Overview For anyone with a balance stuck on Bitget, only one question has mattered over the past six days: when can the money move. At 18:31 UTC on September 24, the exchange's security systems detectOverview For anyone with a balance stuck on Bitget, only one question has mattered over the past six days: when can the money move. At 18:31 UTC on September 24, the exchange's security systems detect

Bitget Resumes Withdrawals: Full Timeline for BTC, ETH, USDT & Major Crypto Assets

Overview

 
For anyone with a balance stuck on Bitget, only one question has mattered over the past six days: when can the money move. At 18:31 UTC on September 24, the exchange's security systems detected unauthorized transfers from some of its hot wallets, and withdrawals were suspended platform-wide. Trading and deposits kept running, but a closed withdrawal channel means a balance that looks intact on screen and cannot leave the venue.
 
That question now has a dated answer. Under the phased resumption notice Bitget published at 03:55 UTC on September 26, withdrawals reopen in four batches by coin and network: BTC from 08:00 UTC on September 28, ETH and its EVM networks from 08:00 UTC on September 29, USDT across four chains from 08:00 UTC on September 30, and all remaining tokens, fiat and P2P from 08:00 UTC on October 2. The same notice states that the pause is a final security validation step unrelated to the availability of user assets, that user account balances remain unaffected, and that Bitget's Protection Fund covers the financial impact of the incident.
 
 

Key Takeaways

 
The timetable is public and the first three batches ran on time. BTC, ETH and USDT all reopened at the 08:00 UTC slots listed in the notice. The final batch, covering other tokens, fiat and P2P, is set for 08:00 UTC on October 2.
 
The loss figure was revised once. The initial estimate of roughly $351.6 million was later restated at roughly $387.5 million, with the difference coming from assets on Zcash and TRON that the first count omitted rather than from any new unauthorized transfer.
 
Account balances and platform reserves are separate questions. Bitget says user balances are accurate and unaffected, with the loss absorbed by its User Protection Fund, while its 47th Proof of Reserves, published September 30, shows a 131% composite ratio across 19 assets.
 
The attack path was not a stolen private key. Independent investigations by Mandiant and SlowMist both point to compromised third-party security products that ultimately enabled unauthorized access to the wallet environment.
 
A reopening window is a phishing window. Bitget has warned about accounts and links impersonating its official channels, and no legitimate support process asks for a password, a 2FA code or a seed phrase.
 

From 18:31 UTC to a Greyed-Out Withdraw Button

 

How the Incident Surfaced

 
According to the security notice Bitget published on September 24, its security systems detected unauthorized transfers from some hot wallets at 18:31 UTC that day, and the security team activated emergency response protocols immediately. The confirmed points included an estimated $351.6 million of affected funds, cold wallets remaining fully secure under a three-tier wallet architecture with the breach containing only part of the hot and warm wallet layers, and the loss falling inside the coverage of a User Protection Fund then holding more than $464 million.
 
The actions taken covered activating the emergency response team within minutes of detection, identifying, flagging and reporting the abnormal transfer addresses, suspending withdrawals as a precautionary measure pending security review, and formally notifying relevant authorities and on-chain security firms. Deposits and trading, the notice said, remained fully operational.
 

Why the Number Changed

 
The fund tracing and recovery bounty update published on September 25 revised the figure to approximately $387.5 million. Bitget explained that the revision reflects a more complete accounting of transfers during the incident, adding affected assets on Zcash and TRON that the initial estimate did not include, and that it does not represent further unauthorized transfers. The confirmed affected assets span XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX and TRX across Ethereum and several EVM networks, the XRP Ledger, Zcash and TRON. Decrypt reported that the single largest component was roughly 103 million XRP worth about $157 million.
 
On method, CoinDesk reported CEO Gracy Chen's account that the attacker compromised a critical backend system within the wallet infrastructure, used it to spoof transaction data and triggered transfers, with private key compromise ruled out. She described it as the digital equivalent of pushing forged withdrawal slips through a bank's own teller window.
 

The Full Phased Withdrawal Timetable

 
Bitget's schedule opens withdrawals by coin and network. All times are Coordinated Universal Time.
 
