TL;DR
-
Bitget confirmed unauthorized transfers affecting approximately $351.6 million held in some of its hot wallets.
-
Initial onchain analysis identified more than $170 million moving from Bitget-labeled addresses to a newly created wallet.
-
The receiving address began swapping assets including ETH, USDT, USDC, AVAX, and BNB onchain.
-
Bitget suspended withdrawals while working with law enforcement and blockchain security companies.
-
The exchange says its cold wallets remain secure and that its $464 million User Protection Fund fully covers the loss.
Cryptocurrency exchange Bitget has confirmed a security breach involving unauthorized transfers from some of its hot wallets, with approximately $351.6 million in assets affected.
The company temporarily suspended withdrawals while it investigates the incident alongside law-enforcement agencies and onchain security firms. Bitget said its cold wallets remain secure and promised to release a full report within 24 hours.
The confirmation followed blockchain activity showing more than $170 million leaving several addresses labeled as belonging to Bitget and moving to a newly created wallet. The receiving address subsequently began exchanging the assets through onchain services.
Onchain Analysts Initially Flagged $170 Million in Transfers
The incident first drew attention after more than $170 million in cryptocurrency moved from several Bitget-labeled wallets to one fresh blockchain address within approximately an hour.
The transfers included ether, Tether’s USDT, Circle’s USDC, Avalanche’s AVAX, and BNB. After receiving the funds, the new address began swapping some of the assets onchain.
Rapid consolidation of funds from several exchange wallets into a previously unused address can indicate a security incident, particularly when the recipient immediately begins trading the assets.
However, blockchain data alone could not initially establish whether the transactions were unauthorized. Exchanges sometimes move large amounts between addresses for treasury management, wallet maintenance, liquidity provision, or other internal operations.
Wallet labels on services such as Arkham Intelligence are also based on attribution analysis and may not always distinguish accurately between hot wallets, cold storage, and intermediary addresses.
Early reports described transfers from both hot and cold wallets labeled as belonging to Bitget. The exchange later said the unauthorized transactions came from some hot wallets and that its cold storage remained secure.
That official statement indicates that either the initial labels lacked precision or that some of the observed movements were connected to Bitget’s response to the breach.
Bitget Says $351.6 Million Was Affected
Bitget confirmed Thursday that its security systems had identified unauthorized transfers affecting approximately $351.6 million.
[SECURITY NOTICE] Bitget Hot Wallet Incident — September 24, 2026
— Gracy Chen @Bitget (@GracyBitget) September 24, 2026
At 18:31 UTC on September 24, 2026, Bitget's security systems detected unauthorized transfers from some of our hot wallets. Our security team activated emergency response protocols immediately.
What we have…
That total is substantially larger than the $170 million initially observed moving to the fresh address. The difference may reflect additional transactions, assets held on other blockchains, or transfers identified after the first public analysis.
The exchange did not immediately provide a complete breakdown of the affected cryptocurrencies or explain whether all $351.6 million had been transferred successfully to addresses controlled by the attacker.
Bitget also did not specify how the hot wallets were compromised. The promised incident report is expected to provide more information about the attack method, affected systems, and sequence of events.
Hot wallets remain connected to online infrastructure so exchanges can process customer deposits and withdrawals. Their accessibility makes them operationally necessary but also more exposed to attackers than offline cold-storage systems.
Exchanges generally limit the funds held in hot wallets and maintain monitoring controls intended to detect unusual transactions. Bitget said its security systems identified the unauthorized transfers, although it did not clarify how quickly the company responded after the first movement occurred.
Withdrawals Suspended During Investigation
Bitget temporarily halted withdrawals after confirming the incident. The suspension is intended to prevent further unauthorized transfers and give investigators time to assess whether the affected systems have been contained.
Some users had reported withdrawal problems through social media and other online channels before Bitget issued its confirmation.
The exchange did not provide a specific time for restoring withdrawals. Resuming normal service will likely depend on completing security checks, isolating compromised infrastructure, and confirming that new transactions can be processed safely.
Bitget said law enforcement and blockchain security firms are involved in the investigation. Onchain specialists may attempt to trace the transferred assets, identify counterparties, and notify exchanges or protocols that receive the funds.
The crypto exchange also stated that the attack could be linked to North Korea.
JUST IN: 🇰🇵 Bitget crypto exchange says the $350 million hack is likely linked to North Korea.
— Watcher.Guru (@WatcherGuru) September 25, 2026
The recipient’s decision to swap assets onchain could complicate recovery efforts by distributing value across different tokens, networks, and services. Public blockchain records still allow investigators to follow subsequent transactions, although tracing does not guarantee that funds can be frozen or returned.
User Protection Fund Exceeds Reported Loss
Bitget said the loss is fully covered by its User Protection Fund, which holds more than $464 million.
Based on the company’s figures, the fund exceeds the affected amount by approximately $112.4 million. The exchange presented that coverage as assurance that customer balances will not absorb the loss.
The existence of sufficient assets in a protection fund does not by itself explain how or when customers would be reimbursed. Bitget will need to disclose whether it plans to use the fund immediately, how it values its holdings and whether any affected users must submit claims.
Market fluctuations could also change the fund’s value if it contains cryptocurrencies rather than cash or stablecoins.
Still, Bitget’s statement distinguishes the event from incidents in which an exchange lacks sufficient resources to meet customer obligations after a breach.
The company’s claim that cold wallets remain secure is also important because those wallets typically hold the majority of an exchange’s customer assets.
Bitget CEO Gracy Chen publicly acknowledged the incident in an X post at approximately 5:30 p.m. Eastern Time.
“Bitget has navigated multiple market cycles,” Chen wrote. “We will not run from this. Every dollar and every decision will be accounted for, transparently and in full.”
She said updates would be published through her account and Bitget’s official communication channels.
The exchange has promised a complete report within 24 hours. That disclosure will need to reconcile the initial $170 million in observed transfers with the company’s $351.6 million affected-funds estimate.
Users will also be looking for an explanation of how the wallets were compromised, whether personal account information was exposed, and when deposits and withdrawals will resume.
Until those details are published, the confirmed facts remain that some Bitget hot wallets experienced unauthorized transfers, withdrawals are suspended, and the exchange says it has enough protection-fund assets to cover the incident.
Hassan Maishera