Bitget Starts Phased Withdrawal Restart at 08:00 UTC
Bitget is scheduled to reopen Bitcoin withdrawals first today at 08:00 UTC, followed by Ether across supported networks on September 29, USDT on September 30, and other tokens, fiat and P2P services by October 2, per the exchange's published timeline and NewsBTC.
The confirmed loss figure now stands at approximately $387.5 million, up from the initial $351.6 million — a revision Bitget attributes to additional assets identified during transaction tracing, not a second wave of transfers. The exchange says the attack path has been identified and the underlying vulnerability remediated, with Mandiant and SlowMist participating in the investigation. A recovery bounty program pays a percentage of assets secured to parties whose voluntary actions directly result in funds being frozen or recovered, and some funds have already been frozen through coordination with industry partners. Blockchain Reporter and CryptoRank corroborate the schedule.
The restart is the first real-world test of Bitget's assurances that customer balances are intact and covered; the phased ordering is designed to manage liquidity without creating a fresh security event at the withdrawal layer.
THORChain Declines Bitget's Request to Block Attacker Addresses
Bitget CEO Gracy Chen publicly called on THORChain to refuse service to addresses linked to the hack, writing that "decentralization is a design principle, not a shield for facilitating known stolen funds," per Coinpedia — which reports the protocol declined the request.
The exchange pointed to precedent: after the Bybit hack, nearly $1.2 billion in stolen funds reportedly moved through THORChain, and Cointelegraph's Hodler's Digest notes the network is again a favored swap rail for attacker funds. Chain-analysis reporting indicates the Bitget attacker has also cycled holdings through Wasabi CoinJoin while keeping most of the stolen funds dormant, per BigGo Finance.
The standoff revives an unresolved question for cross-chain infrastructure: whether permissionless protocols can or should intervene against known-stolen funds, and who decides what "known" means when no court has ruled.
DarkMe RAT Campaign Targets Crypto Users With Plain Phishing
New research from Huntress documents a 2026 DarkMe campaign that abandoned zero-day exploits for simple phishing emails and image-themed links delivering multi-stage Visual Basic 6 loaders. Before deploying its final payload, the loader probes the infected machine for 329 installed applications — a list that includes cryptocurrency wallets, trading terminals, password managers and communication tools, per Help Net Security and IT Security Guru.
DarkMe — also tracked as DarkCasino and historically associated, with the usual attribution caveats, with the financially motivated Water Hydra group — has previously targeted forex traders, stock-trading forums, gambling platforms and cryptocurrency users. The shift from zero-days to plain phishing lowers the attackers' cost and raises the burden on users: the delivery vector is now an email attachment or link, not a software vulnerability, which makes mailbox-level suspicion the primary control. Defenders can hunt the documented rundll32.exe command-line indicator for early-stage detection.
TrustGrade tracks the security posture of platforms and protocols in digital assets. Verified trust data: trustgrade.ai.