SPONSORED PARTNERMEXCExplore global spot and futures marketsEXPLORE MEXC →
CHARTING PARTNERTradingViewAdvanced charts, indicators and market analysisOPEN CHARTS →
TRADING PARTNERGMX via NetNapz TradeTrade decentralised perpetual marketsSTART TRADING →Bitget Raises Security-Incident Estimate to $387.5M and Sets Phased Withdrawals

Bitget has raised its confirmed affected-assets estimate from $351.6 million to approximately $387.5 million after adding Zcash and TRON transfers to its accounting. The exchange says the revision does not represent a second theft, that the vulnerability has been remediated, and that withdrawals are scheduled to restart in phases beginning with Bitcoin at 08:00 UTC on September 28.
Updated September 28, 2026 at 05:45 UTC. The withdrawal timetable below is an announced schedule, not confirmation that each service is already live. NetNapz will treat actual on-platform availability and successful user withdrawals as the operational confirmation.
What changed since the first disclosure
Bitget’s September 25 follow-up says approximately $387.5 million in assets were transferred to attacker-controlled addresses. The earlier notice put the estimate at $351.6 million. According to the exchange, the $35.9 million increase reflects a more complete classification of transfers on Zcash and TRON and does not reflect additional unauthorized transfers after the incident was contained.
The confirmed affected assets span XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX and TRX across Ethereum and several EVM networks, XRP Ledger, Zcash and TRON. Bitget published primary receiving addresses for those networks and a live tracing dashboard for exchanges, issuers, bridges and security teams.
Bitget says the vulnerability is remediated
Bitget says its investigators identified the attack path and the method used to bypass existing controls, remediated the underlying vulnerability and concluded that no further unauthorized transfers are possible. Independent cybersecurity firms Mandiant and SlowMist are supporting the investigation, according to the company.
Those are material improvements from the initial notice, which did not identify a mechanism. They remain company statements rather than a public independent root-cause report. The exchange has not yet published enough technical detail for outsiders to reproduce the finding or evaluate every control change.
The initial statement continues to say that cold wallets were unaffected and that the loss falls within the coverage of Bitget’s User Protection Fund, which it valued at more than $464 million. Customer balances, deposits and trading were reported as unaffected while withdrawals remained paused.
Withdrawal restoration is staged across four dates
Bitget’s published schedule starts with BTC withdrawals on Bitcoin at 08:00 UTC on September 28. ETH withdrawals on Ethereum, BNB Smart Chain, Arbitrum, Base and Optimism are scheduled for September 29 at 08:00 UTC. USDT withdrawals on Ethereum, BNB Smart Chain, Solana and Tron are scheduled for September 30 at 08:00 UTC. Other tokens, fiat and peer-to-peer services are scheduled for October 2 at 08:00 UTC.
A phased restart reduces the number of systems exposed at once, but it also means “withdrawals resumed” should not be treated as a single binary event. Traders should check the specific asset and network they intend to use. Availability for BTC would not confirm that Ethereum, stablecoin, fiat or P2P rails have passed their later milestones.
Tracing and recovery have become the next test
Bitget has launched a recovery bounty programme offering 5% of funds successfully frozen and 5% of funds successfully recovered to eligible parties whose voluntary actions directly caused that result. Actions performed under court orders, law-enforcement requests or other legal processes are excluded. The company also says some assets have already been frozen through coordination with industry partners, although the follow-up does not publish a total recovery figure.
Specialist reporting based on MistTrack data says a small portion of the stolen assets was routed through THORChain and converted into native Bitcoin. THORChain’s response, as reported on September 27, emphasized that it operates as a permissionless network comparable to Bitcoin, Ethereum and BNB Chain. NetNapz has not independently verified the reported routing total, so it should not be read as a confirmed recovery shortfall or as proof that THORChain controlled the attacker.
The episode nevertheless highlights a real enforcement boundary: issuers and centralized venues can freeze some assets or accounts, while permissionless base-layer and cross-chain protocols may have neither the governance consensus nor the technical controls to block an address. That difference can materially affect the recoverability of stolen funds.
Why this matters for customers and traders
The revised estimate increases the scale of the incident by about 10% from the initial figure. More importantly, the operational risk is now measurable against dated milestones. A smooth BTC restart followed by ETH, USDT and the remaining services would support Bitget’s claim that the vulnerability is contained and its withdrawal infrastructure is safe. Delays, additional pauses or restrictions would weaken that assessment even if trading continues normally.
This is primarily an exchange-counterparty and market-infrastructure event, not automatically a directional signal for Bitcoin or Ether. Broad-market implications would strengthen only if the investigation exposes a shared vendor or wallet-control weakness, if other venues report related activity, or if prolonged withdrawal restrictions create visible liquidity stress.
NetNapz assessment
Base case: the incident remains contained, and services return in stages while tracing and reimbursement work continue. The published timetable gives customers concrete checkpoints that were missing from the first notice.
Bull case: each withdrawal phase opens on schedule, users complete withdrawals without material restrictions, the protection fund absorbs the loss as stated, and Bitget publishes a credible independent root-cause review with verifiable remediation.
Bear case: scheduled phases slip, withdrawal limits persist, the affected-assets estimate rises again, or evidence shows that the same weakness exists elsewhere in the exchange’s infrastructure or at another venue.
Confirmation: successful public withdrawals on the listed assets and networks, a quantified record of frozen or recovered funds, and a detailed post-incident report supported by the outside investigators.
Invalidation: new unauthorized transfers, a reversal of the containment claim, inability to honor customer withdrawals, or evidence that protection-fund coverage is insufficient or unavailable.
What to watch next
The first checkpoint is BTC withdrawal availability after 08:00 UTC on September 28. The following checkpoints are ETH on September 29, USDT on September 30, and remaining token, fiat and P2P services on October 2. Beyond operations, the decisive evidence will be the promised root-cause report, a verified tally of frozen and recovered assets, and proof that affected customers remain whole.
Sources
Bitget — initial security notice, September 24, 2026
Bitget — fund tracing, revised estimate and recovery bounty, September 25, 2026
Bitget — phased withdrawal schedule, September 26, 2026
The Block — corroborating report on the revised estimate
RootData — reported THORChain response, September 27, 2026
NetNapz provides news, market monitoring and scenario analysis, not personalised financial advice.