Date and time (UTC)
Coin
Network
September 28, 08:00
BTC
Bitcoin
September 29, 08:00
ETH
Ethereum, BSC, Arbitrum, Base, Optimism
September 30, 08:00
USDT
Ethereum, BSC, Solana, Tron
October 2, 08:00
Other tokens, fiat, P2P
Not applicable
 

Bitcoin First, September 28

 
BTC withdrawals on the Bitcoin network reopened at 08:00 UTC on September 28, the first of the four batches. Half an hour earlier, Gracy Chen held a live AMA at 07:30 UTC covering the incident, the restoration and next steps. Invezz reported that as of 09:00 UTC on September 28, Bitget had processed 9,585 BTC withdrawals totaling approximately 4,098 BTC.
 

ETH and the EVM Networks, September 29

 
The second batch covered ETH on Ethereum mainnet plus BSC, Arbitrum, Base and Optimism, opening at 08:00 UTC on September 29. The distinction worth holding onto is that this batch released the ETH coin across those five networks, not every token that lives on them. Holders of ERC-20 or BEP-20 tokens fall into the final batch.
 

USDT Across Four Chains, September 30

 
USDT withdrawals reopened at 08:00 UTC on September 30 across Ethereum, BSC, Solana and Tron. This is the batch that touches the widest user base, because stablecoin balances are typically the largest line in an exchange account. The notice lists no USDT networks beyond those four, so anyone holding USDT elsewhere should work to the October 2 slot or check the live status shown on the platform.
 

Other Tokens, Fiat and P2P, October 2

 
The final batch is scheduled for 08:00 UTC on October 2 and covers all remaining tokens, fiat rails and P2P services. Bitget states that the phased rollout is intended to restore withdrawal services in an orderly manner, that the same approach applies consistently across users without preference, and that the objective is to resume withdrawals across all supported assets and networks as quickly and safely as possible. Users need take no action ahead of each stage, since availability is reflected directly in the platform interface.
 

Balances, the Protection Fund and Proof of Reserves

 
Three numbers get conflated in most coverage, and they describe different things.
 
The first is the user account balance. Both the security notice and the resumption notice state that user account balances remain accurate and unaffected, with the financial impact of this platform-wide incident covered by the Protection Fund. What left the building was the exchange's own hot and warm wallet inventory, not a deduction from individual accounts.
 
The second is the User Protection Fund. The incident notice put it at more than $464 million. It is the exchange's own risk reserve, intended for platform-wide events not attributable to a user's own actions, with claims assessed by Bitget, and it is legally distinct from bank deposit insurance. The fund is denominated in BTC and valued daily on its public page, so its dollar figure moves with the bitcoin price.
 
The third is proof of reserves. TechFlow reported that Bitget published its 47th Proof of Reserves on September 30, showing a 131% composite ratio across 19 assets, with BTC at 142%, ETH at 110%, USDT at 107% and USDC at 154%. The prior Issue No. 46 report recorded 135% after coverage expanded from four assets to 19. A proof of reserves is a point-in-time snapshot comparing assets held against balances owed. It is not a full audit, and it says nothing about the solvency of the Protection Fund.
 
On what happened once the gates opened, The Crypto Times, citing Bloomberg data, reported net outflows of about $463 million in the 24 hours into September 29. That figure measures customer behavior after the reopening, which is a different question from reserve coverage.
 

Forensics and the Recovery Effort

 

The Mandiant and SlowMist Reports

 
On September 30, Bitget published an update on the SlowMist and Mandiant reports. Mandiant, part of Google Cloud, and SlowMist conducted independent investigations into the September 24 incident, and both reports are now public, with SlowMist's investigation progress report in its knowledge base and Mandiant's status update hosted by Bitget.
 
The notice says the findings broadly align with the attack path Bitget previously disclosed and that both investigations identified the compromise of third-party security products that ultimately enabled unauthorized access to Bitget Exchange's wallet environment. For users, the practical meaning is that this sits in the supply chain and the internal authorization path rather than on the customer side, so changing a password or a device neither explains the incident nor affects its cause.
 

Bounties and Frozen Assets

 
The September 25 update launched a Recovery Bounty Program offering 5% of successfully frozen funds and 5% of successfully recovered funds to the eligible person or entity whose voluntary efforts directly produced that outcome, with actions taken under court orders, law-enforcement requests or other legal processes excluded. Bitget said it will use Bybit's LazarusBounty initiative as a core channel supporting the effort, and it opened a live tracing dashboard and a reporting portal for exchanges, stablecoin issuers, bridges, blockchain projects and custodians to monitor the identified addresses.
 
