Bitget resumes Bitcoin withdrawals as hacker swaps ETH via THORChain
Ether withdrawals are scheduled to return Tuesday and USDt on Wednesday as Bitget restores services following last week’s $388 million hack.
Asanat Analysis — Why it matters
Bitget's phased withdrawal resumption signals partial recovery from a significant infrastructure breach, but the staged rollout (BTC → ETH → USDT) suggests ongoing forensic work and liquidity management rather than full operational confidence. The $388M loss represents one of the largest centralized exchange hacks in recent years—comparable to the 2014 Mt. Gox incident in scale—and underscores persistent custody and hot-wallet vulnerabilities despite industry maturation.
The hacker's use of THORChain to swap ETH indicates sophisticated laundering tradecraft: cross-chain atomic swaps provide partial obfuscation compared to direct exchange deposits, though blockchain forensics can still track flows. This mirrors evolving attack patterns where threat actors exploit DEX liquidity and bridge infrastructure post-theft. Bitget's recovery timeline and communication cadence will be closely monitored by institutional users and regulators assessing the exchange's operational resilience and insurance/reserve mechanisms.
For the sector, this reinforces the custody debate favoring self-hosted solutions and hardware wallets for material positions, while raising questions about exchange insurance funds and whether $388M+ loss thresholds trigger regulatory intervention or fund-raising obligations. The incident also highlights THORChain's role as preferred infrastructure for capital flight—a regulatory pressure point if exchanges face mandatory asset-freezing requirements.