Bitget Sets a 28 September Restart After Raising the Tally to $387.5M

Bitget published a withdrawal restart schedule early on Saturday, two days after attackers drained its hot wallets. Withdrawals reopen in four stages, each at 08:00 UTC: bitcoin on Monday, ether on Tuesday, tether on 30 September, and everything else, including fiat and peer-to-peer trading, on 2 October. The exchange also settled on a loss figure. It now puts the theft at $387.5 million, above the $351.6 million disclosed on Thursday, and says the difference is counting rather than a second raid. Trading and deposits never stopped.
Where the extra $35.9 million came from
Gracy Chen, Bitget's chief executive, said the revision covers assets missed in the first pass.
"The revised amount includes Zcash and TRON assets that were not fully counted previously, and does not represent newly stolen funds," Chen said in remarks carried by PANews on Friday afternoon.
The Crypto Times puts the gap at $35.9 million and ties it to those two chains. Bitget's own incident update, timestamped 14:05 UTC on Friday, names ten affected assets: XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX and TRX. It lists four attacker addresses, one each for EVM chains, XRP, Zcash and TRON, and gives no per-asset amounts. Startup Fortune, writing Saturday morning, has the two largest slices at 102.93 million XRP and 31,890 ETH, worth roughly $157 million and $86 million. Nothing else in this sweep carries those two numbers. The earlier $351.6 million count is superseded, not contradicted.
What the protection fund covers
Bitget says the loss lands on its own books. The Bitget Protection Fund holds 5,500 BTC, which the exchange valued at about $464 million on Friday, adding that every fund wallet address is public and can be checked on chain at any time. On those two figures the theft is roughly 84% of the cover, a share The Crypto Times and Startup Fortune both publish. The fund is denominated in bitcoin, so what it covers in dollars moves with the price. The exchange's line that "account balances remain unaffected" is a statement about user accounts, not a claim that the money is back.
How the payouts got signed
Nobody stole a private key. Attackers reached a backend wallet system, fed it forged transfer data and let Bitget's own authorization process approve the payouts as routine, on Startup Fortune's account of the method. Cold wallets were untouched, a point Bitget and three other accounts agree on. The breach was caught at 18:31 UTC on Thursday. Mandiant and SlowMist are on the investigation, and Bitget says the vulnerabilities found that day have been "identified and patched."
Who did it is unsettled. Researchers have pointed at the Lazarus Group, the outfit named in a run of earlier exchange thefts, while some analysts dispute a direct link and at least one account calls the attribution unconfirmed speculation. This desk is not in a position to weigh those readings. Tallies of this kind move: PeckShield and CertiK finished August $79 million apart on the same month of hacks, and Bitget's own number has moved once in two days.
What Monday will show
The schedule is the test. Bitcoin withdrawals are due to open at 08:00 UTC on Monday, and Chen holds a public question session ninety minutes before that, at 07:30. Bitget has offered 5% of any funds successfully frozen and 5% of anything recovered, excluding results produced by court order or law enforcement, and no freeze has been reported yet. The laundering trail is thinly sourced. One account has 6,300 ETH, about $19 million, moving through the Tornado Cash mixer; another has $1.23 million pulled off Binance into an attacker-controlled wallet. Neither figure is confirmed anywhere else. Nothing Bitget has published says whether the protection fund gets topped back up, or when.
Read also: Stolen Keys Cost More Than Code Bugs in DeFi's 2026 Loss Tally