Bitget has confirmed a major security breach involving approximately $351.6 million in affected cryptocurrency assets, replacing earlier estimates that put suspicious transfers between $170 million and $183 million.
Bitget CEO Gracy Chen said the exchange detected unauthorized transfers involving a limited number of wallets at approximately 18:31 UTC on September 24. Bitget activated its emergency response procedures and temporarily suspended withdrawals while investigating the incident.
The first public indications of trouble came from blockchain activity. More than $170 million initially moved from Bitget-labeled wallets to a newly created address, with ETH, USDT, USDC, AVAX, BNB and other assets appearing among the transfers. As additional transactions were identified, the estimated exposure increased substantially.
Bitget’s subsequent disclosure placed the amount affected at approximately $351.6 million. The exchange says the incident involved a limited portion of its wallet infrastructure and that its cold wallets remain secure. Bitget also says customer balances remain intact.
Withdrawals have been temporarily suspended while Bitget conducts a security review. Trading and deposits remain operational, according to the company’s statements reported following the breach. The suspension is significant because restoring normal withdrawals will provide one of the clearest operational signals that Bitget believes the immediate threat has been contained.
Chen said Bitget’s User Protection Fund, valued at more than $464 million, is sufficient to cover the currently reported loss. The protection fund was established to provide an additional financial safeguard for users during qualifying security incidents. The size of the fund exceeds Bitget’s present estimate of assets affected by the breach.
The attack vector remains one of the most important unanswered questions. Bitget has not yet publicly explained how the unauthorized transfers were initiated or how access to the affected wallet infrastructure was obtained. Until the forensic investigation is completed, the technical cause of the breach should remain classified as unknown.
Bitget says addresses associated with the unauthorized transfers have been identified and flagged, while the exchange is coordinating with law enforcement and blockchain security organizations. A more detailed incident report is expected to provide information about the root cause, affected infrastructure and corrective measures.
TOKEN RECON ASSESSMENT
The intelligence picture has changed materially since the first onchain alerts.
This is no longer a suspected security incident based solely on unusual wallet movements. Bitget’s leadership has acknowledged unauthorized transfers affecting approximately $351.6 million and withdrawals have been suspended.
The size of Bitget’s protection fund provides an important financial buffer, but reimbursement capacity and security integrity are separate issues. The central question is how an attacker gained access to the affected wallet infrastructure and whether Bitget can demonstrate that the vulnerability has been contained.
Withdrawal restoration will be an important confirmation signal. Token Recon is also watching for movement from identified attacker addresses, intervention by stablecoin issuers, asset recovery or freezes, changes to the $351.6 million loss estimate and Bitget’s forensic explanation of the breach.
The next intelligence checkpoint is Bitget’s detailed incident report. That report should determine whether this was an isolated wallet compromise or evidence of a broader weakness in the exchange’s custody architecture.
Sources
Bitcoin Magazine, Nearly $352M Moved From Crypto Exchange Bitget Wallets in Suspected Hack
CoinDesk, Bitget Says $352 Million Affected in Hack
TheStreet, Bitget CEO Confirms $351.6M Hack and Withdrawals Paused
CryptoSlate, Bitget’s $351.6 Million Hack Pushes September Crypto Losses Higher