Bitget's $388m hack: what Pakistan's crypto rules would demand
Bitget says its customers lost nothing in last week's $388 million theft, and its P2P market, which lists rupee trades through Easypaisa and JazzCash, reopens on Friday afternoon. Here is what Pakistan's new rulebook would require of an exchange in the same position, and what you can and cannot chec
Key takeaways
- Attackers took about $388 million from Bitget's hot and warm wallets on 24 September, according to the exchange. Bitget says its cold wallets were untouched.
- Bitget says user balances are unaffected and its own Protection Fund covers the loss. Fiat and P2P withdrawals are scheduled to resume at 13:00 PKT on 2 October.
- Pakistan's licensing regulations would require a licensee to notify PVARA without delay, reconcile customer assets daily and hold insurance, which PVARA can require to include cyber cover.
- Bitget has been reported as preparing to enter PVARA's process. PVARA has not published who applied, and there is no public register to check.
What happened
At about 18:31 UTC on 24 September (23:31 in Pakistan), someone began moving funds out of Bitget's wallets. In its incident page, last updated on 30 September, the exchange puts the total at "approximately $388 million" taken from "hot and warm wallet infrastructure". It says "cold wallets across all chains were not affected."
Bitget's chief executive, Gracy Chen, told The Block that the attacker first sent two small test transfers below the exchange's risk-control limits, then moved most of the money in 17 transactions over about 70 minutes. Bitget says the attacker "may have exploited a vulnerability in a third-party security product" to obtain high-level internal credentials and send fraudulent withdrawal commands. The security firm SlowMist, reported by Cointelegraph, traces the earliest malicious activity to 31 August, more than three weeks before the theft.
"An incident like this scale is very serious. But serious doesn't mean existential," Chen told The Block.
What Bitget says about customers' money
Bitget's position is that no customer is out of pocket. "User account balances remain unaffected," its incident page says, and the loss falls within its Protection Fund, a reserve the exchange holds itself. Chen told The Block the fund held about $465 million on 25 September and would be topped back up to at least $300 million within a week from corporate reserves.
These are Bitget's statements. We have not seen an independent audit of the fund or of customer balances, and none has been published.
Withdrawals were paused on 24 September and are coming back one asset at a time, each at 08:00 UTC (13:00 PKT):
| Date | What resumes |
|---|---|
| 28 September | Bitcoin |
| 29 September | Ether |
| 30 September | USDT |
| 2 October | Other assets, fiat and P2P |
For Pakistani users the last row is the one that matters. Bitget's P2P market lists PKR trades, with Easypaisa and JazzCash among its payment methods, and it is the final service scheduled to reopen.
What Pakistan's rules would demand of a licensee
Pakistan has a full rulebook for crypto exchanges, the Pakistan Virtual Asset Services Regulations, 2026, notified by PVARA on 21 August. They bind licensees, and no exchange holds a PVARA licence yet. Bitget does not, so none of what follows applies to it today. It is a description of what a licensed exchange would face after an incident like this one.
- Tell the regulator. A licensee must notify PVARA "without delay" when it is failing, or likely to fail, a requirement, and must file a remedial plan (regulation 35(2)). If the failure comes through an outside supplier, regulation 43(1) separately requires notice of a "material disruption, outage, incident, or control failure".
- Own the supplier's failure. A licensee that outsources "remains fully responsible for compliance" (regulation 37(1)). The rule on key and wallet management requires controls over "technology dependencies, integrations, and service providers involved in key or wallet operations" (regulation 61(2)(f)), as well as segregation of duties for anyone who can initiate or approve a transaction (61(2)(c)).
- Keep customer assets separate and counted. Client assets "are not owned by the Licensee" (regulation 109(2)). An exchange that moves client assets daily must reconcile them at least daily (111(1)), report any material shortfall it cannot fix to PVARA "without delay" (111(3)), and show its liabilities to clients are fully matched by reserves (112(1)).
