Five days after the $387.5 million Bitget breach, the recovery math is bleak. Of the total drained from the exchange's hot wallets, less than $503,000 has been frozen anywhere in the world, TechTimes reported — and CEO Gracy Chen told users in a live Q&A that recovering the bulk of the roughly $388 million is unlikely, citing the precedent of the Bybit hack, per Cointelegraph.

The single recovery data point comes from NEAR Intents, a cross-chain bridge that says it intercepted more than $50 million in laundering flows tied to the attack — of which roughly $503,000 was actually frozen. More than 99 percent of what passed through that one chokepoint escaped. Bitget has launched a bounty program offering 5% on frozen funds and an additional 5% on anything recovered.

Withdrawals Resume in Stages

Ethereum withdrawals reopened September 29 at 08:00 UTC, the second stage of Bitget's phased restoration schedule. In the first hour, the exchange reported 9,674 ETH deposited against 9,023 withdrawn — a net inflow of roughly 651 ETH that Chen framed as a vote of user confidence. The figures are exchange-reported, not independently verified.

The more consequential test opened Wednesday at 08:00 UTC, when USDT withdrawals resumed across Ethereum, BNB Smart Chain, Solana and Tron. USDT is the dominant stablecoin for active trading and typically the first asset holders convert to when exiting a platform under stress. If Wednesday's USDT outflows significantly exceed inflows, solvency pressure on Bitget's Protection Fund will intensify beyond what the ETH data suggests. All remaining tokens, fiat withdrawals and peer-to-peer transfers are scheduled for October 2 at 08:00 UTC.

The Laundering Rails Stay Open

Cross-chain swap protocol THORChain, which has become the default laundering rail for large crypto thefts, declined to block attacker-linked addresses, citing its neutrality policy. TRM Labs has documented that THORChain consistently refused to block illicit activity tied to prior major hacks, including the $1.5 billion Bybit breach in February 2025 and the $300 million KelpDAO hack in April 2026.

Attribution remains suspected rather than confirmed. Elliptic assessed the attack as "highly likely" tied to North Korea based on on-chain connections between XRP taken from Bitget and ether from an earlier DPRK-attributed theft, and Chen said IP addresses traced to the hack matched VPN infrastructure previously used by suspected North Korean-linked groups, per Gizmodo. But no US law enforcement attribution has been issued, and Bitget has not published its technical attribution evidence. Mandiant and SlowMist continue independent forensic work.

The attack vector itself — a zero-day in a third-party security product used to extract internal admin credentials, then used to spoof transaction authorizations through a trusted channel, with no private keys compromised — is a category Bitget shares with SolarWinds-era supply-chain breaches. Exchanges can hold keys in cold storage and still be drained through the systems that authorize movements from it.

TrustGrade tracks the security posture of platforms and protocols in digital assets. Verified trust data: trustgrade.ai.