1. Preserve records before making changes
- Capture total and asset balances, recent deposits and withdrawals, open orders, positions and your UID.
- Download available account or transaction records and note the timestamp.
- If anything is wrong, use the in-site support ticket and retain its number.
- Do not panic-sell into a thin market merely because a withdrawal rail is temporarily unavailable.
2. Audit account security
- Review recent logins and remove unknown devices.
- If a password was reused, secure the email account first and then set a unique Bitget password.
- Verify that 2FA, passkeys, anti-phishing code and withdrawal whitelist remain under your control.
- Delete unused or unknown API keys, especially those with trading or withdrawal privileges.
- Check for unfamiliar addresses, subaccounts, connected apps or security-setting changes.
Bitget currently attributes the incident to exchange wallet backend infrastructure, not a broad leak of customer passwords or private keys. That does not require every user to rotate every credential in panic, but event-themed credential phishing makes an audit worthwhile.
3. Test withdrawals after reopening
- Confirm the specific asset and network are enabled inside the authenticated account.
- Ensure the destination supports the same network; USDT-TRC20, ERC20 and Solana are not interchangeable.
- Send a small amount you can afford to lose and wait for it to settle.
- Recheck address and network before sending any larger amount in batches.
- Do not repeatedly submit a delayed request or pay a private-message “support agent” an acceleration fee.
Should everyone withdraw everything?
There is no universal answer. Small trading balances on an exchange provide convenience; long-term assets that are not actively traded can be diversified across appropriate custody methods. Rushing into self-custody without knowing seed backup, network selection and approval risks can replace platform risk with irreversible user error.
| Choice | Risk reduced | New risk |
|---|---|---|
| One exchange | Simple operations | Concentrated platform and withdrawal risk |
| Several suitable platforms | Less dependence on one venue | More accounts, KYC and attack surface |
| Self-custody | Less exchange-custody exposure | Seed, phishing, wrong-network and approval responsibility |
Five common post-incident scams
- A compensation form asking for a password or seed phrase.
- Priority withdrawals that require a deposit or guarantee fee.
- An “official migration” to an outside wallet.
- Fake BGB or USDT compensation tokens that request unlimited approval.
- A recovery firm demanding advance payment or remote access.
If a balance or withdrawal is wrong
- Record UID, asset, network, amount, time, status, address and TxID.
- Open an official support ticket without posting full account details publicly.
- If there is a TxID, use the matching block explorer to distinguish unbroadcast, pending and delivered transactions.
- Preserve tickets, emails and screenshots; report genuine unauthorized transactions to law enforcement with onchain evidence.
Based on Bitget disclosures available September 28, 2026. Investigation, recovery and service status may change. Read the verified timeline and impact analysis.