Issuers have already acted. crypto.news reported that Circle and Tether had frozen approximately 99,990 USDC and 218,023 USDT linked to the attack by September 26.
 

Where Attribution Actually Stands

 
No government attribution has been issued. Gracy Chen linked the incident to North Korea-linked groups during a livestream, citing IP patterns and on-chain behavior. Blockchain analytics firm Elliptic assessed the attack as highly likely DPRK-linked, pointing to connections between the stolen XRP and ether from a previously DPRK-attributed exploit and to addresses involved in laundering the 2025 Bybit theft. The Hacker News reported Elliptic's observation that shared laundering infrastructure across incidents is a recurring feature of DPRK-attributed cases. TRM Labs has flagged multiple on-chain overlaps pointing to TraderTraitor while stopping short of definitive attribution and noting that another actor remains technically possible. Until an official finding lands, these are analytical assessments rather than settled facts.
 

What to Do Once Your Window Opens

 

Phishing Peaks Exactly Now

 
When an exchange is in the news cycle, impersonation accounts, fake reopening links and urgent direct messages multiply. Bitget used its official account on September 25 to warn users about accounts impersonating its channels and about suspicious links, and it maintains an official channel verification page where a handle or URL can be checked before anyone interacts with it. One boundary is worth memorizing: no legitimate support process asks for a login password, a two-factor code or a wallet seed phrase, and none asks a customer to send crypto in order to verify an account. Search advertisements and browser pop-ups are common entry points for imitation pages, so a bookmark or the official app beats a search result.
 

Match the Coin and the Network on Both Sides

 
A phased restoration means availability is determined by a coin-and-network pair, not by a single on-off switch. If a network has not yet appeared in an opened batch, forcing the attempt only produces a failure or a pending state. Before sending, confirm that the withdrawal network matches the deposit network shown by the receiving platform. This trips people up most often on stablecoins, because the same USDT exists on several chains and a wrong-chain transfer usually requires manual recovery. Assets such as XRP, XLM and ATOM need a memo or destination tag, and a transfer without one lands in a support ticket. For the network traps specifically, this walkthrough on moving crypto off Bitget without losing it on the wrong chain breaks down each checkpoint.
 

Send a Test Amount, Then the Balance

 
In the hours right after a channel reopens, system load and risk controls may not behave as they normally do. Send the minimum first, wait for it to credit, then move the rest. A few dollars of network fee buys certainty against a wrong-chain transfer. Funds sitting in Earn products, locked subscriptions or open futures positions cannot be withdrawn directly and need to be redeemed or closed first, which is where most delayed transfers actually stall.
 
Rather than refreshing the page while the last batch clears, the two days are better spent getting the destination account ready. This breakdown of what 0.10% actually costs over a year answers the switching question with numbers instead of sentiment
 
For a line-by-line comparison of fees, copy trading, leverage and US equity products across the two venues, this MEXC versus Bitget head-to-head runs the dimensions side by side, and for a full scorecard on Bitget itself, this six-dimension review sets out both its strengths and its gaps. Wherever the balance ends up, whether on MEXC or elsewhere, the criteria should be reserve disclosure, incident history and the way the account is actually used, not the news cycle of a given week.
 

What to Watch Next

 
The nearest fixed marker is 08:00 UTC on October 2, when remaining tokens, fiat and P2P are due to reopen. It is the broadest batch, it involves the most counterparties, and fiat and P2P depend on banking and third-party payment rails, which makes it the most likely candidate for partial delay. Whether it lands on time and in full says more about the state of the underlying infrastructure than the first three batches did.
 
The second is the Protection Fund. Against the more than $464 million disclosed in the incident notice, absorbing roughly $387.5 million leaves a visibly thinner buffer, and because the fund is denominated in BTC its dollar value will also move with the market. How it is replenished, and whether a replenishment plan is published, is a direct read on the platform's capacity to absorb a second event.
 
The third is recovery progress. The combination of a bounty program, issuer freezes and a public tracing dashboard has been run before, most recently after Bybit, and recovery rates in such cases typically sit far below the total stolen. Any subsequent freeze or recovery announcement should be read against the attacker addresses and amounts already published.
 
