TL;DR
- Bitget says its Protection Fund was replenished to more than $300 million on September 30 following the September 24 security incident.
- The exchange says user balances remained accurate and unaffected, while withdrawals have been restored in phases.
- The fund is publicly traceable onchain, but the replenishment should not be confused with recovery of all assets connected to the incident.
Bitget has rebuilt its user-protection reserve to above $300 million after drawing on the fund during the security incident that hit the exchange on September 24.
The exchange confirmed the replenishment on September 30, beating the one-week deadline it had set two days earlier. Bitget said the incident affected an estimated $388 million, while user account balances remained accurate and the Protection Fund was used as part of the financial response.
The distinction between those numbers is important. The fund is a balance-sheet protection layer for users, not a running total of assets recovered from an attacker.
The reserve is back above its stated floor
Bitget created the Protection Fund in 2022 with 5,500 BTC and a stated minimum value of $300 million. The exchange publishes wallet addresses so users can inspect the assets onchain.
After the September 24 incident, Bitget said it would restore the reserve to at least $300 million within a week. The company now says that work is complete.
Withdrawals have been returning separately. Bitget’s incident timeline scheduled BTC withdrawals for September 28, ETH and several EVM networks for September 29, USDT across major chains for September 30, and other coins, fiat and P2P services for October 2.
That staged recovery is more useful than simply saying the exchange is “back online.” It shows which operational systems have actually been restored.
The wider push toward stronger market infrastructure runs from regulated US crypto derivatives through Kraken and Bitnomial to the growing use of tokenized bank deposits in the UK. Exchange reserve transparency sits in the same broad category: crypto firms are being judged increasingly on financial plumbing rather than marketing promises. The security side of that shift is also visible in the rollout of audited smart-contract tooling across major networks.
Replenishment is not the end of the incident
A protection fund can absorb losses, but it does not answer every security question.
Investigations, asset tracing and potential recoveries can continue long after users regain access to their accounts. Bitget has also published attacker addresses and a recovery-bounty framework as part of its response.
For users, the immediate milestone is that the reserve has been rebuilt and the withdrawal schedule has reached its October 2 phase. For the exchange, the longer-term test is whether the incident leads to stronger controls and whether onchain transparency remains meaningful once the crisis has passed.
That matters because crypto exchanges do not get judged only on whether they survive an exploit. They get judged on how clearly they account for the damage afterward.
—
This article was written by the News Desk and edited by Samuel Rae.
