Bitget Exploit: What Happened to $351.6M and Are User Funds Safe?

Last Updated:
Bitget Exploit: What Happened to $351.6M and Are User Funds Safe?
Google News

Get our latest news first. Add us as your Preferred Source on Google and tap "Star" to prioritize our updates.

  • Bitget paused withdrawals after an estimated $351.6M hot and warm wallet exploit.
  • Chen said the $464M-plus protection fund covers losses and cold wallets are safe.
  • Chen said attackers forged transaction data; investigators ruled out key compromise.

Bitget temporarily suspended withdrawals after an exploit involving an estimated $351.6 million affected parts of its wallet infrastructure. Following the incident, CEO Gracy Chen said user funds remain safe, all cold wallets are unaffected, and the exchange’s User Protection Fund, holding more than $464 million, will fully cover the loss.

However, the suspension prevents customers from transferring assets out of the exchange while security teams review its systems. 

Bitget Says Protection Fund Covers $351.6M Loss

Chen said the $351.6 million figure corresponds to a preliminary estimate. Bitget said customer account balances remain accurate and protected, while deposits, spot trading and futures trading continue.

The exchange operates three wallet tiers: hot, warm, and cold. According to its incident notice, the breach affected only portions of the hot and warm wallet layers. Hot wallets handle online transfers, while warm wallets provide an intermediate storage layer. Bitget said cold wallets remained outside the affected systems. 

Meanwhile, withdrawals will resume in an orderly manner after the security review, although Bitget has not announced a confirmed timeline.

Backend Breach Triggered Unauthorized Transfers

Bitget’s security systems detected unauthorized transfers at 18:31 UTC on September 24. Arkham Intelligence flagged large movements of AVAX, BNB, ETH, and stablecoins, followed by conversions into ETH.

In a follow-up update, Chen said the attacker compromised a critical backend system within the wallet infrastructure. The attacker then forged transaction data, prompting Bitget’s authorization process to move funds.

Chen said investigators had ruled out private key compromise. Her account attributed the transfers to manipulation of the authorization process, while the specific method of intrusion remained under investigation. She also said the team had contained the loss and that no further unauthorized transfers were possible.

Separately, Bybit CEO Ben Zhou said his exchange would assist in tracking the stolen funds, noting Bitget had previously supported Bybit during its own security incident. 

Investigators Trace Funds and Coordinate Recovery Efforts

Bitget activated an emergency response team within minutes of detecting the incident. The exchange identified, flagged, and reported abnormal transfer addresses as part of its response. Law enforcement authorities and on-chain security firms have received notification and are participating in the investigation and efforts to recover the stolen funds. 

Related: Bitget Protection Fund Hits $441M as Bitcoin Rally Boosts Reserves

Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.