Bitget Rebuilds Services After $388M Security Breach as Stolen Crypto Flows Through THORChain
The exchange implements phased withdrawal restoration following a major security incident, while the attacker exploits decentralized protocols to move stolen assets.
Cryptocurrency exchange Bitget is methodically restoring customer access to funds following a significant security breach that impacted nearly $388 million in assets. The exchange halted withdrawals after discovering the attack on September 24, which compromised portions of its hot and warm wallet infrastructure. Bitcoin withdrawals have already resumed, with additional cryptocurrencies and network services rolling back online throughout the week in a phased recovery approach.
Phased Restoration of Services Underway
Bitget is systematically restoring withdrawal capabilities across its major digital assets and blockchain networks. Bitcoin withdrawals restarted Monday on both the Bitcoin network and BNB Smart Chain, according to statements from Bitget CEO Gracy Chen. The executive indicated that Bitcoin received priority due to security pipeline completion, signaling methodical progress through verification checks.
Ethereum withdrawals are scheduled to resume Tuesday, accessible across Ethereum mainnet, BNB Smart Chain, Arbitrum, Base, and Optimism networks. Tether stablecoin (USDT) withdrawals will follow on Wednesday, spanning Ethereum, BNB Smart Chain, Solana, and Tron. Peer-to-peer services and remaining asset withdrawals are targeted for Friday. The recovery plan applies uniformly across all customer tiers, with no preferential access granted to institutional clients, VIP members, or company employees.
The initial incident assessment revealed that the breach compromised Bitget’s hot and warm storage systems used for active trading operations, though the exchange’s cold storage reserves remained secure. The damage assessment was later updated from the initial $351.6 million estimate to $387.5 million after accounting for additional unauthorized transfers across Zcash and Tron networks.
Attacker Exploits Decentralized Swaps to Launder Stolen Funds
The breach perpetrator is actively converting stolen assets through THORChain, a decentralized cross-chain swapping protocol. On-chain analysts at Lookonchain detected the attacker converting Ethereum into Bitcoin via the THORChain network, with blockchain intelligence firm Arkham tracking substantial ETH flows from the attacker entering THORChain vault contracts.
The situation has exposed significant limitations in how decentralized protocols can respond to targeted theft. Bitget CEO Chen publicly urged THORChain to refuse services to addresses connected to the stolen funds, but the protocol faces structural constraints in responding. THORChain operates without an address blacklist capability, preventing selective blocking of specific wallets. The protocol’s interventions are limited to broad actions affecting all users: halting trading, pausing outbound transactions, or suspending blockchain connections.
THORChain activated its emergency network halt—a protocol-wide safety mechanism deployed during security events. The protocol developers emphasized that this measure represents a broad emergency response rather than a selective freeze targeting specific transactions or the stolen funds. This distinction illustrates a fundamental challenge in decentralized finance: protocols designed to resist censorship often struggle to recover stolen assets once in circulation.
The incident highlights persistent security challenges surrounding cryptocurrency custody and validates the need for institutional-grade safeguards in exchange operations. As Bitget restores full functionality, the broader crypto ecosystem is monitoring how both centralized exchanges and decentralized protocols address large-scale security threats.
Source: Bitget, via Cointelegraph. Not financial advice.
The breach demonstrates how centralized custody vulnerabilities and decentralized protocol limitations create systemic risks that reshape crypto market participant strategies and cross-chain infrastructure security discussions.