theTLDR
- Bitget disclosed a security breach resulting in $351.6 million stolen from hot and warm wallet systems.
- Hackers manipulated transaction data by infiltrating backend wallet infrastructure, according to CEO Gracy Chen.
- Private keys remained intact and cold storage wallets stayed protected throughout the attack.
- Withdrawal services were suspended for security assessment, though deposit and trading functions continued operating.
- The exchange’s $464 million User Protection Fund provides sufficient coverage for affected customers.
Bitget experienced a major security incident that resulted in $351.6 million being extracted from portions of its hot and warm wallet infrastructure. CEO Gracy Chen explained that hackers infiltrated a backend wallet management system, manipulated transaction records, and exploited the platform’s standard approval mechanisms. Investigators confirmed that private key compromise was ruled out as the attack vector.
Unauthorized fund movements were identified by Bitget’s security team at 18:31 UTC on September 24, prompting immediate emergency protocols. Chen reported that the team halted additional outflows and locked down compromised infrastructure. Cold storage systems remained unaffected, allowing deposit and trading operations to proceed during the investigation. Hot wallets maintain funds in connected environments for rapid transactions, whereas warm wallets serve as intermediary layers connecting online operations with offline reserves.
Protection Fund Resources Exceed Stolen Amount
According to Bitget, its User Protection Fund maintains reserves exceeding $464 million, providing complete coverage for the estimated losses. The platform confirmed all customer account balances reflect accurate holdings and the protection mechanism safeguards user assets. This breach occurred alongside a North Korea-affiliated employment scam that targeted thousands of cryptocurrency wallets during the same period.
Withdrawal functionality was disabled as engineering teams conduct comprehensive security audits and implement enhanced wallet safeguards. A specific timeline for restoration has yet to be announced. Chen indicated the platform will share reopening details only when teams verify withdrawal operations can safely resume. The assessment encompasses all wallet infrastructure layers.
Hackers Avoided Direct Private Key Access
Chen clarified that attackers altered transaction data rather than obtaining the private keys that control wallet authorization. This indicates the security breach focused on exploiting Bitget’s internal transaction validation systems rather than acquiring direct wallet control credentials.
This incident follows recent activity where cybercriminals commandeered Cardano’s verified YouTube channel and deployed fraudulent livestreams targeting viewers. Bitget’s investigation team continues analyzing how attackers penetrated the backend infrastructure and circumvented existing security protocols.
Exchange Launches Investigation and Restricts Withdrawals
Bitget has traced and labeled wallet addresses associated with the unauthorized fund transfers. The platform engaged law enforcement agencies and blockchain security specialists for collaborative investigation. In related news, a Coinbase phishing operation resulted in criminal sentencing this week following the theft of approximately $16 million from victims.
Chen stated that technical personnel are executing system remediation and comprehensive security validation. Bitget intends to publish a detailed technical analysis once investigators determine the breach origin, exploitation methodology, and implemented security enhancements. Withdrawal services will remain suspended during this period while deposit and trading capabilities remain accessible.





