- $351.6 million affected: Bitget says unauthorized transfers from parts of its hot and warm wallet infrastructure affected approximately $351.6 million in digital assets.
- Cold wallets unaffected: The exchange says its cold-storage holdings remained secure and customer account balances remain accurate.
- $464 million protection fund: Bitget says its User Protection Fund contains more than $464 million, providing coverage above the reported affected amount.
Bitget confirmed a security breach on Sept. 24 after detecting unauthorized transfers from parts of its hot-wallet infrastructure. The exchange initially faced on-chain reports of more than $170 million moving from wallets associated with the platform before its estimated affected amount reached approximately $351.6 million.
Bitget said the incident was limited to parts of its hot and warm wallet layers and did not compromise its cold wallets. Withdrawals were temporarily suspended while the investigation continued, while deposits and trading remained operational.
How the Bitget Breach Happened
Bitget CEO Gracy Chen said attackers compromised a critical backend system connected to the exchange’s wallet infrastructure. According to Bitget, the attackers manipulated transaction information and used the compromised system to trigger the platform’s authorization process.
The distinction between hot wallets, warm wallets and cold storage is important for understanding the incident. Hot wallets are connected to systems that support routine transactions, while cold wallets are designed to keep assets isolated from normal online operations. Bitget said its cold-storage holdings were not affected.
On-chain monitoring identified several cryptocurrencies connected to the incident, including Ethereum (ETH), XRP, BNB, Avalanche (AVAX), USDT and USDC. Ethereum’s role in large crypto transactions also makes the security of exchange infrastructure relevant to the wider Ethereum market.
The initial on-chain reports focused on roughly $170 million transferred to a newly created address. Further investigation showed that the activity involved additional wallets and assets, resulting in Bitget’s higher $351.6 million estimate.
Bitget’s $464M Protection Fund
Bitget said its User Protection Fund contains more than $464 million, exceeding its current estimate of affected assets. The exchange maintains that customer account balances remain accurate and that the reported loss is covered by the protection fund.
The company also said it identified and flagged abnormal wallet addresses and contacted law-enforcement agencies and blockchain-security companies. Withdrawals were suspended as part of the response, while deposits and trading continued.
The incident demonstrates why crypto exchange security involves more than the amount held in reserves. Exchanges must protect the systems connecting wallet infrastructure, transaction data and authorization controls. A large cold-storage balance does not eliminate vulnerabilities in operational systems.
The Ethereum connection also matters because institutional and corporate holders continue to increase their exposure to the network. Recent Ethereum treasury accumulation has increased attention on custody, settlement and infrastructure security.
What Happens Next for Bitget?
The next major development is the restoration of withdrawals and publication of Bitget’s full forensic report. The exchange said the report will explain the root cause of the incident and detail the measures being implemented to strengthen its wallet infrastructure.
Investigators will also need to determine how much of the transferred cryptocurrency can be frozen or recovered. Once digital assets move through decentralized exchanges, bridges and multiple blockchain networks, tracing remains possible, but recovery can become more complicated.
For crypto traders and exchange users, the incident puts additional attention on wallet segregation, transaction monitoring, authorization controls and protection funds.
Bitget is also investigating a possible connection to North Korean-linked hacking groups. That attribution remains part of the investigation and should not be treated as independently established until further evidence is released.
Conclusion
Bitget currently estimates that approximately $351.6 million in assets were affected, while maintaining that its cold wallets and customer balances remain secure. Its more than $464 million User Protection Fund provides a stated financial buffer above the reported amount.
The final assessment will depend on Bitget’s forensic investigation and its forthcoming incident report. The key unanswered questions are how attackers gained access to the backend system, how transaction authorization was manipulated, how much cryptocurrency can be recovered and what security controls will change.
Until those findings are published, the $351.6 million figure remains Bitget’s current estimate, while the exchange continues to state that its cold-storage assets were not compromised.
Sources & Methodology
Primary-source standard: Market-moving facts should link to original data releases, regulator notices, company filings or official project announcements whenever available. Secondary reporting is used for additional context, not as a substitute for original evidence.
Page last reviewed:
