387.5 million dollars at Bitget: the attack ran through a bought-in security product, what to watch now
Bitget has disclosed how the attackers reached its withdrawal systems on September 24: through a previously unknown flaw in a security product it had bought in. The second stage of the withdrawal schedule opens today at 08:00 UTC, and for the balance you keep on any exchange the case changes the arithmetic.

Table of Contents
Table of Contents



Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
If you keep a balance on a centralised crypto exchange, the Bitget case has read differently since September 28. The exchange's own keys were not cracked, and no cold wallet was emptied. The attacker came in through a security product that Bitget itself had bought, and used that product's privileges to pose as an administrator. On the figures published so far, the damage lies between $387.5 million and $388 million. For you, that means the question of whether an exchange is well secured does not hang on its own technology alone, but on every supplier it lets inside its systems.
This article sets out the attack path, names the documented figures and the schedule under which withdrawals are restarting. It also says which parts of it touch a decision of your own, and which remain corporate news and nothing more.
What Bitget says about the attack path
On the company's account, the attacker exploited a zero-day vulnerability in a third-party security product. Zero-day means a flaw that the software maker did not know about at the time of the attack, so there was neither a patch nor a warning. Through that flaw the attacker obtained valid administrator credentials. With those credentials he wrote forged withdrawal instructions straight into the wallet backend systems, then deleted the traces of those instructions.
The sequence is the real finding. There was no break-in at the key management layer. Bitget chief executive Gracy Chen told The Block that erasing the traces was the most delicate part of the operation, and framed the incident as one that is very serious at this scale, while serious does not amount to existential. Private keys and cold wallets were not compromised on the investigation's current standing. The security firms Mandiant and SlowMist have been engaged to establish what happened.
The timeline of September 24: two test transfers, then 17 transactions
The sequence reads like a test of the alarm thresholds. At 18:31 UTC two tiny transfers went out, 0.184 ETH and 193 TRX. Both sat below the amounts at which the exchange's risk controls fire. Only afterwards came the outflow proper: between 18:58 and 20:09 UTC, 17 large transactions across eight different blockchains, worth roughly $361 million in total.
What stopped it was not the withdrawal control but the ledger reconciliation. At 19:05 UTC the reconciliation system flagged a gap between recorded and actual balances, and Bitget then froze withdrawals across the platform. Seven minutes separated the first large transaction from the alarm; a little over an hour separated the alarm from the end of the outflows.
That two minimal amounts went first is the part that matters most to you as a user. It shows that value thresholds alone are not a defence when an attacker can probe those thresholds beforehand without drawing attention.
Zero-day at the supplier: why an outside flaw hits the entire exchange
A crypto exchange does not only run trading software. It buys in monitoring tools, access management, logging and defence systems, and those tools need far-reaching privileges by their nature in order to do their job. That is exactly where the problem comes from: a product allowed to see everything and to intervene in much of it is worth more as an entry point than any single user account.
For judging an exchange, that shifts the yardstick. A platform can keep its own keys impeccably and still be vulnerable because a supplier had a flaw. This is not a one-off at this exchange but a pattern attackers use across the whole financial sector. For you, nothing about it calls for panic, but one sober consequence follows: the amount you leave sitting on a trading platform should match the amount you could stand not to move for weeks in the worst case.
How to handle custody away from an exchange in practice is covered in the hardware wallet comparison, which looks at devices, prices and the sum above which the effort pays off.

The withdrawal schedule: ETH networks open on September 29 at 08:00 UTC
Bitget did not release withdrawals in one go but in stages. The schedule is set out in the exchange's notice and runs as follows:
- September 28, 08:00 UTC: BTC over the Bitcoin network.
- September 29, 08:00 UTC: Ethereum over Ethereum itself as well as BSC, Arbitrum, Base and Optimism.
- September 30, 08:00 UTC: USDT over Ethereum, BSC, Solana and Tron.
- From October 2, 08:00 UTC: remaining tokens, fiat balances and P2P holdings.
The exchange adds that the pause served a final security review and has no bearing on the availability of user funds; account balances were unchanged, and trading and deposits ran throughout. What you can draw from that: if your balance sits in a token other than BTC, ETH or USDT, nothing moves for you before October 2. The position as of September 26, when the stages were announced, has already been documented by cryptoticker.io.
Keep your coins in your own custodyA $465 million protection fund against $387.5 million of damage
Bitget says it is absorbing the loss in full from its protection fund, which was valued at $465 million on September 25. The fund is to be topped back up to at least $300 million within a week; as a corporate reserve the company cited more than $1.4 billion as of August 31.
A protection fund is not a deposit guarantee scheme. It is a voluntary reserve whose use the exchange decides on itself, and it is subject to no state supervision that could force a payout when it matters. That sets it apart fundamentally from the statutory deposit guarantee on a bank account, which in the EU covers up to 100,000 euros per customer and institution and expressly does not extend to crypto assets. How large the funds of the bigger trading venues actually are, and how they compare with trading volume, was compiled by cryptoticker.io in a count of its own on September 25.
The loss figure has grown over the course of the week. Our first report on September 24 still put it at $351 million, because only part of the outflows had been attributed at that point; that is how cryptoticker.io framed it on the day of the incident. On the figures given on September 28, the value lies between $387.5 million and $388 million. Upward revisions of this kind are the norm in the first days of an exchange incident, and they are a reason not to treat early numbers as final.
MiCA and custody: what a licence requires in Germany
Since the European crypto regulation MiCA applies in full, any provider offering custody, trading or exchange to customers in the EU needs authorisation as a crypto-asset service provider. For custody, the regulation requires among other things that customer holdings be kept separate from the provider's own assets, and that the provider be liable for the loss of crypto assets held in custody where the circumstances are attributable to it. The individual duties that hang on this, and the deadlines the supervisor has set, are broken down in our overview of the MiCA licence.
In practice that means this for you: whether you can invoke that liability in a loss depends on which company your contract was concluded with. Between an EU-regulated arm of a provider and its international entity there are often entirely different legal systems at trading venues. The terms of use state which company is your counterparty and which law applies. It is worth looking that up once, before it matters.

Self-custody against exchange custody: the trade-off after the incident
The case is no argument for avoiding every exchange. It is an argument for making the split deliberately. On a trading platform your balance sits where you can sell or swap it quickly, and where someone else answers for the technology in a loss. In your own custody it sits where no external system access can move it, and where a lost recovery phrase is final.
A workable rule of thumb: the amount on the exchange matches what you actually intend to trade in the coming weeks, plus a buffer. Everything above that belongs in custody you control yourself. Where that line falls depends on how often you trade, not on a figure that holds for everyone. Someone who rebalances every two days needs a different split from someone who adds twice a year.
Two things cost most in this trade-off, in our experience: convenience, and the assumption that an incident always hits the other platform. The 17 transactions of September 24 took 71 minutes. In that window no user could have reacted, not even the most attentive one.
Exchanges with European authorisationHolding period and tax: a withdrawal freeze changes nothing under Section 23 EStG
One question comes up with every withdrawal freeze: does the one-year holding period keep running when you cannot reach your coins? It keeps running. What counts for the period under Section 23 of the German Income Tax Act is the span between acquisition and disposal, not whether you could dispose of the asset in the meantime. Access blocked for technical reasons is not a disposal and therefore interrupts nothing.
Conversely, an incident of this kind does not create an automatic loss you could claim either, as long as your account balance is unchanged and the exchange pays out. A loss that counts for tax presupposes an actual outflow of assets. Should an exchange permanently fail to pay out, the position is a different one and belongs in the hands of a tax adviser, because the question then becomes when a failure counts as final.
In any case, keep your transaction records outside the platform. When an exchange restricts access, experience shows it is the tax documents that become unreachable first.
What is still open
Bitget has announced a formal investigation report. Until then it remains open which security product was involved and whether the underlying flaw has since been closed, because that determines whether other platforms carry the same risk. It is equally open whether the protection fund is refilled within the announced timeframe. And the attribution of the perpetrators remains open; the company said only that in its assessment this is the same group it had already suspected before.
Until those points are documented, the position set out in this article stands. We will update it once the investigation report is available.
Bitget hack: the key points for your decision
- Check which token your balance sits in. BTC has been withdrawable since September 28, ETH and the EVM networks since 08:00 UTC today, USDT from September 30, everything else only from October 2. That determines whether there is anything you can do at all. Where to move if in doubt is shown in the overview of crypto exchanges.
- Set the threshold above which a balance leaves the exchange. Take your bearings from how often you trade, not from the current price. Which devices come into question and what they cost is set out in the hardware wallet comparison.
- Look up who your counterparty is. The terms of use name the company and the applicable law. If the contract sits outside the EU, the MiCA duties do not apply for you; the alternatives with European authorisation are listed under regulated crypto exchanges.
(As of September 29, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Frequently asked questions about the Bitget incident
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- Bitget Withdrawals Resume on September 28: What to Check on a Residual Balance Now
- Crypto Exchange Protection Funds Recalculated: What Really Covers Your Balance After the Bitget Hack
- Customers Pull $463 Million From Bitget: The Consequences for Reserves and Custody
- $766 Million Lost to Crypto Hacks in One Month: What It Means for Your Custody
- Breaking: Trust Wallet Chrome Extension Hack Drains $7M, Full Reimbursements Promised
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
September 29, 2026 7:12 PM

