Bitget Now Says $387.5 Million Walked Out. The Withdrawal Plan Is the Real Story
Bitget raised its confirmed hack loss from $351.6 million to about $387.5 million and laid out a staged withdrawal restart beginning September 28. The revised number matters less than the timetable, because the rollout is where users find out if the exchange's assurances hold up.
I noticed something in Bitget's latest update that most coverage skimmed past. The revised loss figure grabbed headlines, sure. But the withdrawal timetable tucked at the bottom of the exchange's statement is where the real story lives.
Here's what the filing actually says, and why it matters more than the headline number.
The Numbers Under the Hood
Bitget started the week with a $351.6 million estimate. The exchange now puts the figure at roughly $387.5 million. That's a $35.9 million revision in a matter of days, which is a big swing no matter how you slice it.
So is the new number a sign of sloppy bookkeeping or careful tracing? Bitget says it's the latter, that the increase reflects additional assets flagged during transaction tracing, not a second wave of unauthorized transfers. Notably, the affected assets span multiple networks: Ethereum and other EVM chains, XRP Ledger, Zcash and TRON. That's not one vulnerability on one chain. The key detail is the spread, because it tells you how deep the attacker got into Bitget's custody architecture.
The exchange says its security team has identified the attack path and the method used to bypass existing controls. It also says the underlying vulnerability has been remediated, which is a strong claim that only time and independent review will validate. Investigators from Mandiant and SlowMist are on the case. From a compliance standpoint, bringing in outside forensics is the right move, both for the investigation itself and for the post-mortem regulators will eventually want to see.
The Withdrawal Rollout
Withdrawals return in stages. Bitcoin first, on September 28. Ether across supported networks on September 29. USDT on September 30. Everything else, including fiat services and peer-to-peer withdrawals, by October 2.
Staging the restart isn't generosity. It's risk management, plain and simple. Flipping every switch at once invites a second exploit at the exact moment the exchange is most exposed and its users are watching most closely.
Bitget also launched a recovery bounty. Eligible parties whose voluntary actions directly freeze or recover funds can earn a percentage of whatever gets secured. Some funds have already been frozen through coordination with industry partners. That's a smart structure, because it turns random whitehats into an extended recovery team without paying anyone upfront.
What This Means for Users
Here's the thing about exchange breaches. The number gets the attention, but the recovery does the talking. Bitget says customer balances are intact and its protection arrangements cover the financial impact. That's a big promise. The next week tests whether it holds.
I'd watch three things. First, whether the staged rollout goes clean. Any hiccup on September 28 tells you the security work isn't finished. Second, how much of the $387.5 million actually gets recovered. Tracing funds is one skill. Clawing them back is another. Third, what the Mandiant and SlowMist reports say when they land, and whether Bitget publishes the findings in full.
The precedent here's important. If Bitget restores withdrawals on schedule and recovers meaningful assets, it sets a playbook for the next exchange that gets hit. If it doesn't, the trust problem shifts from Bitget to the wider sector, and regulators will notice.
So what should people actually do with this information? If you've funds on Bitget, the answer isn't panic. It's patience and paranoia in equal measure. Wait for September 28. Watch the first wave. And move what you can't afford to lose once withdrawals are live. That's not advice about Bitget specifically. It's just how you should treat any centralized exchange holding your coins.
Related Articles
Key Terms Explained
The first cryptocurrency, created in 2009 by the pseudonymous Satoshi Nakamoto.
A reward offered by crypto projects for completing specific tasks like finding bugs, writing code, or creating content.
Following the laws and regulations that apply to financial activities, including crypto.
Who holds and controls your crypto assets.