Bitget has rebuilt its Protection Fund to approximately $309 million and resumed withdrawals for major assets including Bitcoin, Ether, and USDT, as the exchange works to restore normal operations after a $388 million security breach.
According to the exchange, $1.1 million in stolen funds has been frozen, and it reports a 131% reserve ratio. The Protection Fund is designed to cover user losses in security incidents where users are not at fault. Bitget had previously stated the fund held more than $464 million, and CEO Gracy Chen said the exchange will cover the loss: We will not run away from this, and every dollar will be accounted for.
PeckShield counted 55 major crypto hacks in September, totaling $766.49 million in losses, about 462% above August's $136.3 million. The two dominant incidents were the Bitget exploit at roughly $387 million and the Liquid Network theft of about $320 million, of which $285 million was returned. They are now the largest and second-largest crypto thefts of the year to date. Excluding those two cases, the remaining 53 hacks accounted for about $59 million.
Bitget said its security systems flagged unauthorized transfers from parts of its hot wallets at 18:31 UTC on September 24. Chen explained that the attacker accessed a backend system in the wallet infrastructure, spoofed transaction data, and tricked the authorization process into releasing funds. She ruled out a private key compromise and noted that cold wallets, which hold most of the exchange's assets, were not touched.
The Liquid Network loss occurred earlier on September 6, when purported white-hat hackers withdrew roughly 4,000 BTC from the Liquid Federation wallet. The withdrawal used the SideSwap peg-out authorization key, though Liquid noted the key itself was not compromised. In on-chain messages to Blockstream, the hacker promised to return the money once every node was patched, but Ledger CTO Charles Guillemet was skeptical, noting that legitimate security researchers would not typically drain a bridge and then request on-chain contact.
SlowMist reported on September 29 that North Korea-linked hackers are laundering the stolen Bitget funds by pairing CoW Protocol orders with Chainflip deposit addresses, converting proceeds to BTC, and then using CoinJoin to obscure movements. Chainflip is attempting to block the flows and has rejected at least one deposit but refunded the money instead of freezing it. The remaining top-10 hacks ranged from $3.15 million to $7.81 million, including a front-run involving the MEV bot yoink that was returned, and the LimitBreak contract incident in which 23,155 NFTs worth nearly $6 million were moved out of exposed wallets.