Bitget Resumes Bitcoin Withdrawals Following Massive $387.5 Million North Korean Cyber Heist

Major cryptocurrency exchange Bitget has officially recommenced Bitcoin withdrawals following a temporary, platform-wide halt implemented last week. The suspension was triggered when security systems detected a sophisticated cyberattack that drained hundreds of millions of dollars from the exchange’s infrastructure. According to updated blockchain forensics, state-sponsored actors—identified through behavioral patterns and on-chain analysis as North Korean hackers—siphoned a staggering $387.5 million in digital assets from the platform’s hot and warm wallets.
While Bitcoin transactions are now flowing again, the exchange is rolling out remaining asset classes through a phased timeline to ensure absolute system integrity. The incident highlights the enduring vulnerability of centralized financial platforms to advanced persistent threat (APT) groups, placing the spotlight once again on the staggering scale of state-backed cryptocurrency theft.
Phased Restoration of Withdrawal Services
In an official statement released following the initial breach, Bitget management confirmed that the critical security vulnerability exploited during the attack has been fully patched. To prevent secondary exploits and ensure the underlying architecture remains stable under load, the company structured a careful, staged rollout for restoring withdrawal capabilities across various supported blockchains and fiat gateways.
According to the published schedule, Bitcoin (BTC) withdrawals were the first to go live. This was followed by Ethereum and associated layer-2 networks—including Arbitrum, Base, and Optimism, alongside Binance Smart Chain (BSC)—which reopened on September 29 at 8:00 UTC. The next phase targets high-volume stablecoins, with USDT withdrawals across Ethereum, BSC, Solana, and Tron scheduled for September 30 at 8:00 UTC. Finally, remaining altcoins, fiat currencies, and peer-to-peer (P2P) assets are slated to return to normal operations starting October 2 at 8:00 UTC.
Bitget has consistently emphasized that the temporary withdrawal freeze was purely a precautionary containment measure and did not reflect an underlying insolvency or liquidity crisis. The company stressed that user account balances were entirely unaffected by the security breach. Furthermore, the platform announced that its dedicated Protection Fund will absorb the entirety of the financial impact, insulating individual account holders from direct loss. Core platform operations, including spot trading and deposits, remained fully functional throughout the ordeal.
Chronology of the Breach and Escalation
The sequence of events began late last week when automated security monitoring tools at Bitget flagged a series of anomalous, unauthorized transactions originating from a restricted subset of the exchange’s crypto wallets. Immediate internal investigations confirmed that malicious actors had successfully breached critical backend infrastructure connected to Bitget’s wallet management systems.
By manipulating transaction data, the attackers managed to bypass standard authorization checks, tricking the exchange’s protocols into approving massive outflows from hot and warm storage. Gracy Chen, Chief Executive Officer of Bitget, took to social media to provide transparency regarding the scope of the breach. Chen disclosed that the multi-chain assault impacted several prominent blockchain ecosystems, including Ethereum, the XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base. A diverse basket of cryptocurrencies was plundered, comprising ETH, XRP, BNB, AVAX, USDT, USDC, and various other tokens.
Initially, early estimates placed total losses at approximately $350 million. However, as independent blockchain analytics firms and internal investigators finalized their tracking, the figure was revised upward. On Friday, following comprehensive on-chain tracing and transaction classification, Bitget updated the official tally to $387.5 million, with the stolen funds actively tracked across numerous attacker-controlled addresses.
Attribution and the North Korean Threat Nexus

In the wake of the breach, cybersecurity researchers and exchange executives quickly turned their attention to external threat actors. CEO Gracy Chen explicitly pointed the finger at North Korean state-sponsored hackers, citing distinct behavioral patterns in the attackers’ Internet Protocol (IP) usage, transaction timing, and sophisticated laundering techniques.
This attribution aligns with a well-documented global pattern of cyber warfare and financial crime. Over the past decade, North Korean threat groups—most notably the notorious Lazarus Group and associated syndicates—have systematically targeted the cryptocurrency sector to bypass international economic sanctions and fund the regime’s state priorities. These actors have evolved from basic ransomware operators and bank-robbing digital crews into highly specialized financial threat actors capable of executing complex supply-chain attacks, social engineering campaigns against blockchain developers, and direct infrastructure compromises.
The scale of these operations is historic. Bitget’s $387.5 million loss, while catastrophic for a single corporate entity, sits within a broader campaign of state-sponsored digital heists. In recent years, North Korean hackers have been linked to some of the largest cryptocurrency thefts in history, including the record-breaking $1.5 billion heist targeting Bybit’s Ethereum cold wallet earlier in the decade. Comprehensive data compiled by British blockchain analytics firm Elliptic in early 2025 indicated that North Korean threat actors have collectively stolen upwards of $6 billion in cryptocurrency assets since 2017.
Mitigation, Recovery Efforts, and Bounty Programs
In response to the unprecedented financial drain, Bitget launched an aggressive counter-offensive aimed at tracking, freezing, and recovering the stolen funds. Recognizing that on-chain movements can be monitored in real-time, the exchange partnered with prominent blockchain intelligence and security firms to blacklist addresses linked to the attackers and alert major centralized exchanges worldwide to freeze incoming tainted deposits.
Additionally, Bitget introduced a specialized Recovery Bounty Program. The initiative offers a lucrative 5% bounty to independent security researchers, ethical hackers, and blockchain investigators who successfully provide actionable intelligence leading to the recovery or freezing of the stolen assets. By crowdsourcing investigative talent, the exchange hopes to pressure the hackers and limit their ability to cash out the funds through decentralized exchanges, cross-chain bridges, or over-the-counter (OTC) brokers.
Broader Implications for the Cryptocurrency Industry
The Bitget security incident serves as a stark reminder of the persistent and evolving risks inherent in centralized cryptocurrency exchanges. Despite the implementation of multi-signature architectures, hardware security modules (HSMs), and rigorous internal controls, threat actors backed by nation-state resources continue to find novel vectors of attack. By targeting backend infrastructure rather than direct cryptographic keys, modern hackers can subvert the operational logic of exchange wallets from the inside out.
For the wider digital asset ecosystem, the breach underscores the urgent need for enhanced cross-industry collaboration. As blockchain forensics become more sophisticated, tracing stolen funds has grown faster and more accurate, but the challenge of recovering assets once they enter privacy-enhancing mixers or cross-chain protocols remains immense.
Regulatory bodies and industry associations are likely to face renewed pressure to mandate stricter security baselines for custodial platforms, potentially introducing standardized auditing frameworks for backend wallet infrastructure. In the interim, exchanges will need to accelerate their adoption of zero-trust security models, real-time behavioral monitoring, and decentralized custody solutions to mitigate the risk of catastrophic single-point-of-failure breaches.
As Bitget completes the final phases of its withdrawal restoration schedule, the focus will inevitably shift toward the long-term forensic investigation and the ongoing efforts of the global security community to neutralize the financial networks of state-sponsored cybercrime syndicates.







