Bitget Confirms $351.6 Million Wallet Breach as Withdrawals Remain Suspended
Key Takeaways
- โขBitget confirmed that unauthorized transfers of approximately $351.6 million in cryptocurrency occurred from part of its internet-connected hot and warm wallet infrastructure, with suspicious activity detected at 18:31 UTC on September 24.
- โขCold wallets remain secure and customer account balances are accurate, while deposits and trading continue but withdrawals are temporarily suspended pending a security review.
- โขBitget flagged the addresses tied to the unauthorized transfers and notified law enforcement and on-chain security firms to enable coordinated tracing, though it has not disclosed how attackers gained access.
- โขThe exchange's User Protection Fund holds more than $464 million, exceeding its $300 million minimum target and providing sufficient coverage for the amount involved in the breach.
- โขBitget has committed to providing hourly updates and plans to publish a full incident report covering the root cause and corrective actions within 24 hours.

Bitget has confirmed that a security breach affecting part of its hot and warm wallet infrastructure resulted in unauthorized transfers of approximately $351.6 million in cryptocurrency. The exchange detected the suspicious activity at 18:31 UTC on September 24 and immediately activated its emergency response procedures.
Hot and warm wallets are internet-connected systems exchanges rely on for operational liquidity, making them a recurring focal point in exchange security incidents, while cold wallets are kept offline by design. According to the company, its cold wallets remain secure and customer account balances remain accurate. Deposits and trading continue to operate, while withdrawals remain temporarily suspended as Bitget completes a security review โ a containment measure exchanges commonly adopt while assessing potentially compromised infrastructure.
Unusual On-Chain Movements Raised the Alarm
The incident first drew attention after unusual on-chain movements were detected in wallets associated with Bitget, with early estimates placing the suspicious transfers below the final figure the exchange ultimately disclosed.
Bitget said it has since identified and flagged the addresses linked to the unauthorized transfers, and has notified law enforcement agencies as well as on-chain security firms. Sharing the flagged addresses with on-chain security firms enables coordinated tracing and monitoring of the funds as they move across public blockchains. The exchange has not disclosed how the attackers gained access, stating that it will refrain from speculating about the attack vector while its investigation continues.
Protection Fund Said to Cover the Losses
Bitget stated that its User Protection Fund currently holds more than $464 million, which the exchange said provides sufficient coverage for the approximately $351.6 million affected in the incident. The fund was created to safeguard user assets and has previously maintained a minimum target of $300 million, a level that the latest reported balance exceeds relative to the amount involved in the breach.
The exchange has pledged to provide hourly updates and plans to publish a full incident report covering the root cause and corrective actions within 24 hours. Until that review is complete, withdrawals remain paused as Bitget works to secure its wallet infrastructure and assess the affected assets. The promised incident report, along with any announcement on when withdrawals resume will be the key developments to follow as the security review progresses.
Source: CryptoMeter io