MEXC Refunds $340,000: The Attacker's API Key Survived the Account Freeze
During an account takeover at MEXC, an attacker created an API key with withdrawal rights that the exchange did not revoke when it restored the account. Twenty-seven minutes after the withdrawal freeze expired, roughly $340,000 was gone.
August 13, 2026 4:59 PM

Trezor Data Breach: First 13,689 Customers, Then Roughly 67,000 More Exposed
A breach at Trezor shipping partner ShipMonk exposed names, phone numbers and home addresses of 13,689 customers in August; in September Trezor reported roughly 67,000 more in the US. Devices are safe, phishing risk is not.
August 15, 2026 9:31 PM

Crypto Exchange Shutting Down: What to Do Before the Deadline Passes
Binance, BitMart, Luno and Revolut have ended or cut back their European business within seven weeks. This guide shows which deadline expires first, how a forced sale is treated for tax, and what to secure before the account closes.
October 2, 2026 4:32 AM

NEAR Intents halts withdrawals after a $3.8 million exploit: here are the reasons
NEAR Intents confirms an exploit of more than $3.8 million and holds deposits and withdrawals on eleven networks. Reimbursement is promised, a date for it is not.
September 27, 2026 4:32 AM

Hester Peirce Leaves the SEC: What Now Applies to Your Custody in Germany
The most crypto-friendly voice at the US securities regulator goes on October 2, 2026, and the commission shrinks to two members. For investors in Germany it is still the European rulebook that decides, and there a deadline falls in July 2027.
September 25, 2026 4:11 AM

Bitget Hack of $351 Million: What to Check at Your Crypto Exchange Now
Bitget reports unauthorised outflows of around $351.6 million and has suspended withdrawals. For existing customers in Europe, that closes the one route MiCA had left them.
September 7, 2026 7:26 PM

Stolen Keys Beat Code Flaws: Why the Private Key Is the Way In for 2026 Crypto Hacks
Compromised private keys overtook smart contract code flaws as the most common attack route for the first time in 2026. What sits behind the shift, and how to check your own setup for its single point of failure.
September 4, 2026 10:26 PM

Pocket Bitcoin Data Breach: When Name, Home Address and Bitcoin Address Circulate Together
The Swiss Bitcoin service Pocket Bitcoin closed its investigation on September 3, 2026: 5,411 people affected, and for 291 of them the Bitcoin addresses they used along with copies of identity documents. Why this one data pairing has lasting effect, and what you should check with your own provider.
September 16, 2026 7:39 PM

Deutsche Bank to Custody Bitcoin and Ether: Why Retail Clients Are Missing and What to Check in Your Own Custody
Deutsche Bank will custody Bitcoin, Ether and three stablecoins, but addresses corporates and institutions only. What the launch under supervisory reservation means, and the four questions you should put to any custody arrangement.
September 30, 2026 5:03 PM

Bitget after the hack: withdrawals are back and the Protection Fund is above $300 million
Six days after the attack, Bitget is back with strong numbers: withdrawals for Bitcoin, Ether and USDT are running again, the Protection Fund was refilled two days ahead of its own deadline, and the proof of reserves shows 131 percent coverage.
July 10, 2026 10:30 AM

Binance Reveals Where Its EU Users Went After MiCA
Binance just revealed where most departing EU users moved their crypto after MiCA — and the answer is raising hard questions about the new rulebook.
September 23, 2026 10:11 AM

Kraken: 45 coins are on cancel only, 21 were announced – what to check when trading pairs are blocked
On September 23, 2026 we counted the public market directories of three trading venues. At Kraken, 82 of 1,450 trading pairs are listed as cancel only, a state in which an order can only be cancelled and no longer executed. The 45 underlying assets affected include just 21 that appear in the delisting notice we reported on September 3.
August 30, 2026 10:38 PM

Crypto Cards: Where Your Card Balance Really Sits and What the August 28 Solana Exploit Reveals About It
An attack on a card balance contract on Solana took the loaded balance from 1,685 users while their wallets stayed untouched. The case shows why it matters whether your crypto card holds funds as e-money at a licensed institution or in a smart contract.
August 20, 2026 4:20 AM

