Bitget will begin restoring customer withdrawals on Sept. 28, starting with Bitcoin, following a four-day breach that moved approximately $387.5 million from portions of its wallet infrastructure.

The exchange detected unauthorized transfers from its hot wallets at 18:31 UTC on Sept. 24. Initial estimates placed affected funds at $351.6 million; Bitget revised the figure upward to $387.5 million on Sept. 25, making it the largest reported exchange hack of 2026.

Bitget's three-tier wallet structure contained the breach to its hot and warm wallet layers. Cold wallets remained secure. CEO Gracy Chen said the attacker breached a backend system and spoofed transaction data rather than stealing private keys. Attacker patterns were consistent with groups previously linked to North Korea, though attribution remains unconfirmed pending investigation.

This mechanism—transaction data spoofing without direct private key compromise—reveals a specific vulnerability. It implies a bypass of standard cryptographic security protocols through backend system manipulation, despite integrity of core key management. The ability to move assets without possessing keys suggests the exchange's authorization layer was circumvented at the infrastructure level.

Bitget paused withdrawals as a security measure while keeping deposits and trading open. The exchange asserted user account balances were unaffected and losses fell within its User Protection Fund, which held over $464 million at the time of the incident.

Mandiant and SlowMist are supporting the investigation. Bitget's internal teams are conducting validation checks across withdrawal infrastructure. Assets including XRP, Zcash, TRON and Avalanche are slated for restoration in the Oct. 2 batch, following earlier phases for Bitcoin and other major cryptocurrencies.

Chen will host a live session at 07:30 UTC on Sept. 28 to address incident details and the restoration process with the community.