Bitget has settled the size of its September 24 breach at approximately $387.5 million in affected assets, up from the roughly $351.6 million first reported, and published a schedule for reopening withdrawals in phases from September 28 at 08:00 UTC, with full restoration expected by October 2 at 08:00 UTC.

The timeline appears in the exchange's withdrawal service update and a detailed official announcement. The incident began at 18:31 UTC on September 24, when Bitget detected unauthorized transfers out of its hot and warm wallets; cold wallets were not affected.

Where the Money Went

On-chain breakdowns of the theft show XRP was the largest single portion, at around $157.5 million, with the remainder spread across Ether, Tether's USDt, Zcash, USDC, USDT0, Tether Gold, BNB, AVAX and TRX, per Lookonchain data cited by CoinCentral.

Blockchain analytics firm Bitquery, in an on-chain investigation of the laundering trail, reports that stolen BNB and TRX have already been consolidated and swapped into roughly 126.71 BTC. Bitquery also notes the attacker's main Ethereum wallet received funds on September 26 from a wallet that had been funded the day before through five withdrawals from Binance — an operational detail investigators will scrutinize as the case develops.

What Bitget Says Happened

Bitget has attributed the incident to a compromise of a backend system connected to its withdrawal and transfer authorization flow, describing a spoofed-transfer technique that let attackers push fraudulent approvals through that pipeline, as CoinCentral and Startup Fortune report. The exchange says the underlying vulnerability has since been identified and remediated, and that security checks continue during the phased restart, per NewsBTC.

The restart sequence opens Bitcoin withdrawals first on September 28 at 08:00 UTC (16:00 Beijing time), followed by Ethereum, BSC, Arbitrum, Base and Optimism assets in later phases through October 2 — an 86-hour containment-and-recovery window from detection, as ChainCatcher lays out.

Attribution remains unconfirmed by law enforcement. TRM Labs previously assessed the laundering infrastructure as matching clusters linked to prior suspected North Korean operations including the Bybit and AFX Bridge thefts, and Elliptic has called the attackers likely North Korea-linked. Those assessments are analytic judgements, not official attributions. Stablecoin issuers Circle and Tether froze about $318,000 in a linked wallet, and Bitget has offered a bounty of 5% for voluntarily freezing attacker funds and 5% for voluntary recovery.

What to Watch

The first test comes Monday: whether phase-one Bitcoin withdrawals open on schedule and clear at normal latency, which would signal the rebuilt authorization path is holding. The October 2 full-service date is the second checkpoint. Until then, the $387.5 million figure makes this the largest exchange breach of 2026 and the event that pushed suspected North Korea-linked theft past the $1 billion mark for the year, according to Elliptic's tally.

TrustGrade tracks the security posture of exchanges and platforms in digital assets. Verified trust data: trustgrade.ai.