Crypto Exchange Delisting: What Happens to Your Tokens When Trading and Withdrawals Close
A delisting runs in four stages, and only one of them is genuinely dangerous: the end of the withdrawal deadline. Using two live OKX dates as the example, we show what happens at each stage and how to tell whether it affects you.
September 30, 2026 4:15 PM

Zcash today: 2,746 ZEC from the Bitget hack vanish into the Ironwood pool
Wallets from the Bitget break-in pushed 2,746 ZEC into Zcash's Ironwood pool on Wednesday morning, roughly $3.9 million. What the shielding means for tracing, and what applies to your exchange account from July 2027.
September 26, 2026 4:11 AM

Shielded Bitcoin: what the privacy proposal means for your Bitcoin addresses
Three researchers published a draft for encrypted Bitcoin transfers without a soft fork on September 24, 2026. What Shielded Bitcoin hides, what stays public and which points you can check on your own wallet today.
September 17, 2026 4:14 PM

D'CENT App Wallet: How to Tell If Your Recovery Phrase Has to Move Now
Manufacturer IoTrust reports suspicious asset transfers in the D'CENT app wallet and asks users to move their holdings. One question decides the matter: has your recovery phrase ever been entered into the app?
September 5, 2026 10:33 AM

ZIL Withdrawals Frozen: Why Your Zilliqa Balance Is Stuck After the Hard Fork
The Zilliqa hard fork of September 2, 2026 moved the ZIL balances of ten exchanges to new addresses. Three days later, deposits and withdrawals were still halted at the three venues we checked: what that means for your balance, what self-custodians are waiting for, and why the announced compensation is not a decision yet.
September 4, 2026 10:15 PM

Trezor Data Breach: Am I Affected and What Should I Do Now?
Trezor widened the ShipMonk data breach on September 4, 2026: around 67,000 further people affected, just over 80,000 in total, from orders placed between November 2019 and August 2021. How to check in two minutes whether you are among them, and what an exposed home address means for self-custody.
September 3, 2026 4:41 AM

Kraken Delists 21 Tokens: Trading End on September 11 Has Passed, Withdrawals Run Until December 10
As of September 27, 2026: Kraken had set the end of trading and deposits for 21 cryptocurrencies for September 11, 2026 at 14:00 UTC, and that date has passed. According to the exchange, withdrawals remain possible until December 10, 2026 at 15:00 UTC. Our September 3 survey showed that none of these tokens could be deposited at Bitvavo, Coinbase or Bitstamp.
August 19, 2026 7:27 AM

Blockchain Rollback After an Exploit: What Happens to Your Tokens When a Chain Is Reset
At Harmony, roughly four billion ONE were minted without authorisation, and a rollback of the chain has been on the table ever since. This piece explains what a blockchain rollback means technically, when it can still succeed, and what it triggers for your holding period.
August 5, 2026 10:33 PM

$130 Million Gone Because the Randomness Was Predictable: Which Hardware Wallet You Can Still Buy
The Coldcard flaw proved the most respected wallet is not the safest. Which vendor has which track record – and why now is the wrong moment to pause your savings plan.
May 4, 2019 5:44 PM

Microsoft Hackers Stole Crypto Using Victims Emails
Another batch of crypto users have lost money recently through an unlikely breach. Recently, Microsoft services such as Hotmail, MSN, and Outlook have been hit by a breach. It was later learned that the breach was due to an employee’s […]
October 2, 2026 7:16 AM

$1.26 Billion in Three Months: Crypto Hacks Hit Their 2026 High
The security firm CertiK counts around $1.26 billion in damage from 247 incidents for the third quarter of 2026. September was the worst month of the year with 99 cases, and this is the background and what it means for your custody.
October 2, 2026 10:46 AM

3 Details Are All It Takes: How SIM Swapping Reaches Your Crypto Account
Fraudsters have a new SIM card activated in your name at the mobile operator and intercept every SMS code with it. How the attack on your crypto account unfolds and which settings make it run into the void.
October 1, 2026 4:21 AM

Velocity Replaces Drift After the 285 Million Dollar Hack: What Changes for Investors in Germany
The Solana perp DEX Drift is back as Velocity, and since September 29, 2026 a new team has been running it. What the overhaul after the outflow of 285 million dollars means for your deposits, for settlement in USDT and for the legal position in Germany.
More from CryptoTicker

