Saturday, October 3, 2026

The Business Is Gradually Back To Usual

Bitget's Protection Fund Back Above $300M as Withdrawals Resume — Full Restoration Set for Friday

 

Bitget's Protection Fund returns above $300 million after the September 24 hot wallet breach, with Proof of Reserves at 131%.

Key Takeaways:

  • Bitget's Protection Fund is back above $300 million, with 3,705 BTC in the fund wallet.

  • Proof of Reserves stands at 131% across 19 covered assets, with LINK, BTC, and ETH all above 110%.

  • BTC, ETH, and USDT withdrawals have resumed. P2P and all remaining assets open Friday at 8AM UTC.

  • The September 24 breach involved approximately $351.6 million in stolen assets.

  • The investigation into the attack, including a possible North Korea link, is still ongoing.


Bitget is closing in on full operational recovery after the September 24 security breach. On Wednesday, CEO Gracy Chen confirmed two critical milestones: the Protection Fund has been replenished above $300 million, and P2P withdrawals will resume Friday at 8:00 AM UTC alongside all remaining assets and fiat.

Protection Fund Replenished

Bitget fulfilled its commitment to restore the Protection Fund within a week of the incident. According to the exchange's official Protection Fund page, the fund is now valued at $309 million, with 3,705 BTC held in the fund wallet .

Chen stated: "Bitget Protection Fund back to >$300M as we promised."

Before the breach, the fund held $464 million. The exchange committed to replenishing it within a week, and the latest data shows that commitment has been met.

Withdrawals Resume in Phases

Bitget has been restoring withdrawal services step by step since the incident:

ServiceStatus
BTC WithdrawalsResumed Sept 28
ETH WithdrawalsResumed Sept 29
USDT WithdrawalsResumed Sept 30
P2P WithdrawalsFriday, Oct 2, 8AM UTC
All Remaining Assets + FiatFriday, Oct 2, 8AM UTC

Chen confirmed the schedule applies equally to all users — no priority access for institutions, VIP customers, or Bitget employees.

"P2P withdrawal starts on Friday UTC 8am, together with everything else," Chen posted Wednesday.

Proof of Reserves Remains Strong

Bitget published its 47th Proof of Reserves update on September 29, showing a total reserve ratio of 131% across all covered assets. The snapshot was taken at 17:00 UTC+8 on September 29, 2026 .

Individual asset ratios show that all covered assets remain above 100%:

AssetReserve Ratio
NEAR181%
USDGO169%
USDC154%
BTC142%
LINK137%
LTC131%
ETH110%
USDT107%

The exchange emphasized that the September 24 incident did not impact its reserves. PoR updates will continue monthly, as they have since December 2022.

What Happened on September 24

Attackers moved approximately $351.6 million in assets from Bitget's hot and warm wallets. The stolen assets included ETH, XRP, BNB, AVAX, USDT, and USDC across multiple blockchains.

Chen said the attacker compromised a critical backend system within the wallet infrastructure, used it to spoof transaction data, and triggered the exchange's authorization process to move funds. Importantly, she stated that private keys were not compromised and cold wallets remained unaffected.

Bitget engaged cybersecurity firms Mandiant and SlowMist to assist with the investigation, alongside law enforcement agencies.

Investigation Continues

Chen has said the attack method is "highly consistent with known patterns of North Korean hacker organizations," citing IP behavior patterns and on-chain analysis.

Blockchain analytics firm Elliptic assessed the incident as "highly likely" linked to North Korea, noting infrastructure overlaps with previous DPRK-attributed exploits including the 2025 Bybit hack. TRM Labs similarly pointed to on-chain links with previously identified North Korean thefts.

The Bitget incident pushed Elliptic's tracked total of DPRK-attributed crypto theft in 2026 past $1 billion.

However, definitive attribution has not been publicly confirmed. Bitget's initial security notice said the company would not speculate on the attack vector until the investigation was complete.

What This Means for Bitget Users

For users, the immediate concern — access to funds — is nearly resolved. By Friday, all withdrawal channels will be operational.

The bigger question is trust. Bitget's rapid response — replenishing the Protection Fund, resuming withdrawals in phases, and maintaining 131% PoR — has been faster than some peers in similar situations.

But the incident also highlights a broader issue: the September 24 breach was not a private key theft. It was a backend compromise that manipulated the exchange's own authorization systems. That's a different kind of failure, and it raises questions about operational security that go beyond cold storage.

Frequently Asked Questions

Is Bitget's Protection Fund fully replenished?
Yes. It's back above $300 million, with the official page showing $309 million and 3,705 BTC in the fund wallet.

When will all withdrawals resume?
P2P, all remaining assets, and fiat withdrawals open Friday, October 2, at 8:00 AM UTC.

What is Bitget's Proof of Reserves ratio?
131% as of the September 29 snapshot, covering 19 assets. All covered assets are above 100%.

Was North Korea behind the attack?
Multiple analytics firms have assessed it as "highly likely" linked to DPRK, but definitive attribution has not been publicly confirmed.

What was the attack method?
A backend system compromise that allowed the attacker to spoof transaction data and trigger Bitget's authorization process. Private keys were not compromised.

Bottom line: Bitget is nearly back to full operations. The Protection Fund is replenished, Proof of Reserves is above 131%, and withdrawals resume fully on Friday. The exchange moved quickly to stabilize — but the North Korea investigation continues, and the backend compromise raises operational security questions that won't be resolved by a fund balance alone.