Quick Take
- More than 4,000 BTC was withdrawn from Bitget after Bitcoin withdrawals resumed, while tracked reserves fell by nearly 5,000 BTC.
- The rapid outflow shows users are testing access and confidence just days after the exchange suffered its biggest security incident.
- Investigators are now racing to trace the $387.5 million haul as laundering networks scatter assets across chains and privacy tools.
Nearly 5,000 Bitcoin has left Bitget’s tracked reserves after the crypto exchange reopened withdrawals following its $387.5 million hack.
On Sept. 28, Bitget Chief Executive Officer Gracy Chen said the exchange had processed 9,585 withdrawal orders totaling 4,098.036 BTC as of 17:00 UTC+8, shortly after it resumed Bitcoin withdrawals.
Separate DeFiLlama data showed Bitget’s tracked Bitcoin balance falling to about 30,770 BTC from 35,412 BTC, a decline of roughly 4,642 BTC. At prevailing prices, the drop represents about $391 million of Bitcoin.

The reserve decline is larger than the amount Chen said Bitget had processed through customer withdrawal orders. DeFiLlama tracks assets held in wallets attributed to exchanges, meaning changes can also reflect wallet movements or differences in address coverage rather than customer withdrawals alone.
Still, the rapid outflow provides the first indication of how users are responding after Bitget froze withdrawals for four days while investigating the largest security incident in its eight-year history.
Bitget restored Bitcoin withdrawals at 08:00 UTC on Sept. 28 after completing additional checks on its withdrawal infrastructure. Ethereum withdrawals are scheduled to follow on Sept. 29, USDT on Sept. 30, and remaining tokens, fiat, and peer-to-peer services on Oct. 2.
The restart comes as Bitget attempts to reassure customers that the attack did not compromise its private keys or cold-wallet reserves.
Chen said a completed internal trace found that attackers exploited vulnerabilities in third-party products to obtain internal credentials. Those credentials were then used to submit fraudulent withdrawal instructions that bypassed Bitget’s risk controls.
The exchange has isolated affected systems, revoked and reissued internal credentials, and restructured access to sensitive infrastructure, Chen said. Bitget also disabled the affected third-party functionality while the vendor works on a fix.
Blockchain security firms, including Mandiant and SlowMist, continue to assist with forensic analysis and attempts to trace the stolen assets. Bitget previously said the incident involved a critical backend system in its wallet infrastructure and that it had remediated the vulnerability before withdrawals began returning.
Bitget has said customers will bear no losses from the incident and that its Protection Fund will cover the shortfall. Chen said the company plans to replenish the fund with its own capital to more than $300 million within a week.
Stolen funds move as THORChain resists calls to intervene
Meanwhile, recovering the stolen Bitget funds is becoming more difficult as the assets are fragmented across bridges, cross-chain protocols and privacy services.
Blockchain investigator ZachXBT said Chinese illicit actors were laundering proceeds from the exploit on behalf of hackers he described as allegedly linked to North Korea. He said the funds were being chain-hopped and deposited into mixing services including Wasabi.

ZachXBT also linked one participant in the laundering network to movements following the $292 million Kelp DAO exploit earlier this year, saying he had seen similar behavior after several attacks attributed to the TraderTraitor campaign.
The laundering action has put THORChain at the center of a growing dispute over whether permissionless infrastructure should intervene when stolen assets pass through its systems.
THORChain says it would not selectively block wallets or swaps, arguing that its role is comparable to censorship-resistant networks such as Bitcoin and Ethereum. However, blockchain security firm GoPlus challenged that comparison, saying THORChain's architecture gives its node operators powers that base-layer validators do not have.
GoPlus pointed to THORChain's threshold-signature vaults, where active nodes jointly authorize outbound transfers, and said releasing assets from those vaults requires an affirmative signing action. It also cited per-chain signing halts, network-wide pauses, and Mimir governance as evidence that node operators can coordinate intervention when they choose.
That makes the argument less about whether THORChain has emergency controls than about when its operators are willing to use them.
GoPlus also pointed to THORChain's response to its own $10.7 million exploit in May, when the network was halted as part of the containment effort. The security firm argued that the same emergency framework could be used against addresses linked to the Bitget attackers.
THORChain disputes that conclusion, saying a network halt is meant to protect the protocol itself and differs from selectively censoring a particular user, wallet, or swap. It also said attacker addresses were not blacklisted during the May incident, maintaining that the protocol should remain neutral even when known stolen funds move through it.
GoPlus has accused THORChain of benefiting financially from that stance. It estimated that about 101.5 BTC, worth roughly $8.5 million, had already exited through the protocol from the Bitget exploit, while another 27.63 million XRP, valued at about $43 million, was being converted into Bitcoin.
The firm also cited THORChain's role in laundering proceeds from the 2025 Bybit hack, when the attacker moved hundreds of thousands of ETH through the protocol and generated millions of dollars in fees. GoPlus argued that the fee income creates an incentive conflict when node operators decline to interfere with illicit flows.
THORChain has not accepted that characterization, and its position leaves the industry with a question of whether decentralized protocols that retain emergency controls should remain transaction-neutral when those same systems are used to launder funds from major hacks.
For Bitget, that debate has immediate consequences. As Ethereum, USDT, and other withdrawals reopen, investigators are racing to recover assets that are already being broken up across chains and routed through infrastructure whose operators may refuse to stop them.



