NewsCryptoBitget breach freezes retail withdrawals as Sygnum offers institutions off-exchange custody

Bitget breach freezes retail withdrawals as Sygnum offers institutions off-exchange custody

Author: CryptoNewsNet·

Key Takeaways

  • •Bitget detected unauthorized transfers at 18:31 UTC on Sept. 24 and later lifted its loss estimate to about $387.5 million after adding Zcash and TRON transactions, with cold wallets untouched.
  • •Withdrawals were paused while deposits and trading stayed live, and the exchange pledged a withdrawal plan or status update by Sept. 26 at 04:00 UTC.
  • •Bitget said it identified and fixed the underlying vulnerability, with Mandiant and SlowMist aiding the probe, and froze an unquantified portion of the stolen assets via industry partners.
  • •On the day of the breach, Sygnum announced that eligible Bitget institutional clients can trade with pledged collateral kept in segregated, bankruptcy-remote custody at the Swiss bank under its Protect service.
  • •Bitget's User Protection Fund, listed at 5,500 BTC and valued above $464 million at the time, is positioned to cover losses from the incident.
Bitget breach freezes retail withdrawals as Sygnum offers institutions off-exchange custody

Bitget says approximately $387.5 million in assets was transferred to attacker-controlled addresses in a Sept. 24 wallet breach. Withdrawals remained suspended in notices issued through Sept. 25, even as deposits and trading continued to function.

The same day the breach was detected, Swiss bank Sygnum announced that Bitget's institutional clients could trade against collateral held at the bank rather than placing that collateral in Bitget's wallets.

The juxtaposition raises a question behind the promise of off-exchange custody: which assets sit beyond the reach of an exchange wallet breach, and what still depends on the exchange itself when trading or withdrawals are disrupted?

Sygnum's offering is available to eligible institutional clients who onboard directly with the bank. Neither company has disclosed how many Bitget clients use the service, or whether any Sygnum-held collateral was connected to the incident.

A breach alongside a new custody route

Bitget said its systems detected unauthorized transfers at 18:31 UTC on Sept. 24. Its initial notice put the affected funds at about $351.6 million and said the breach reached portions of its hot and warm wallet layers, while cold wallets remained secure. In exchange architectures of this kind, internet-connected hot wallets handle routine deposits and withdrawals, warm wallets serve as an intermediate buffer, and the bulk of reserves is held in offline cold storage.

In a Sept. 25 update, the raised its estimate of assets moved to attacker-controlled addresses to about $387.5 million after including Zcash and TRON transfers in a fuller accounting. Bitget said the revision did not reflect a fresh wave of unauthorized transfers.

According to Bitget, it identified and remediated the underlying vulnerability and contained the incident, with Mandiant, a cybersecurity firm owned by Google, and blockchain security specialist SlowMist assisting the investigation.

The withdrawal notice said withdrawals were temporarily unavailable while deposits and trading stayed operational, and the exchange committed to announcing a withdrawal plan or status update by Sept. 26 at 04:00 UTC. For a customer holding an ordinary Bitget balance, a displayed balance and the ability to trade do not by themselves provide an exit while withdrawals are paused: custodial balances sit on the exchange's internal ledger and can only leave the platform once the withdrawal function is restored.

How the Sygnum arrangement works

Sygnum said Bitget's institutional clients can use its Protect service for spot and derivatives trading while pledged collateral remains in Sygnum custody in Switzerland. Bitget mirrors the balance as trading margin. The model is part of a broader set of off-exchange settlement offerings in which collateral stays with a regulated third party while the trading venue mirrors it as margin.

The bank lists Bitcoin, Ethereum, stablecoins and US Treasuries among the eligible collateral. Its published process requires a client to onboard with Sygnum, sign a contractual framework, open a Protect portfolio, and pledge assets before receiving exchange margin.

Under Sygnum's description, the collateral is held in segregated accounts off the bank's balance sheet and is bankruptcy remote under Swiss banking law. Keeping pledged assets at the bank reduces direct custody exposure to Bitget's own wallets, and it addresses the concern that if an exchange faces financial distress, the collateral is intended to remain outside its estate. These are features of the arrangement as Sygnum describes them.

The announcement is dated Sept. 24 but does not state when Bitget client access became operational, whether the integration preceded the 18:31 UTC breach or arose in response to it, or whether any Bitget client had completed onboarding. It gives no Bitget-specific collateral balance and does not say whether Sygnum-held assets were involved in the incident. Figures cited in the release for Protect's total assets and the trading-volume share of all its integrated exchanges do not measure Bitget client uptake.

The limits of custody and a separate backstop

Protect's public page advertises flexible collateral top-ups and withdrawals. It does not publish the Bitget-specific contract that would determine when pledged assets can be released, how positions are settled, or what happens to margin if Bitget pauses its withdrawal service.

A trading balance mirrored at an exchange is also not the same thing as an ordinary customer's withdrawable exchange balance. Trading still depends on the exchange's order, margin, and settlement processes even when the pledged assets are held elsewhere.

Segregated custody can reduce exposure to theft from Bitget-held wallets and to Bitget insolvency, as Sygnum describes. However, the public materials do not establish that a Protect client can instantly reclaim pledged collateral during an exchange disruption, or that an exchange's operational problems could never delay settlement. They equally do not show that any Sygnum client is blocked from its collateral in this incident. The arrangement creates an optional boundary between institutional collateral and Bitget wallet custody.

For users holding assets on Bitget, the exchange pointed to its User Protection Fund. In its initial Sept. 24 notice, Bitget said the fund was worth more than $464 million and that the then-estimated $351.6 million incident fell within its coverage.

The fund's public page lists 5,500 $BTC and says users may claim for qualifying losses from platform-wide events beyond their own actions or trading behavior, with Bitget reserving the right to assess and investigate claims. The dollar value of a Bitcoin-denominated fund moves with Bitcoin's price: Bitget's report for August put the fund's monthly average at $382 million and its month-end value near $432 million on the same 5,500 $BTC holding.

Bitget also said it froze some affected assets through work with industry partners, though its Sept. 25 update did not quantify the frozen or recovered amount. Across the industry, such freezes typically depend on counterparties such as other exchanges and token issuers being able to blacklist attacker-controlled addresses.

The next measurable tests are a confirmed withdrawal timetable, a firmer loss and recovery accounting, and the terms of any fund disbursement. For the custody comparison, the missing facts are Bitget-specific Protect uptake and the contract governing collateral release and settlement when the exchange is under strain.