Bitget Restores Bitcoin Withdrawals After $388M Hack
Bitcoin withdrawals are back at Bitget, with ether due Tuesday and USDt on Wednesday after last week's $388 million hack, as the attacker swaps ETH through THORChain.

Adrian Cole
Markets & Mining Editor, RefreshCoin
Bitget has resumed Bitcoin withdrawals after a hack last week drained about $388 million from the exchange. Ether withdrawals are scheduled to return on Tuesday and USDt on Wednesday, as the venue rebuilds its services layer by layer. How fast the remaining channels open, and how far the stolen funds travel across chains before anyone can stop them, will decide how this incident is remembered by traders and by the exchanges that study it.
Which withdrawals are back, and when
Bitcoin is first. It is the asset whose withdrawal status traders treat as a health check on any venue, and its return suggests the exchange considers its reserves deep enough to honour redemptions in the coin that matters most. Ether follows on Tuesday, then USDt on Wednesday. USDt is the stablecoin behind most trading pairs on the platform and the token people use to park value between trades, so its reopening completes the basic loop of deposit, trade and exit.
Other tokens were not part of Monday's restart, and no dates have been announced for them.
Staggering the reopening limits the strain on liquidity. If every channel lit up at once, the venue would face a wall of requests in the same hour, and a liquidity squeeze is how a bad day turns into a solvency debate. A rollout spread across several days lets the exchange work through queues, watch outflows and adjust if one asset drains faster than expected.
Each published date is now a commitment the market will grade.
How the hacker is moving the stolen funds
The money is not sitting still. The attacker is swapping ether through THORChain, a decentralized exchange protocol that lets one blockchain's native asset be traded for another's without routing the order through a centralized platform. Swapping across chains is a familiar laundering step because it changes the asset and the network at the same time, pushing value into a form that is harder to connect back to the original breach.
Every swap carries the proceeds one more hop from the hacked wallet.
Once an address is flagged by security firms or by exchanges, deposits touching it can be refused or frozen, so the attacker has an incentive to convert quickly. Permissionless venues do not run those checks before a trade settles, which is why trails in cases like this tend to break at the swap rather than at the cash-out point, where identity checks usually apply.
Speed is the whole point of the maneuver.
Why does THORChain matter in this case?
THORChain matters because it settles in native assets rather than tokenized stand-ins, so an attacker can leave one chain and arrive on another holding a liquid coin in a single transaction. That convenience is why protocols of this type keep surfacing in the aftermath of large crypto thefts. The trade-off is exposure: a swap of this size needs depth, and depth is finite on any decentralized venue.
Big trades leave a footprint anyone can read.
Analysts who follow stolen funds map these transactions publicly, and each hop gives them another data point on where the money is headed and which exchanges might receive it next. The result is a race between conversion and identification, with the attacker trying to reach liquid markets before the addresses carrying the funds are tagged.
What does this mean for Bitget users?
It means users should hold the exchange to its published dates. Bitcoin is live again, ether arrives Tuesday, USDt on Wednesday, and each batch that clears reduces the pressure on whatever channels remain shut. For anyone with funds on the platform, the practical issue is whether their token has a date attached and whether that date holds once the queue starts moving.
Confirm every address through official channels before sending.
Staged withdrawals are the industry's standard response after a breach. A venue that has just lost money needs to identify compromised wallets, reconcile on-chain and off-chain balances and preserve operating capital while service comes back. The range of outcomes is wide: FTX stopped withdrawals in November 2022 shortly before it collapsed, while other venues have reopened within days and absorbed the hit from treasury.
How does $388 million compare with past hacks?
The figure puts this breach among the larger single-venue thefts of recent years, still well below the roughly $1.5 billion taken from Bybit in February 2025, which set the ceiling for a coordinated exchange compromise. Scale decides whether an exchange covers customer balances out of its own pocket or needs outside support, and it also shapes how much selling pressure the stolen coins could create if they are liquidated rather than swapped.
The next number that matters is the reimbursement plan.
Recovery prospects depend on what the funds become. Stablecoin issuers can freeze specific addresses, and that power has repeatedly cut short attempts to cash out, while ether already converted into other assets is far harder to stop than coins still parked in a known breach wallet. Watch whether tagged addresses appear and whether any of the $388 million is locked before it moves again.
What usually happens after an exchange breach?
The playbook is consistent across the industry. Withdrawals freeze to stop further outflows, outside investigators trace the movement of funds, and the venue reconciles its balances before reopening anything. Service then returns in stages, typically starting with the asset that is easiest to verify and ending with stablecoins, which are spread across many wallets and chains.
Disclosure follows the same order: confirmation of the loss, a restoration timeline and a plan for customer balances. Depositors read the speed of communication as a signal of control, which is why venues that publish concrete dates tend to settle nerves faster than those that describe events in vague language about unauthorized access.
What to watch in the days ahead
Three dates anchor the week: bitcoin already restored, ether on Tuesday, USDt on Wednesday. Clean execution on all three closes the incident for most users, while a missed deadline would restart questions about liquidity and internal controls. Beyond the calendar, the attacker's next move matters, because a shift from public swaps into mixers or privacy tools changes how much of the $388 million can ever be traced.
One missed deadline would bring the doubts back.
Regulatory attention is the other thread to follow. Large breaches tend to prompt questions about custody design, cold storage and disclosure standards, and those questions arrive faster when the amount runs into the hundreds of millions. Traders will also watch the broader market, since forced sales of stolen coins are one of the few hack-related flows that shows up directly in price.
Mentioned in this article
Frequently asked questions
Which Bitget withdrawals are working now?
Bitcoin withdrawals were restored first, following the $388 million hack last week. Ether is scheduled to return on Tuesday and USDt on Wednesday, while other tokens have no announced dates yet.
Why is the hacker using THORChain?
THORChain trades native assets across chains in a single transaction, so the attacker can change both the asset and the network at once. That breaks the trail before receiving addresses are tagged and frozen by exchanges.
Is $388 million a large exchange hack?
It ranks among the bigger single-venue thefts of recent years, but stays below the roughly $1.5 billion taken from Bybit in February 2025. Scale determines whether the exchange can cover customer balances from its own treasury.
Comments(0)
No comments yet. Be the first to weigh in.