BingX began restoring cryptocurrency withdrawals on September 21, 2024, after an apparent hot-wallet breach led the exchange to suspend asset transfers and move funds into safer storage.

The exchange’s notice scheduled the first withdrawals for 08:30 UTC+8 on September 21. The initial group covered USDT, USDC, bitcoin, ether, TRX, XRP and solana. Other assets remained subject to a phased reopening and additional security review.

The development mattered because withdrawal access is a direct test of an exchange’s ability to honor customer claims after a custody failure. Reopening selected routes reduced the immediate operational disruption, but it did not establish the breach’s final cost, its technical cause or whether every customer and asset had regained normal transfer access.

A breach followed by emergency controls

BingX said its technical team detected abnormal access at approximately 04:00 UTC+8 on September 20, 2024, potentially indicating an attack on one of its hot wallets. It responded by transferring assets urgently and suspending withdrawals.

Hot wallets remain connected to operational systems so exchanges can process routine transfers. That accessibility also creates a different exposure from cold storage, where signing material is kept offline or otherwise isolated. BingX said most platform assets were held in cold wallets and characterized the affected amount as a minor loss that it could cover. Those were contemporaneous company claims, not an independently audited balance-sheet finding.

External estimates were substantially larger than the exchange’s initial characterization. The Block reported that blockchain-security company PeckShield estimated approximately $43 million in cryptocurrency had been removed in multiple tranches. Cointelegraph reported estimates ranging as high as $52 million from Cyvers, while noting that BingX was still calculating the loss.

Those dollar figures were forensic firms’ event-period valuations of multiple tokens across chains, not a final accounting figure. They depended on which wallets and transfers each firm attributed to the incident and on token prices used for conversion. The divergence made a single definitive loss number unavailable on September 21.

Withdrawal access returned in stages

BingX’s restoration notice did not describe a complete return to normal operations. It said withdrawals for assets outside the initial group would resume gradually. Requests for those other assets would be processed at 16:00 UTC+8 each day while security reviews continued.

The exchange also canceled withdrawal requests submitted before the reopening. Customers who still wanted to transfer their assets had to submit new requests. Deposits remained suspended on September 21, according to the event-day notice.

This distinction is important. Restoring seven withdrawal assets demonstrated that part of the wallet system was functioning, but it did not prove that all networks, tokens or customer requests were available without delay. Nor did it provide an independent test of reserves or establish that the attacker’s access had been conclusively eliminated.

Trading availability was also separate from custody access. An exchange can continue matching trades internally while deposits or withdrawals are restricted. Customers may therefore see account balances and execute trades without being able to move every asset off the platform.

What remained unknown on September 21

BingX had not published a technical root-cause analysis by September 21. Its notices did not identify the attacker, the compromised credentials or systems, the complete set of affected wallets, or a final asset-by-asset loss ledger.

No defensible market-price effect is attributed to the incident. The stolen assets spanned multiple tokens and networks, cryptocurrency trading continued across unrelated venues, and the reviewed evidence supplies no controlled window for isolating the breach’s effect on bitcoin, ether or another instrument.

The event-day conclusion was narrower: BingX restored withdrawal access for seven major assets while the exchange’s security review and loss calculation remained incomplete. That was meaningful operational progress after a custody breach, but not evidence that the incident had been fully resolved.

Later confirmation

A BingX FAQ dated September 25 later said the selected withdrawals had resumed before 08:30 UTC+8 on September 21 and that initial deposit services opened on September 22. That later company record confirms the stated sequence but does not resolve the event-day uncertainty over loss size, cause or independent reserve verification.

Primary sourceBingX — Notice on Resumption of Withdrawal Services

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.