Trade Smarter. Win Bigger.

Up to Welcome Bonus

Bitget Confirms $351.6 Million Backend Hack as Withdrawals Remain Frozen

Bitget has confirmed a $351.6 million security breach in which attackers compromised a critical wallet backend, falsified transfer data and passed fraudulent transactions through the exchange’s authorization process.

The attack was detected at 18:31 UTC on September 24. It reached Bitget’s hot and warm wallets, while the company says its offline cold storage remained secure. Deposits and trading remain available, but withdrawals have been suspended without a confirmed reopening time, according to Bitget CEO Gracy Chen’s incident statement and CoinDesk’s September 25 update.

The Keys Were Not Stolen

Bitget says the attackers did not obtain its private keys. Instead, they compromised a system responsible for preparing transaction information and used forged data to trigger legitimate authorization infrastructure.

That distinction narrows the immediate risk. An attacker holding private keys could continue signing transfers until the wallets were emptied or the remaining assets were moved. Bitget says the unauthorized route has been closed and no further transfers are possible.

It does not make the failure less consequential. An exchange wallet system must validate the destination, asset, amount and approval conditions before a transaction is signed. If manipulated data can reach the signing stage, the authorization process becomes a mechanism for executing the attacker’s instructions.

The incident affected both the online hot-wallet layer and the semi-connected warm-wallet layer. Reaching the second tier suggests that the compromise extended beyond one exposed transaction server or individual operational wallet.

Protection Fund Faces Its Largest Test

Bitget says its User Protection Fund holds more than $464 million and can absorb the entire loss. On the reported figures, the fund exceeds the breach by approximately $112 million.

The nominal balance alone does not establish how rapidly the fund can be converted into the specific assets owed to customers. Token composition, custody, market liquidity and price movement determine whether the protection remains sufficient during a stressed withdrawal period.

Bitget says customer account balances remain accurate. The decisive verification will come when withdrawals reopen and users can redeem those balances outside the exchange.

Keeping trading open while withdrawals are suspended also requires close monitoring. Internal trades can continue changing customer positions even though assets cannot leave the platform. Bitget will need to show that its remaining reserves, matching systems and settlement records stayed intact throughout the incident.

A Backend Failure, Not a Blockchain Failure

The affected blockchains appear to have processed validly signed transactions exactly as designed. The security breakdown occurred within Bitget’s centralized wallet and approval infrastructure.

This attack pattern demonstrates why proof of reserves cannot answer every exchange-risk question. Reserve attestations may show that assets existed at a measured time, but they do not prove that transaction preparation, signing policies, access controls and withdrawal systems are resistant to internal compromise.

The exchange has promised a complete technical report after the intrusion method is confirmed. That report needs to identify the initial access route, the systems altered, why the forged transactions passed validation, how warm wallets became accessible and what controls have been rebuilt.

TOKEN RECON ASSESSMENT

Bitget has contained the visible outflow, but containment is only the first defensive position.

The company’s claim that private keys remained secure is encouraging because it limits the attacker’s continuing authority. It also shifts attention toward transaction integrity. A signing key is not protective when the system feeding it instructions cannot distinguish a legitimate withdrawal from fabricated backend data.

The protection fund now faces a real-world solvency and liquidity test. Token Recon will treat “user funds are safe” as an operational claim until customers can withdraw normally and the exchange publishes updated reserve and protection-fund evidence.

Watch:

  • Restoration of withdrawals
  • A complete technical postmortem
  • Independent confirmation that private keys were not compromised
  • The protection fund’s asset composition and deployment
  • Updated proof-of-reserve information
  • Changes to transaction validation and warm-wallet controls
  • Movement from identified attacker addresses
  • Any regulator or law-enforcement response

The breach is large enough to rank among the most consequential centralized-exchange failures of 2026. The next measure of Bitget’s response is not whether trading remains open. It is whether customers can remove their assets at full value.

Sources

CoinDesk: Bitget says spoofed transfers enabled the $351.6 million hack

The Block: Bitget confirms exchange wallet breach

Gracy Chen: Technical description and containment update

Gracy Chen: Customer-fund and cold-wallet statement

+ posts

RELATED ARTICLEs

Get exclusive intelligence,
market updates, and
recon reports straight
to your inbox.

RECON.
ANALYZE.
DECIDE.

STAY AHEAD.
STAY INFORMED.