The outflows happened in the 24 hours leading into Tuesday (Sept. 29), Bloomberg News reported, saying this surge happened when Bitget began restoring withdrawals. It represents the largest one-day outflow since data aggregator DefiLlama began monitoring proof-of-reserves four years ago, the report added.
Bitget announced last week that assets equivalent to about $387.5 million were stolen in an attack. The company has said its security systems identified unauthorized transfers involving a limited number of hot wallets, and activated emergency response procedures and began a full investigation. Withdrawals were suspended while the company conducted a security review.
According to Bloomberg, Bitget is reopening withdrawals in stages, beginning with bitcoin on Monday, followed by Ether and Tether’s USDT stablecoin.
We’d love to be your preferred source for news.
Please add us to your preferred sources list so our news, data and interviews show up in your feed. Thanks!
Withdrawals of other tokens, as well as fiat and peer-to-peer services, are due to resume Oct. 2, Bitget said on its website. This staggered rollout was a security measure “unrelated to the sufficiency or availability of user assets,” the company added.
The Bloomberg report characterizes the wave of outflows as another blow to the exchange as it tries to recover from a hack cybersecurity experts have linked to North Korea. Tuesday’s outflows represent upwards of 10% of the company’s reserves.
The $464 million user protection fund Bitget had pointed to assure customers their money was safe has now dropped below $200 million, Bloomberg added, citing the three wallet addresses that Bitget has called the source of the funds.
“The Protection Fund is being used to absorb the financial impact of the incident,” Bitget CEO Gracy Chen told Bloomberg via email. “Bitget will replenish the Fund using its own capital, with the Fund targeted to be above $300 million within one week.”
A report earlier this month from CoinGecko found that hacks and thefts had cost cryptocurrency platforms more than $3.6 billion in the last 18 months. The report said most of these incidents — the results of cyberattacks and stolen passkeys — took place despite the companies carrying out security audits.
Around 88% of the stolen funds and roughly 60% of the affected platforms had “completed independent security audits,” the report said, though most of the attacks involved areas that checks do not typically cover.
Nearly every theft covered by that report is surpassed by the attack on Bitget, save for the $1.4 billion theft from Bybit in February of last year.