First action: open the official app or type bitget.com yourself, then verify balances, orders and live withdrawal status. Bitget says users do not need to register for compensation or move assets to an outside “safe address.”

1. Preserve records before making changes

  • Capture total and asset balances, recent deposits and withdrawals, open orders, positions and your UID.
  • Download available account or transaction records and note the timestamp.
  • If anything is wrong, use the in-site support ticket and retain its number.
  • Do not panic-sell into a thin market merely because a withdrawal rail is temporarily unavailable.

2. Audit account security

  1. Review recent logins and remove unknown devices.
  2. If a password was reused, secure the email account first and then set a unique Bitget password.
  3. Verify that 2FA, passkeys, anti-phishing code and withdrawal whitelist remain under your control.
  4. Delete unused or unknown API keys, especially those with trading or withdrawal privileges.
  5. Check for unfamiliar addresses, subaccounts, connected apps or security-setting changes.

Bitget currently attributes the incident to exchange wallet backend infrastructure, not a broad leak of customer passwords or private keys. That does not require every user to rotate every credential in panic, but event-themed credential phishing makes an audit worthwhile.

3. Test withdrawals after reopening

  1. Confirm the specific asset and network are enabled inside the authenticated account.
  2. Ensure the destination supports the same network; USDT-TRC20, ERC20 and Solana are not interchangeable.
  3. Send a small amount you can afford to lose and wait for it to settle.
  4. Recheck address and network before sending any larger amount in batches.
  5. Do not repeatedly submit a delayed request or pay a private-message “support agent” an acceleration fee.

Should everyone withdraw everything?

There is no universal answer. Small trading balances on an exchange provide convenience; long-term assets that are not actively traded can be diversified across appropriate custody methods. Rushing into self-custody without knowing seed backup, network selection and approval risks can replace platform risk with irreversible user error.

ChoiceRisk reducedNew risk
One exchangeSimple operationsConcentrated platform and withdrawal risk
Several suitable platformsLess dependence on one venueMore accounts, KYC and attack surface
Self-custodyLess exchange-custody exposureSeed, phishing, wrong-network and approval responsibility

Five common post-incident scams

  • A compensation form asking for a password or seed phrase.
  • Priority withdrawals that require a deposit or guarantee fee.
  • An “official migration” to an outside wallet.
  • Fake BGB or USDT compensation tokens that request unlimited approval.
  • A recovery firm demanding advance payment or remote access.
Official support does not need your seed phrase, private key, password, SMS code or 2FA code. Anyone requiring an external transfer to restore withdrawals should be treated as a scam risk.

If a balance or withdrawal is wrong

  1. Record UID, asset, network, amount, time, status, address and TxID.
  2. Open an official support ticket without posting full account details publicly.
  3. If there is a TxID, use the matching block explorer to distinguish unbroadcast, pending and delivered transactions.
  4. Preserve tickets, emails and screenshots; report genuine unauthorized transactions to law enforcement with onchain evidence.

Based on Bitget disclosures available September 28, 2026. Investigation, recovery and service status may change. Read the verified timeline and impact analysis.