- Carry insurance, and don't oversell it. A licensee must hold insurance that PVARA can specify to include cyber risk cover (regulation 36(2)(c)). The insurer must normally be licensed in Pakistan, and the licensee "shall not represent insurance as a guarantee of customer recovery" (36(5)).
- Expect consequences. PVARA may suspend a licence when a licensee "has suffered a material cybersecurity, operational, or safeguarding incident" (regulation 13(1)(d)).
One contrast is worth drawing. Bitget's cover is a fund the exchange holds itself. Pakistan's rules ask for insurance from an outside insurer instead, and they explicitly stop an exchange from presenting that cover as a promise that customers will be repaid.
Where Bitget stands in Pakistan
In mid-2026 TechJuice reported that Bitget was preparing to enter PVARA's process, following Binance and HTX. That report did not say Bitget had applied for, or received, a no-objection certificate (NOC).
We could not confirm Bitget's status from the regulator. On 1 October, PVARA's news page named only Binance and HTX as NOC recipients, in an item dated December 2025. Its licensing page still says licences will come "when full licensing becomes available". The addresses pvara.gov.pk/licensees and pvara.gov.pk/register returned "not found". The regulations require PVARA to publish "an up-to-date public register of Licensees" (regulation 9(6)), but with no licensees there is nothing yet to list. PVARA has not published who met the 5 September deadline for existing operators to apply.
Update: (October 2, 2026 7:35PM PKT)
- New facts from CNBC today:
- About $1.1m of the stolen funds is frozen, and the CEO doesn't expect to recover much;
- Bitget has refilled its Protection Fund above $300m;
- its own reserves report shows a 131% reserve ratio, which nobody has audited;
- the Mandiant and SlowMist investigation reports don't blame North Korea.
- Industry context: CertiK counts $1.26bn lost to crypto hacks in July–September, and Bitget's was the largest.
- Not confirmed: whether P2P actually reopened at 13:00 PKT. Bitget's page still says "scheduled" and hasn't changed since 30 Sep, and the update says so.
What this means for Pakistani users
- If you have funds on Bitget, Bitget says your balance is intact. Check it yourself after P2P reopens at 13:00 PKT on 2 October, before relying on it.
- Expect a queue. Everyone whose withdrawal was paused will be trying at the same time. Don't send PKR to a P2P counterparty until the platform shows your order as live, and keep to the escrow flow. We explained how P2P escrow works.
- No Pakistani regulator stands behind any exchange today. That includes Binance and HTX, whose NOCs are not licences. If an offshore exchange fails, your recourse is that exchange's own terms and whatever fund it chooses to keep.
- A protection fund is a promise, not a guarantee. Bitget says it is covering this loss from its own. The next exchange may not have one, or may not be able to pay.
What we're watching
- Whether Bitget's P2P and fiat withdrawals reopen on schedule on 2 October. We will update this article in place.
- Bitget's promised incident report, and whether the third-party product is named.
- Whether PVARA publishes a list of NOC applicants, or says anything about how exchanges in its process handle incidents like this.
- Our PVARA licence tracker will record the first licence, and the register that has to follow it.
Sources
- Bitget, Bitget Security Incident: What Happened, Timeline, Impact and Response, updated 30 September 2026.
- The Block, "Bitget attacker tested risk controls with small transfers before $388 million theft, CEO says", 28 September 2026.
- Cointelegraph, "SlowMist traces Bitget hack activity to Aug. 31 zero-day exploit".
- PVARA, Pakistan Virtual Asset Services Regulations, 2026 (S.R.O. 1419(I)/2026), regulations 9, 13, 35, 36, 37, 43, 61 and 109 to 112.
- PVARA, News & Updates and Licensing, checked 1 October 2026.
- Bitget, P2P trading, PKR, checked 1 October 2026.
- TechJuice, "Global Crypto Giant Bitget Set to Enter Pakistan's Regulated Market".