Bitget resumes withdrawals following $387.5 million hack, but major test is still ahead for exchange and BGB
Cryptocurrency exchange Bitget has begun restoring withdrawal services following a $387.5 million hack. While the resumption of operations gives relief to clients, the financial impact of the breach will depend on how many users choose to withdraw their assets now that the service is back online. The exchange currently faces a test of its ability to meet this demand, while its native token, BGB, faces a test of market confidence in the platform's resilience.
The exchange initially estimated losses at $351.6 million but later raised the figure to $387.5 million after accounting for additional transactions involving Zcash and TRON. According to Bitget, an attacker compromised the internal wallet infrastructure system and manipulated the data used to validate transfers. The exchange states that the vulnerability has been resolved and cold wallets remain unaffected, with investigations continuing in collaboration with Mandiant and SlowMist.
Notably, the attacker didn't gain access to private keys. According to Roman Prudnikov, co-founder of Rubin, financial infrastructure for onchain economy, the cold reserves remained untouched because the hackers “manipulated the transaction history within the back-end system and triggered unauthorized withdrawals by exploiting a logic vulnerability”.
Key security alone proves insufficient if the system accepts manipulated data as the basis for a legitimate transaction. TRM Labs draws a parallel with the 2025 Bybit hack, where attackers also manipulated information received by trade-matching systems.
Hackers’ Routes and Schemes Revealed
Following the hack, the stolen assets were distributed across various wallets and transferred to other blockchains. TRM Labs observed the fragmentation of ETH and XRP reserves, as well as routes used to convert a share of the funds into Bitcoin via THORChain. Such operations complicate investigations, as analysts must correlate transactions across multiple networks simultaneously. Moreover, the ability to track the movement of funds does not automatically allow for their blocking.
ZachXBT published additional information on the parties involved in the alleged money laundering. The researcher linked five accounts to the stolen funds transfers, citing, among other things, inquiries made by their owners in public support chats. While this data could help the investigation, identifying intermediaries and recovering assets remain a challenge. And analysts remain cautious about the potential recovery of the stolen assets. Prudnikov compared the Bitget hack with the accident that happened to the Liquid network earlier this month. However, unlike that case, there are “no signs of a potential fund return”, according to the expert.
BGB Token’s Reaction
Growing pressure on the exchange's token was observed within the first 24 hours following the hack. On September 25, BGB dropped by 5% — from $2.05 to $1.95. For BGB, it is not just the size of the stolen amount that matters. The token is linked to the use of Bitget services, and a potential customer exodus could weaken demand for it, even after damages are compensated. Still, the reverse scenario is also possible: adhering to the withdrawal schedule and transparently disclosing investigation results could reduce the discount the market applies to account for operational risk.

Image source: FXStreet
The Protection Fund and the Cost of Restoring Trust
At the time of the initial announcement, Bitget valued its protection fund at over $464 million and stated that it covered the hack-related losses. To put the scale in perspective, the revised loss figure of $387.5 million represents approximately 83.5% of that $464 million.
Rubin’s Roman Prudnikov highlights protection funds become increasingly important, but the market may demand more insurance against such incidents. He explained:
“Protection funds, increasingly used by crypto exchanges as a marketing aspect lately (however impressive they may seem), will likely come under increasing pressure as users and institutional partners begin to scrutinize the exchange’s architecture and security audits more rigorously.”
Combined, these two incidents make September 2026 the worst month of the year for hack-related losses, surpassing even April, which saw $646.9 million in losses (involving Drift and KelpDAO). “If spoofing within the internal transaction accounting system is confirmed, it will set an alarming precedent for any exchange utilizing a similar withdrawal verification architecture, which applies to the majority of the market,” noted Prudnikov.
For Bitget, the decisive milestone will be adherence to the recovery schedule and the readiness to fulfill client requests, while for BGB, the key factors will be holder behavior once transfers resume. The resumption of withdrawals allows the exchange to validate its claims in practice, and the outcome of this test will determine the long-term impact of the hack.
Author

Julia Magas
Independent Analyst
Julia Magas is an analyst and writer specializing in cryptocurrency and fintech market trends. Her work has been featured in leading financial publications such as Nasdaq, InvestorPlace, Cointelegraph, and Investing.




