Hacked crypto exchange Bitget recorded roughly $463 million in net outflows in the 24 hours into Tuesday, as customers moved assets off the platform following last week’s $388 million theft.
The surge came after Bitget began restoring withdrawals and marked the largest one-day net outflow since data aggregator DefiLlama began tracking proof-of-reserves four years ago. The exchange currently holds about $5.7 billion in reserves.
Bitget is reopening withdrawals in stages, starting with Bitcoin on Monday, followed by Ether and USDT. Withdrawals of other tokens, along with fiat and peer-to-peer services, are set to resume Oct. 2, Bitget said in a post on its website. The staggered rollout was a security measure “unrelated to the sufficiency or availability of user assets,” the company said.
Related: Agentic Intelligence for Claims Dominates New Tech Launches
The exodus is another blow to the exchange ā among the world’s top 10 by trading volume ā as it seeks to recover from a hack that cybersecurity experts have said was likely linked to North Korea. Tuesday’s outflows represent more than 10% of its current reserves.
The $464 million user protection fund Bitget had cited to assure customers their funds were safe has now fallen below $200 million, according to the three wallet addresses that Bitget cites as the source of the funds.
“The Protection Fund is being used to absorb the financial impact of the incident,” Bitget Chief Executive Officer Gracy Chen said in an emailed response to Bloomberg. “Bitget will replenish the Fund using its own capital, with the Fund targeted to be above $300 million within one week.”
The Timeline
Chen said she “immediately got involved with the team” after waking up around the time of the hack at 2:30 a.m. in Singapore.
The attacker exploited a vulnerability in a security product supplied by a third party to obtain internal credentials, which were used to send fraudulent withdrawal commands to Bitget’s wallet system, according to Chen. Those commands bypassed existing risk controls, resulting in abnormal transfers.
Bitget has begun the phased resumption of withdrawals following the security incident identified on September 24, with BTC withdrawals on the Bitcoin network started at 08:00 UTC on September 28 as scheduled.
The resumption follows additional security work across Bitget’sā¦
ā Bitget (@bitget) September 28, 2026
The breach was confined to portions of hot-wallet and warm-wallet infrastructure, according to Chen. A subsequent investigation found that no private keys or cold wallets were compromised, she added. Hot wallets stay online for frequent transactions, cold wallets stay offline for maximum security, while warm wallets sit in between.
The Investigation
In addition to working to replenish the funds, the exchange is working with Google’s Mandiant and blockchain-security firm SlowMist to continue to investigate the hack.
While Chen initially pointed to signs of North Korean involvement, a link that outside researchers have now also made, she was cautious about making a final conclusion at this stage.
“What I shared previously was based on preliminary indicators identified during the investigation,” she said. “Those indicators are still being assessed and should not be treated as a definitive attribution.”
Top photo: Bitget is reopening withdrawals in stages, starting with Bitcoin, followed by Ether and USDT. Bloomberg.
Was this article valuable?
Here are more articles you may enjoy.


Apollo’s Rowan Blasts Regulators for Handling of Walter Insurers
DoorDash to Pay $132 Million in NYC Over Missing Wages
Public Adjuster Coalition Unveils Ethics Code, Plans Complaint Board
US Northeast Braces for Flooding as Coastal Storm Brews