Bitget Resumes Withdrawals After $387.5M DPRK Heist
Bitget restored Bitcoin withdrawals September 28, days after suspected North Korean hackers stole $387.5 million from the exchange in a backend compromise.

Bitget has restored Bitcoin withdrawals as of September 28, roughly four days after the exchange suspended them following a backend compromise that suspected North Korean state actors used to drain funds from hot and warm wallets. The total loss has been revised upward to $387.5 million, up from the $351.6 million the exchange reported when the breach first became public on September 25.
BleepingComputer reports that Bitget acknowledged the higher figure as it announced the resumption. The exchange detected unusual wallet activity at 18:31 UTC on September 24 and moved to halt withdrawals to contain further losses. Beyond that, Bitget has not released a formal post-incident report and has not named the specific access vector used to enter the backend.
Attribution continues to point toward a North Korea-linked threat actor. Blockchain analytics firms and U.S. government reporting have tracked this pattern for years: state-sponsored theft funding Pyongyang’s weapons programs, typically executed by groups operating under the umbrella commonly called the Lazarus Group. The FBI and Treasury’s OFAC have sanctioned multiple individuals and wallet addresses tied to those operations, which slows laundering but does not prevent the theft.
The speed of resumption is worth noting. Exchanges that absorb breaches at this scale often spend weeks restoring full service. Bitget’s ability to resume in under five days suggests the exchange held sufficient reserve liquidity to cover withdrawal demand, but that judgment is preliminary without a full post-incident accounting.
What typically comes next in these cases is silence. The disclosure window closes fast once withdrawals are back, and the structural question of how the backend was accessed tends to go unanswered in public. Users with funds at centralized exchanges are left to decide whether resumed operations are the same thing as fixed operations.
For full background on how the breach unfolded, see the original Bitget breach report from September 25.
Found this useful? Share it.


