Bitget has confirmed a security breach affecting approximately $351.6 million in crypto assets, sharply raising the scale of an incident that first emerged through unusual on-chain transfers from wallets linked to the exchange.
The crypto exchange said unauthorized transactions were detected at 18:31 UTC on September 24 and affected portions of its hot and warm wallet infrastructure. Bitget temporarily suspended withdrawals while it carries out a security review, although deposits and trading remain operational.
CEO Gracy Chen said the company’s cold wallets remain secure and that customer account balances are accurate. Bitget also said the estimated loss is fully covered by its User Protection Fund, which it currently values at more than $464 million.
Initial $170 Million Outflow Grew Into a $351.6 Million Incident
The first warning came from blockchain activity rather than a company disclosure.
More than $170 million in cryptocurrency was initially observed moving from several addresses labeled as belonging to Bitget into a newly created wallet over roughly an hour. Assets involved included ether, USDT, USDC, AVAX and BNB, with the receiving address rapidly beginning to swap some of the tokens on decentralized exchanges.
Subsequent tracking pushed the visible on-chain total above $180 million before Bitget disclosed that the estimated amount affected by the broader incident was approximately $351.6 million.
One of the more unusual transactions took place on Arbitrum, where a newly created address used roughly $19.67 million of USDT0 to acquire about 7,111 ETH in approximately six minutes through UniswapX and 1inch Fusion. Some of the execution reportedly occurred materially above the prevailing spot price, adding to early suspicions that the movements were not routine treasury management.
Blockchain trackers initially labeled some of the sending addresses as cold wallets. Bitget later disputed that interpretation, saying the breach was confined to portions of its hot and warm wallet layers and that its cold-storage infrastructure remained secure. Wallet labels maintained by third-party analytics platforms can differ from an exchange’s own internal classifications.
The incident also triggered reports from users experiencing withdrawal problems. Those reports initially lacked an official explanation, but Bitget later confirmed a platform-wide withdrawal suspension as part of its emergency response.
The broad pause is materially different from the USDC withdrawal interruption on Base that Bitget announced earlier this week. That September 22 restriction was described as wallet maintenance affecting one specific asset-network combination. Bitget has not publicly linked that earlier maintenance event to the current security breach, so there is not enough evidence to treat the two as connected.
Bitget Says Its Protection Fund Can Absorb the Loss
Bitget said its emergency team was activated shortly after the unauthorized transfers were detected. Addresses associated with the abnormal activity have been identified and flagged, while the company says it has contacted law enforcement and on-chain security firms.
The exchange has not yet disclosed how the attacker obtained access. Chen said Bitget would not speculate about the attack vector before the investigation is complete and promised a full incident report covering the root cause and corrective measures within 24 hours.
That distinction matters. Crypto security incidents can originate from compromised private keys, signing systems, internal access controls, application vulnerabilities or other infrastructure failures. Recent security incidents affecting exchange-connected infrastructure have shown why the exact failure point must be established before conclusions are drawn about the underlying blockchain or asset.
The financial focus now shifts to Bitget’s Protection Fund.
Bitget reported earlier in September that the fund held 5,500 BTC and had averaged about $382 million in value during August. Its value ranged from approximately $345 million to $441 million during the month as Bitcoin prices moved. The exchange now says the fund is worth more than $464 million, placing its stated value above the estimated $351.6 million affected by the breach.
The Protection Fund is separate from Bitget’s proof-of-reserves program. Its August proof-of-reserves disclosure reported a 122% total reserve ratio, marking the exchange’s 45th monthly reserve update.
Those numbers provide useful context, but neither should be confused with a guarantee that every operational issue has been resolved. The industry has repeatedly learned that proof of reserves and actual withdrawal access answer different questions. The immediate test for Bitget is whether it can absorb the loss while restoring unrestricted customer withdrawals.
This Is Now a Test of Bitget’s Custody Architecture
The size of the breach matters, but the more important issue is what it reveals about Bitget’s wallet controls.
A $351.6 million loss is large enough that this cannot be treated as a minor hot-wallet incident. Bitget says cold storage remained untouched, which, if confirmed by the investigation, would show that the most isolated layer of its custody structure performed as intended. But the compromise of both hot and warm infrastructure would still raise serious questions about how access was segmented between the layers that are designed to handle operational liquidity.
The distinction resembles the broader trade-off visible in other incidents involving custodial accounts. Centralized custody is useful because a platform can manage transactions, liquidity and recovery procedures for users. It also creates concentrated infrastructure that becomes extremely valuable if an attacker finds a way through the controls protecting it.
There is another reason the on-chain behavior matters. The rapid conversion of transferred stablecoins and other assets into ETH reduces exposure to tokens that can potentially be frozen by centralized issuers. The industry has already seen how stablecoin issuers can freeze specified wallets after suspicious or sanctioned activity is identified.
Converting assets quickly does not make stolen funds disappear. Blockchain investigators can continue following transfers. But once assets move into tokens without an issuer-controlled freeze mechanism and are routed through decentralized protocols, recovery can become considerably more complicated.
Withdrawals Are the Most Important Signal From Here
The Protection Fund gives Bitget something many smaller crypto platforms lack: a large pool of assets specifically presented as a backstop against extraordinary losses.
Now investors get to see what that protection looks like under real stress.
The difference between having a $464 million protection fund on a dashboard and deploying it against a $351.6 million breach is substantial. The company will need to show whether those assets remain immediately available, how losses are accounted for and whether replenishing operational wallets affects any other part of its balance sheet.
Users will care about something simpler: withdrawals.
Temporarily stopping asset outflows after detecting unauthorized transactions is a rational containment measure. Exchanges routinely isolate wallet infrastructure when they need to stop additional transfers, and even planned platform-wide deposit and withdrawal suspensions can occur during sensitive wallet work.
The difference here is that the shutdown follows an actual breach.
That makes the duration of the restriction a key indicator. A relatively quick reopening after wallet rotation, balance reconciliation and security checks would support Bitget’s claim that the incident has been financially contained. A prolonged or repeatedly extended suspension would increase questions about how much remediation is still required.
The incident should also separate security risk from solvency risk. Losing $351.6 million does not by itself establish that Bitget cannot meet customer obligations, particularly if the Protection Fund is available as described. But confidence in centralized exchanges depends heavily on users believing that balances shown on-screen remain withdrawable when requested.
That is why discussions around major crypto exchange insolvency tend to focus on broad withdrawal failures, reserve shortfalls and hidden liabilities rather than on a security breach alone.
Bitget now has a much more immediate credibility test. The company has put forward three clear claims: cold wallets are secure, customer balances are protected and the Protection Fund is large enough to cover the loss.
The next evidence investors need is operational rather than promotional. Withdrawals need to reopen, the $351.6 million figure needs to remain stable after reconciliation, and the promised incident report needs to explain how an attacker reached hundreds of millions of dollars in operational wallets.
Until then, the breach may be contained financially, but the investigation is only beginning.
Johan Shamshad is a financial markets writer at Dave Finances covering cryptocurrencies, trading platforms, brokers, fintech, financial regulation, and developments across global markets. He previously worked at Gulf News, adding newsroom experience to his coverage of fast-moving financial and digital-asset markets.
His work focuses on identifying market-moving events, company developments, regulatory changes, product launches, and shifts in trading and financial infrastructure.
Johan contributes news and analysis designed to help readers understand not only what happened, but why a development matters and how it may affect the wider financial landscape.

