Bitget has confirmed a security breach affecting an estimated $351.6 million across portions of its hot and warm wallet infrastructure, prompting the exchange to suspend withdrawals while investigators assess the attack. Bitget detected the unauthorized transfers at 18:31 UTC on September 24 and says its cold wallets were not affected. The company has flagged attacker-linked addresses and engaged law enforcement and blockchain-security firms.
According to the official Bitget security notice, customer account balances remain accurate and the exchange says its User Protection Fund, currently valued above $464 million, is sufficient to cover the estimated loss. The $351.6 million figure remains an estimated affected amount while the security review and asset-recovery work continue. Bitget had reported an average Protection Fund value of $382 million in August, illustrating that the fund’s dollar value can fluctuate with its underlying assets.
Backend Investigation Rules Out Private-Key Theft
CEO Gracy Chen provided additional preliminary findings after the initial notice. She said investigators had found no evidence that attackers obtained private keys for Bitget’s cold, hot or warm wallets and clarified that the attackers did not forge customer withdrawal requests. The current working theory instead centers on unauthorized access to internal wallet infrastructure that enabled assets to be transferred directly. Bitget has not yet published enough technical evidence to establish the precise initial-access vector or failed control.
Chen said affected assets included ETH, XRP, USDT, USDC, AVAX, BNB and USDT0, with activity spanning Ethereum, XRP Ledger, Avalanche, BNB Smart Chain and Arbitrum. That multi-chain scope explains why early on-chain estimates around $170 million captured only part of the incident. The episode reinforces the importance of identifying the actual security boundary, as seen in other incidents where Chainflip isolated an exploit to its TRON USDT integration rather than the underlying blockchain.
Chen has also said preliminary IP evidence resembles infrastructure associated with a North Korean hacking group, but that attribution remains unconfirmed. No public law-enforcement attribution currently establishes who conducted the Bitget attack. The distinction between backend compromise and private-key theft is also operationally important: recent cases involving malicious mobile software stealing crypto keys involved a fundamentally different security failure.
Withdrawals Remain Paused During Security Review
Withdrawals remain unavailable while Bitget completes its security assessment. Standard deposits and trading were initially kept operational, although the exchange later reported delays in crediting some crypto deposits and separately suspended Bitget Onchain trading during the review. The incident therefore has broader operational effects than the withdrawal freeze alone, even though Bitget has not announced a halt to its core spot and derivatives trading systems.
Bitget’s response mirrors a common containment strategy in crypto infrastructure: restrict the movement path most relevant to the incident while keeping unaffected systems isolated. Similar security boundaries mattered when CoW Swap suspended frontend infrastructure after a DNS hijack and when other protocols paused only compromised components rather than their underlying networks. A service pause indicates containment activity, not proof that the root cause has already been eliminated.
Chen said some stolen assets have been recovered, but Bitget has not published an amount. The Protection Fund commitment therefore addresses customer-loss coverage separately from asset recovery, and the exchange’s statement that the fund exceeds $464 million remains a company-reported valuation rather than evidence that the entire incident has already been economically settled.
The next concrete milestone is Bitget’s promised full incident report, which is expected to document the root cause, affected systems and corrective actions, followed by restoration of withdrawals. Until that post-mortem is published, the confirmed picture is narrower: approximately $351.6 million was transferred without authorization from parts of Bitget’s hot and warm wallet infrastructure, cold wallets remained unaffected, and the exact intrusion mechanism is still being investigated.
