Invest2 publishers3 min readPublished Updated
Bitget customers withdrew $463 million in 24 hours, more than the $388 million hack took
Bitget customers pulled about $463 million in the first 24 hours after withdrawals reopened, more than the $388 million hackers stole on September 24. The protection fund covers the theft with about $76 million to spare, so the withdrawals now test whether the $5.7 billion left in reserves matches what Bitget owes customers.
The Investor · Invest desk

What happened
- The attackers used a zero-day flaw in a third-party security app and stolen internal credentials to spoof transactions, and Bitget says its private keys and cold wallets were untouched.
- Withdrawals came back one asset at a time: bitcoin on September 28, ether on September 29, USDT on September 30, with other assets and peer-to-peer transfers targeted for October 2.
- Bitget hired Mandiant and SlowMist to trace the stolen funds, and initial assessments point to possible involvement by North Korea-linked hackers.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- constraint The fund has about $76 million left, so a second loss anywhere near this size would have to be paid from money outside it.
- contradiction The reported balances leave about $149 million of the decline unexplained, and Crypto Briefing's separate $600 million figure fits neither total. That makes any single reserve number a weak guide to Bitget's position.
- constraint Holders of assets outside bitcoin, ether and USDT, and peer-to-peer users, cannot get out until the October 2 target, while bitcoin holders have been able to withdraw since September 28.
- exposure Attackers got in through a vendor's security app, so any exchange running third-party security software has the same route in, and according to Crypto Briefing most regulatory frameworks do not yet set standards for it.
The protection fund and the withdrawals are paid from different money. Bitget's User Protection Fund held over $464 million before the breach [5], so covering a $388 million theft [1] leaves about $76 million [1]. The $463 million customers took out in the first 24 hours [2] comes within roughly a million dollars of the fund's entire pre-breach size [8], but none of it came from the fund. It came from the reserves that back customer balances.
If an exchange holds a full reserve, each withdrawal cuts its assets and its liabilities by the same amount, and it can pay a run of any size. So whether Bitget can pay comes down to a ratio. Crypto Briefing puts tracked reserves at about $5.7 billion [3]. That figure counts assets only, and the report does not include Bitget's customer liabilities.
The balance figures also fail to reconcile. Reserves stood above $6.7 billion before the hack [4], so the fall to $5.7 billion is at least $1.0 billion [2]. Theft plus first-day outflows comes to $851 million [3], which leaves about $149 million unaccounted for [4]. Crypto Briefing separately puts the decline since the day before withdrawals reopened at about $600 million and says that figure combines the theft with voluntary outflows [12]. The theft took place on September 24 [1], before that window opened [7]. Withdrawals after the first day, or falling coin prices, could each explain part of the $149 million. The source does not break it down.
The schedule matters for reading the first day. Bitcoin withdrawals came back on September 28, ether on September 29 and USDT on September 30, with other assets and peer-to-peer transactions targeted for October 2 [7]. If the 24-hour count started with the bitcoin reopening, the $463 million left while most assets were still locked. Bitget processed over 4,098 BTC in withdrawals shortly after that window opened [9].
In the mild version, the first day was the peak and outflows fade once every asset is open. In a worse one, outflows build as ether, USDT and the rest come back. At $463 million a day, customers would be taking out about 8.1% of the remaining $5.7 billion daily [5], and the question becomes how much of the reserve is held in the coins customers want. The third version turns on the forensics. Mandiant and SlowMist are tracing the funds, and initial assessments point to possible involvement by North Korea-linked groups [11]. Bitget says private keys and cold wallets were never compromised [10]. If that finding changes, a $76 million cushion [1] leaves little room.
I think Bitget pays. It kept trading and deposits running while withdrawals were shut [8]. Chief executive Gracy Chen has reassured users that their balances will remain whole, according to Crypto Briefing [6]. The counter-case is in the schedule. Crypto Briefing describes the phased reopening as a way to avoid a bank-run dynamic and buy time to manage liquidity [13]. An exchange with matching reserves in every coin would have less reason to ration exits by asset. Bitget has chosen to open one asset at a time. It is also spending most of a fund that, after this week, could not cover another theft of this size [1]. If the remaining assets miss the October 2 target [7], this view is wrong.
What to watch
- A Bitget disclosure of customer liabilities set against the $5.7 billion in tracked reserves, the figure that settles whether every withdrawal can be paid in full.
- Mandiant and SlowMist findings: evidence that keys or cold wallets were reached would put new claims on a fund with about $76 million left.
- Daily outflows after ether and USDT reopened: another day near $463 million would point to a sustained run, not a one-day spike.