NewsCryptoBitget Halts Withdrawals After $351.6 Million Hot Wallet Security Incident

Bitget Halts Withdrawals After $351.6 Million Hot Wallet Security Incident

Author: Crypto Ninjas·

Key Takeaways

  • •Bitget reported roughly $351.6 million in unauthorized transfers from parts of its hot and warm wallet layers on September 24, while its cold wallets remained unaffected.
  • •The exchange suspended withdrawals after detecting abnormal transfers at 18:31 UTC, but deposits and trading continued functioning during the ongoing security review.
  • •User balances remain accurate, and the affected is protected by Bitget's User Protection Fund, which exceeds $464 million.
  • •CEO Gracy Chen stated that preliminary investigation uncovered IP addresses possibly connected to VPN services owned by a DPRK-backed hacking group, while emphasizing this is an investigative clue rather than confirmed attribution.
  • •Bitget urged its wallet users to revoke contract approvals, confirmed its independent self-custody wallet infrastructure was unaffected, and plans to publish a full incident report covering the root cause and corrective actions.
Bitget Halts Withdrawals After $351.6 Million Hot Wallet Security Incident

Crypto exchange Bitget on September 24 reported unauthorized transfers totaling approximately $351.6 million from part of its hot and warm wallet infrastructure, describing the event as one of the largest crypto security incidents of 2026. The company told reporters that its cold wallets remain intact and that deposits and trading are still functioning, while withdrawals have been suspended for the time being as its security team examines the situation.

Abnormal Transfers Detected at 18:31 UTC

According to the exchange, its security systems detected abnormal transfers at 18:31 UTC on September 24 and triggered its emergency response procedures within minutes. Bitget estimates that about $351.6 million was affected.

The company's official X account posted the following about the incident:

Live about Bitget Hot Wallet Incident on September 24, 2026 — Bitget (@bitget) September 24, 2026 (source)

Only Parts of Hot and Warm Wallet Layers Affected

Bitget said the event affected only portions of the company's hot and warm wallet layers. Its official security notice states that cold wallets were not affected. The exchange also noted that funds in users' accounts remain accurate and that the affected amount is protected by its User Protection Fund, which exceeds $464 million. Protection funds of this kind are reserve pools that major exchanges maintain to cover user losses stemming from security incidents.

Withdrawals are suspended while the security review is carried out, but Bitget's recent update says trading and deposits were still open. Suspending outbound transfers while other functions stay live is a containment step exchanges commonly take during active security reviews, since withdrawals are the main channel for moving funds off a platform. The exchange revealed that it has detected and marked the abnormal receiving addresses and has informed police and blockchain security firms.

Bitget Wallet Users Urged to Revoke Contract Approvals

The incident also prompted a precautionary advisory for Bitget Wallet users. Bitget urged users to revoke their current contract permissions as part of the investigative protocol and to refrain from certain trading activity until more information is provided. Token approvals give smart contracts standing permission to interact with a user's funds, which is why clearing unused ones is a routine precaution during platform-related security incidents. According to the exchange's own security advice, users should review their approval logs and cancel permissions that are no longer required, as removing unneeded token permissions can lower the chances of exposure to unwanted contract interactions.

Bitget Wallet further announced that it was not affected by the incident with respect to its own wallet systems and user assets, adding that its self-custody wallet infrastructure is independent of the exchange's custody wallet network.

Investigation Turns to the Attack Route

For now, Bitget has not publicly announced the specific flaw that enabled the unauthorized transfers. The exchange did not reveal further details about the attack vector in its official notification, saying it would withhold that information until investigations are complete.

Gracy Chen, the company's CEO, later said the preliminary investigation showed IP addresses that could have been related to VPN services owned by a DPRK-backed hacking group. She emphasized that it was an investigative clue and not a finalized attribution. DPRK-linked groups have been tied by United Nations investigators and blockchain analytics firms to a series of large cryptocurrency thefts in recent years, a pattern that explains the close scrutiny such a clue attracts before attribution is confirmed.

On-chain analysts have observed assets pouring into new addresses and being traded between decentralized exchanges (DEXs). However, those blockchain movements have not yet been mapped to their owners, nor has the manner in which the initial break-in was made been established. Tracing on public blockchains is typically incremental, as analysts follow assets across addresses and venues step by step before recipients can be identified or funds frozen.

Crypto Exchange Security Under the Spotlight

The incident highlights the differences among hot wallets, warm wallets and cold storage at centralized crypto exchanges. Hot wallets remain connected to systems that facilitate transactions, making them useful for day-to-day withdrawals but also exposing them to a larger online attack surface. Cold wallets are kept offline or otherwise isolated from routine online operations. Warm wallets sit between the two under tighter access controls and limited connectivity, and exchanges run such layered setups to balance day-to-day liquidity against the risk of keeping large sums online.

Bitget said the investigation is ongoing and that it plans to publish a full incident report covering the root cause and corrective actions. The exchange has also said withdrawals will resume after its security review is completed. Until then, the open questions are the root cause detailed in that report, the timeline for restoring withdrawals, and whether the preliminary clues lead to confirmed attribution.

Source: Crypto Ninjas