The fourth is the full incident report. Mandiant and SlowMist have named compromised third-party security products as the enabling factor, but the products themselves have not been identified publicly. If that detail is disclosed, the relevance extends beyond one exchange, because tooling of that kind is usually deployed across many institutions at once.
 
On scenarios, the constructive case is a full restoration on October 2, outflows balancing within days and reserve coverage holding above 100%, leaving the episode as an expensive but competently handled incident. The neutral case is full restoration alongside persistent outflows, with the platform absorbing a trust discount over a longer period. The tail case that deserves attention is a later finding of larger exposure, or the same third-party weakness reaching other venues, at which point the market's focus shifts from one exchange to the sector's supply chain.
 

Exclusive View from James Mitchell

 
For James Mitchell, the part of this episode worth remembering is not the headline loss but the fact that a timetable was published and then honored batch by batch. When an exchange is breached, what frightens users most is rarely the absolute number; it is the information vacuum. The four-stage schedule released at 03:55 UTC on September 26 converted open-ended uncertainty into four verifiable timestamps, and the first three opening on schedule gave that commitment something markets could check. From a risk management standpoint, a timetable the public can audit line by line carries more information than any broad assurance that funds are safe.
 
Two misreadings are likely. The first is treating the reserve ratio, the Protection Fund and user balances as one fact. The 131% composite ratio describes assets against liabilities at a single moment, the $464 million-plus Protection Fund is the exchange's own risk reserve, and the statement that balances are unaffected is a commitment about ledger entries. The three differ in nature, scope and legal standing, and none implies the other two. The second is reading "no private key compromise" as a lower-risk finding. On the forensic account, the attacker entered through compromised third-party security products and spoofed transaction data to trigger authorization that looked legitimate. That path defeats the approval chain rather than the key material, and defending it is no easier than defending a key.
 
The variable most worth tracking from here is whether net outflows converge once every asset is unlocked. The $463 million single-day figure arrived at the moment a dammed queue cleared, which makes it a poor basis for extrapolation. The real signal comes in the week after October 2: outflows that fall away quickly, or turn positive, indicate users have filed the episode as a handled incident, while sustained outflows indicate a trust discount that takes longer to work off. Running alongside that, the recovery curve of the Protection Fund balance and the eventual naming of the compromised third-party product are the two disclosures that would most change the risk assessment.
 
The cross-market lesson pushes the industry's risk frontier outward by one layer. For several years, exchange security has been argued mostly in terms of key management and hot-versus-cold segregation. What this incident shares with Bybit is that the attack landed in the authorization and signing workflow rather than on the keys themselves. Once the defensive question moves from where the keys are kept to who can initiate a transfer and how many third parties sit on that chain, supply chain security becomes a dimension no serious exchange assessment can omit. For ordinary users, that means judging a venue on the speed and granularity of its disclosure after an event, alongside its reserve reports and protection fund, because that behavior often reveals more about governance than the incident itself.
 

FAQ

 

Are Bitget withdrawals working now?

 
Yes, but in batches by coin and network. BTC on the Bitcoin network reopened at 08:00 UTC on September 28, ETH on Ethereum, BSC, Arbitrum, Base and Optimism at 08:00 UTC on September 29, and USDT on Ethereum, BSC, Solana and Tron at 08:00 UTC on September 30. All remaining tokens, fiat and P2P are scheduled for 08:00 UTC on October 2. Live availability is reflected in the platform interface.
 

When can I withdraw USDT from Bitget?

 
Under the official schedule, USDT withdrawals reopened at 08:00 UTC on September 30 across Ethereum, BNB Smart Chain, Solana and Tron. The notice lists no other USDT networks, so a balance held on a different chain falls under the final batch at 08:00 UTC on October 2. Confirm that the withdrawal network matches the deposit network at the receiving end before sending.
 

Why were Bitget withdrawals suspended?

 
At 18:31 UTC on September 24, Bitget's security systems detected unauthorized transfers from some hot wallets, and withdrawals were suspended as a precautionary measure pending a security review. The exchange has stated that the pause allows it to complete final security validation and is not related to the availability of user assets. Deposits and trading continued throughout, and account balances were unaffected.
 

How much was lost, and will user balances be reduced?

