cryptocurrency exchange **Bitget** has begun to restore withdrawal services for Bitcoin following a significant security breach last week, which saw an estimated $387.5 million stolen from its hot and warm wallets. The incident, attributed to suspected North Korean state-sponsored hackers, prompted a temporary halt on all withdrawals as **Bitget** addressed the exploited vulnerability.

**Bitget** has announced the resumption of Bitcoin withdrawals, a critical step toward normalcy after a major security incident. The exchange had paused all withdrawals last Thursday when its systems detected unauthorized transfers, leading to the discovery of a substantial theft.
### The Breach and Its Aftermath
Initially, **Bitget** reported a loss of $351.6 million. However, subsequent on-chain analysis and transaction classification revised the total to $387.5 million transferred to attacker-controlled addresses. The breach impacted multiple assets across various chains, including Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base, affecting cryptocurrencies like ETH, XRP, BNB, AVAX, USDT, and USDC.
**Bitget** CEO **Gracy Chen** attributed the attack to North Korean hackers, citing on-chain analysis and IP behavior patterns. According to Chen, the attackers compromised a critical backend system within **Bitget**'s wallet infrastructure. This access allowed them to spoof transaction data, thereby triggering the exchange's authorization processes to move funds from compromised hot and warm wallets.
### Restoration Efforts and User Assurance
**Bitget** has confirmed that the exploited security vulnerability has been addressed. The exchange is now working to restore withdrawal services for all other supported assets and networks. The estimated schedule for resuming withdrawals includes:
* **ETH** (Ethereum, BSC, Arbitrum, Base, Optimism): September 29, 8:00 UTC
* **USDT** (Ethereum, BSC, Solana, Tron): September 30, 8:00 UTC
* Other tokens / Fiat / P2P assets: Starting October 2, 8:00 UTC
**Bitget** emphasizes that the temporary withdrawal pause was purely a security measure, assuring users that their account balances remain unaffected and that the **Bitget Protection Fund** covers the financial impact of this platform-wide incident. The company maintains that the incident is contained, and no further unauthorized transfers are possible, with trading and deposits continuing to operate.
### Recovery Bounty Program Launched
In an effort to retrieve the stolen funds, **Bitget** has launched a **Recovery Bounty Program**, offering a 5% reward for assistance in recovering or freezing the funds. This initiative aims to leverage the broader cybersecurity community and blockchain analytics experts to trace and secure the illicitly moved assets.
### North Korean Threat Actors: A Persistent Problem
This incident adds to a long list of cryptocurrency heists linked to North Korean state-sponsored threat groups. These groups have a documented history of targeting crypto exchanges and decentralized finance (DeFi) platforms, often to fund the nation's weapons programs. Notable past incidents include the theft of $1.5 billion from **Bybit**'s ETH cold wallet, marking it as the largest crypto heist ever recorded.
British blockchain analytics firm **Elliptic** estimated in February 2025 that North Korean hackers have stolen over $6 billion in crypto assets since 2017, highlighting the persistent and evolving threat they pose to the digital asset ecosystem.