Bitget Hot-Wallet Breach Exposes $351.6M

A conceptual breakdown of the Bitget hot-wallet security incident.

Bitget hot-wallet breach exposed $351.6 million on September 24, CEO Gracy Chen said. She shared the update on X. Withdrawals are paused. However, deposits and trading remain live.

Why the Bitget hot-wallet breach matters

Chen said cold wallets and user funds are safe. The exchange uses a three-tier wallet architecture. Specifically, the attack hit part of the hot-wallet layer. It also hit the warm-wallet layer. That layer is a semi-connected buffer. It sits between automated hot wallets and offline cold storage.

“Cold wallets remain fully secure,” Chen wrote. “User funds are safe.” She added that account balances are accurate and assets are protected.

Additionally, Bitget’s User Protection Fund holds more than $464 million. Consequently, Chen said it is enough to cover the full loss. The breach surfaced at 18:31 UTC on September 24. At that time, Bitget’s systems flagged unauthorized transfers. The transfers came from some exchange hot wallets. Chen promised a full incident report within 24 hours.

How the attacker got in

Chen later described the intrusion method. First, the attacker compromised a critical backend system. That system sits within Bitget’s wallet infrastructure. Second, the attacker used it to spoof transaction data. Third, the attacker triggered Bitget’s authorization process. That process moved funds out.

However, Chen ruled out private key compromise. The specific intrusion method remains under investigation. Bitget confirmed loss containment. No further unauthorized transfers are possible, Chen said.

What on-chain researchers saw

Before Chen’s post, on-chain data flagged unusual movements. Independent researchers also flagged them. The movements totaled roughly $183 million. The wallets appeared to belong to Bitget.

Emmett Gallic is an analyst at Arkham Intelligence. He posted on X about the transactions. He said they involved three Bitget hot wallets. They also involved one cold wallet. The wallets spanned multiple blockchains. The attacker consolidated funds into a single address. The assets included ETH, BNB, AVAX, and USDT0. Gallic initially put the figure at $178 million.

His post named one cold wallet among the four addresses. In contrast, Bitget has said cold wallets were untouched. The exchange has not addressed the discrepancy.

The missing pieces

First, the $351.6 million figure is Chen’s estimate. It is not an on-chain total. Second, Bitget has not confirmed publishing the 24-hour report. Third, the attacker’s identity remains unknown. The location of the consolidated funds also remains unknown. Finally, whether the $464 million fund covers the loss rests on Bitget’s claim.

Market reaction and context

BGB Price Source : TradingView

BGB fell 2.9% as of 22:10 UTC on September 24. Bitcoin fell about 0.29%. Ether fell 0.2% over the prior 24 hours. The breach follows the Liquid Network losing $320 million earlier this month. If the $351.6 million figure holds, it may rank as the largest crypto exchange hack of 2026.

Related posts

Robinhood CEO Sells HOOD Stock: 500K Shares

NEAR Ondo Partnership Brings Tokenized Stocks

BitMine Buys ETH Again, Nears 5% Supply Target

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Read More