 
Bitget has confirmed that assets equivalent to approximately $387.5 million were transferred to attacker-controlled addresses, revised up from an initial $351.6 million estimate after assets on Zcash and TRON were traced. The exchange states that user account balances remain accurate and unaffected, with the financial impact covered by its User Protection Fund, which held more than $464 million at the time of the notice.
 

Is the Protection Fund large enough to cover the loss?

 
On the disclosed figures, the fund at more than $464 million exceeds the roughly $387.5 million loss, so it covers the amount, though the remaining buffer is visibly thinner afterwards. The fund is denominated in BTC and valued on its public page, so its dollar figure moves with the bitcoin price. It is the exchange's own risk reserve with claims assessed by Bitget, and it is legally different from bank deposit insurance.
 

How did the attack happen?

 
Independent reports from Mandiant and SlowMist both identified the compromise of third-party security products that ultimately enabled unauthorized access to Bitget's wallet environment. Bitget's CEO had previously described an attacker compromising a critical backend system in the wallet infrastructure, spoofing transaction data and triggering transfers, with private key compromise ruled out. The specific product has not been named publicly.
 

Can the stolen funds be recovered?

 
Some affected assets have already been frozen through coordination with industry partners, and Circle and Tether had frozen roughly 99,990 USDC and 218,023 USDT by September 26. Bitget has launched a bounty offering 5% of funds successfully frozen and 5% of funds successfully recovered, and it publishes a live tracing dashboard. Judging by comparable incidents, final recovery rates usually sit well below the total stolen.
 

What scams should I watch for while withdrawals reopen?

 
Accounts impersonating official channels, fake reopening or refund pages, and unsolicited direct messages from people posing as support staff. Bitget has told users to verify any related account, message or link and offers an official verification page for that purpose. No official process asks for a login password, a two-factor code or a seed phrase, and any request to send crypto in order to verify an account is a scam. Reach the site through a bookmark or the official app rather than through search advertisements or pop-ups.
 

Disclaimer

 
The information above is provided for general information and factual context only and does not constitute investment advice, financial advice, legal advice, tax advice or a recommendation to trade. Prices of crypto assets and other related financial assets can fluctuate sharply, and past performance, technical indicators and on-chain data do not guarantee future results. The timetable, loss figures, reserve data and investigative conclusions cited here reflect public information available at the time of writing, the situation continues to develop, arrangements may change without notice, and live withdrawal status should be confirmed on the platform interface and official announcements. Readers should conduct their own research and make decisions based on their own financial circumstances, investment objectives and risk tolerance, consulting a qualified professional where appropriate. The MEXC Crypto Pulse team accepts no liability for any direct or indirect loss arising from the use of this information.
 

About the Author

 
James Mitchell specializes in technical analysis, market trends, and trading strategies for both Bitcoin and altcoins. Based in London, he has over 10 years of experience in financial markets. Before joining MEXC Learn, James worked as a senior analyst at a leading European investment firm, where he developed expertise in risk management and quantitative trading. His transition to cryptocurrency markets began in 2017, and he has since become recognized for his data-driven approach. He holds a Master's degree in Financial Economics from the London School of Economics. His analytical approach combines traditional technical analysis with on-chain metrics to provide readers with actionable insights.
 
Areas of Expertise: Technical Analysis, Market Trends & Cycles, Trading Strategies, Bitcoin & Altcoin Analysis, Risk Management.
 

Research References

 
 
Want the fastest access to MEXC's latest updates? Join our official Telegram group now!
Join MEXC Community: X (Twitter) | Telegram | Discord
Account Verification: Understand KYC | How to Complete KYC
External Content Platforms: Substack | Medium | Paragraph | LinkedIn | X(News)
Market Opportunity
Ethereum Logo
Ethereum Price(ETH)
$2,690.38
$2,690.38$2,690.38
USD

The articles shared on this page are sourced from public platforms and are provided for reference only. They do not represent the position or views of MEXC. All rights belong to James Mitchell. If you believe any content infringes upon the rights of a third party, please contact service@support.mexc.com for prompt removal. MEXC does not guarantee the accuracy, completeness, or timeliness of any content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be interpreted as a recommendation or endorsement by MEXC. For expert insights and in-depth analysis, visit MEXC Learn.