Bitget is set to resume USDT withdrawals at 08:00 UTC on September 30, six days after a security breach triggered the movement of about $387.5 million from its internet-connected wallets. The exchange recorded a net outflow of about $463 million in the 24 hours after withdrawals reopened, the largest one-day outflow recorded for Bitget by DeFiLlama.
At the same time, Bitget’s latest Proof of Reserves report shows reserves covering 131% of customer assets. The figures highlight both the withdrawal pressure on the exchange and the level of reserves it reported after the incident.
We have never touched customer funds — which is why, even after this incident, our reserve ratio remains above 131%. That’s not a coincidence. It’s many years of discipline.
Thank you for your trust. We’re coming back stronger. https://t.co/XB9a2zkHB1
— Gracy Chen @Bitget (@GracyBitget) September 29, 2026
The USDT withdrawal service will restart across Ethereum, BNB Smart Chain, Solana and Tron. Bitget had already reopened Bitcoin withdrawals on September 28, followed by Ether withdrawals on September 29.
The $463 million outflow is significant because it shows how quickly customers moved funds after being allowed to withdraw again. Bloomberg reported that Bitget’s remaining reserves stood at about $5.7 billion, meaning the one-day outflow represented roughly 8% of that amount.
However, the exchange has also reported a healthy reserve ratio. Its 47th Proof of Reserves report, based on a snapshot taken at 09:00 UTC on September 29, showed overall coverage of 131%. All 19 assets covered in the report had reserves above 100%. In simple terms, Bitget says it held more crypto assets than the balances owed to customers at the time of the snapshot.
The latest ratio is slightly lower than the 135% reported in the previous monthly report. Customers can use Merkle Tree verification to check whether their individual balances were included in the reserve snapshot without seeing information about other users.
There is another important part of the story. Bitget’s User Protection Fund, which was presented as a safety cushion following the breach, has fallen below $200 million, according to figures reported by Bloomberg based on the wallet addresses identified by the exchange. When the breach was disclosed, Bitget said the fund held more than $464 million.

Source: Bitget.com
The decline reflects the use of the fund to absorb the financial impact of the incident. Bitget has said it will replenish the fund, although it has not specified how much will be added or when the replenishment will be completed.
The security incident began on September 24, when Bitget detected unauthorised transfers from parts of its hot and warm wallets. The attacker eventually moved about $387.5 million in assets across several blockchain networks. Bitget later said the attacker exploited a vulnerability in a third-party security product and obtained high-level internal credentials.
Importantly, Bitget said its cold wallets were not affected and that customer account balances were not altered. The exchange also engaged Mandiant and SlowMist to investigate the incident and said the vulnerability had been patched.
The exchange has suggested that some activity resembles operations previously linked to North Korean actors, but this attribution has not been confirmed. Bitget has also launched a recovery bounty programme offering 5% of funds recovered with outside assistance.
As USDT withdrawals resume, the exchange faces a key test of customer confidence. The reserve report indicates that Bitget had more assets than customer liabilities at the September 29 snapshot. At the same time, the large outflow and the reduced protection fund show that the breach has had a significant financial and operational impact.
Stay informed with the latest trends in Web3, blockchain innovation, and cybersecurity updates at 3verseTV
You need to login in order to Like










Leave a comment