Bitget Exchange Resumes Bitcoin Withdrawals as Hacker Moves Stolen ETH via THORChain

Crypto exchange Bitget has resumed Bitcoin withdrawals after halting them due to a security breach that compromised nearly $388 million in assets. The September 24 attack affected parts of Bitget's hot and warm wallets, while its cold storage remained secure. Meanwhile, the attacker continues moving stolen crypto by swapping Ether through the decentralized protocol THORChain.
Timeline and Scale of the Breach
On September 24, Bitget suffered a security breach compromising parts of its hot and warm wallets. Initially, the stolen amount was estimated at $351.6 million but later rose to $387.5 million after including additional transfers on Zcash and Tron. The exchange confirmed that its cold wallets remained secure throughout the incident.
Resumption of Crypto Withdrawals
After temporarily halting withdrawals, Bitget resumed Bitcoin withdrawals on the Bitcoin network and BNB Smart Chain on Monday. CEO Gracy Chen explained that this was the first step in the phased restoration plan. Withdrawals for Ether (ETH) and Tether (USDT) across multiple chains—including Ethereum, BNB Smart Chain, Arbitrum, Base, Optimism, Solana, and Tron—are scheduled to resume in the following days. Other assets’ withdrawals and peer-to-peer services are expected to return by Friday.
The company made clear that the recovery schedule applies equally to all users, with no priority given to institutional clients, VIPs, or Bitget employees.
THORChain’s Response and Decentralized Protocol Limits
Following reports that the attacker is swapping stolen ETH for BTC via THORChain, Bitget’s CEO called on THORChain to block addresses associated with the attack. THORChain representatives responded that their network halt is an emergency security feature affecting the entire protocol and does not perform selective freezes on individual funds or swaps.
Crypto analyst Anndy Lian noted that while THORChain can halt trading, stop outgoing transactions, or pause a connected blockchain to mitigate risks, it lacks a built-in blacklist function to block specific addresses. This limits its ability to prevent malicious actors from using the protocol selectively.
Why it matters
This news highlights how major exchanges like Bitget manage large-scale hacks by cautiously resuming withdrawals under tightened security protocols, maintaining user trust. It also exposes the challenges decentralized protocols such as THORChain face when their infrastructure is exploited to launder stolen funds, due to inherent limitations in selectively blocking malicious actors. The situation underscores the critical need for developing enhanced security mechanisms and effective cross-platform cooperation to combat cybercrime in the evolving crypto landscape.
Prepared from the source material with AI-assisted editing and checked against the supplied facts.
Open original source ↗