Bitget Confirms $351.6 Million Wallet Breach, Suspends Withdrawals
Key Takeaways
- •Approximately $351.6 million was moved without authorization from Bitget's internet-connected hot and warm wallet layers, while its offline cold wallets remained untouched.
- •Bitget suspended withdrawals as a containment measure, but deposits and regular trading stayed operational, and no timeline for restoring withdrawals has been announced.
- •The entire loss is covered by Bitget's User Protection Fund, which held more than $464 million when the incident was disclosed, exceeding the amount stolen.
- •A September 17 proof-of-reserves recorded a 135% aggregate reserve ratio across 19 covered assets, released one week before the breach.
- •Bitget has not identified the attacker or confirmed the attack method, and a full report on the root cause and corrective measures is due within 24 hours of its initial disclosure.

Bitget has confirmed that approximately $351.6 million in unauthorized transfers occurred from portions of its wallet infrastructure after the exchange detected abnormal activity at 18:31 UTC on September 24.
According to the exchange, the incident was contained to parts of its hot and warm wallet layers within its three-tier custody system. Its cold wallets were not affected. Hot wallets stay connected to the internet to process day-to-day withdrawals, while cold wallets remain offline for long-term storage, a structure designed to keep deeper reserves out of reach if online infrastructure is compromised.
Bitget activated its emergency response process within minutes of the detection, identified and flagged addresses connected to the transfers, and notified law-enforcement agencies and on-chain security firms. The company published incident notices on its official support portal and addressed the event on X.
Withdrawals Paused During Security Review
Bitget suspended withdrawals while its security team reviews the affected infrastructure, a standard containment measure while investigators trace fund movements. Deposits and regular trading remained available under the exchange's initial operational notice. Bitget later said its separate Onchain trading service had also been temporarily affected by the security review and was unavailable early on September 25.
The exchange said withdrawal services will resume after the review is completed. No restoration time had been announced in its latest public support notices.
The shutdown follows precautionary moves by other crypto services after recent security incidents. Blink temporarily paused services after unauthorized withdrawals from custodial accounts, while Swiss Bitcoin Pay took its servers offline following suspected unauthorized access to internal systems.
Protection Fund Exceeds Reported Loss
Bitget said the entire loss falls within its User Protection Fund, which held more than $464 million when the incident was disclosed. The fund was created separately from the exchange's reserves to provide an additional layer of financial protection for users, and Bitget has committed to keeping its valuation above $300 million. Dedicated funds of this kind serve as capital buffers that exchanges maintain to absorb losses from security incidents without drawing on customer balances.
A September 17 Proof of Reserves report recorded a 135% aggregate reserve ratio across 19 covered assets. The snapshot was published one week before the breach and marked Bitget's 46th monthly reserve update since December 2022. Proof-of-reserves reports are published snapshots intended to show that an exchange's holdings cover customer balances, a practice that spread across major exchanges after the 2022 collapse of FTX.
The exchange said user account balances remain accurate and that affected assets will be covered through the protection mechanism.
No Attacker Attribution Published
Bitget has not publicly identified the attacker or confirmed the technical method used to initiate the unauthorized transfers. Its incident notice specifically states that the exchange will not speculate about the attack vector before the investigation is completed.
Bitget has also not attributed the breach to North Korea's Lazarus Group in its published security notice. Lazarus is a hacking collective linked to North Korea that government agencies have connected to some of the crypto sector's largest thefts. Any attribution will require separate evidence from the exchange, law enforcement, or investigators directly involved in tracing the incident.
A full incident report covering the root cause and corrective measures is scheduled for publication within 24 hours of Bitget's initial disclosure. The report and the timeline for restoring withdrawal services are the main developments to watch as the review continues. Withdrawals remained suspended as of the latest official update while the security review continued.