Bitget Estimates Wallet Breach Affected $351.6 Million in Crypto
Key Facts
Bitget estimated that unauthorized transfers from its wallets affected about $351.6 million in crypto on September 24, confirming a security breach. The exchange said its systems detected the transfers at 18:31 UTC and activated an emergency response. It placed the breach in parts of its hot and warm wallet layers and said its cold wallets remained secure. Bitget temporarily suspended withdrawals for a security review while deposits and trading continued. For customers, the immediate operational question is when assets can again be moved off the exchange, alongside the final size of any loss. Continued trading allows positions to change inside an account, but it does not restore the ability to transfer assets into external custody.
Smaller figures circulated before Bitget set out its estimate of the incident. Early reports tracked more than $170 million moving from addresses labeled as belonging to the exchange to a new address over roughly an hour. Subsequent tracking raised the observed amount to about $183 million, whereas Bitget estimated affected assets at roughly $351.6 million. Those numbers reflect different stages of observation and assessment, so the one-hour window cannot be applied to the exchange's full estimate. Visible onchain transfers also do not, by themselves, establish the net loss after any recovery or reconciliation. Comparing the figures requires distinguishing transfers observed in a defined period from a broader estimate of affected assets; neither measure alone settles the exchange's eventual loss.
Researchers tracked transfers across multiple networks involving assets including ETH, USDT, USDC, AVAX and BNB, with funds arriving at a newly created address. Decrypt described a transaction that used $19.67 million in USDT0 to acquire 7,111 ETH in 6 minutes. The transaction illustrates how quickly withdrawn assets can be converted before every related wallet and transfer has been identified. It does not, on its own, explain Bitget's entire estimate because it represents a specific part of the observed activity. Establishing the final scale requires distinguishing unauthorized outflows from any other transfers made in the exchange's normal operations. A swap after the initial transfer also changes the assets investigators must follow, making the subsequent path of funds relevant to assessing exposure.
The type of wallet matters because its connection to online systems shapes both its operational use and its exposure. Hot wallets support routine transfers, warm wallets provide another layer of accessible liquidity, and cold wallets are kept away from direct online access. Early reports described some addresses that sent assets as Bitget cold wallets. Bitget subsequently said its cold wallets remained secure and located the breach within parts of its hot and warm layers. A label assigned to an address by a tracking service therefore does not, by itself, establish that a cold wallet's keys were compromised. Assessing risk to assets held away from direct online access requires evidence about those wallets separately from a preliminary address label.
The withdrawal halt affects a different function from deposits and trading, which Bitget said continued. A customer may be able to change a position within the exchange while trading remains available, but cannot move a balance to an external wallet during the pause. Suspending that route can limit further outflows while investigators examine the transfers. It also makes the resumption of withdrawals dependent on the security review, even if account balances remain visible. Bitget said customer balances were accurate; that statement addresses its account records, not the timing of restored transfers. For customers who need to settle an obligation or move an asset elsewhere, reopening withdrawals is a practical test distinct from seeing a balance on screen.
Chief Executive Gracy Chen said Bitget's user protection fund held more than $464 million and covered the full estimated $351.6 million affected. On the exchange's current figures, the stated value of the fund exceeds the estimated amount involved in the incident. That comparison does not establish that customers have already been compensated, since the scope and settlement of claims depend on the investigation. Bitget's published fund terms say claims involving lost assets are subject to a review of the circumstances. For a customer with a confirmed loss, the practical test will be how that commitment is applied, as well as the size of the fund. The stated capacity to cover losses and the actual settlement of claims answer different questions about the protection available to individual users.
Bitget reported that its protection fund averaged $382 million in August and was worth about $432 million at that month's end. The exchange said the fund held 5,500 BTC, making its dollar valuation sensitive to bitcoin's price. A value reported for a prior month therefore should not be treated as a fixed cash balance at the time of this incident. Likewise, Chen's statement that the fund exceeded $464 million does not by itself specify how much could be deployed immediately for individual claims. Those distinctions matter when assessing how a large loss might be absorbed and when affected users could be paid. A comparison expressed in dollars applies to the time of valuation; it does not imply that the gap between the fund and the estimated exposure remains fixed.
On September 17, Bitget expanded its published proof of reserves to cover 19 assets and said its August report showed an aggregate reserve ratio of 122%. That disclosure lets users check whether their holdings were included in a periodic reserve snapshot, but it serves a different purpose from the protection fund. A reserve ratio compares stated assets with customer liabilities at the measurement date; the fund is intended to address certain losses. An earlier report alone cannot establish the condition of wallets after the September 24 transfers or when withdrawals will resume. Anyone assessing exposure to the exchange therefore needs updated reserve disclosures alongside the investigation's findings and the status of transfers. The ratio describes the assets within its measurement scope at that time, while the incident calls for information about subsequent wallet conditions and service availability.
Bitget said it had flagged addresses linked to abnormal transfers and contacted law enforcement and firms that trace assets on blockchains. It has not disclosed how the affected wallets were accessed. Chen promised periodic updates and a full report within 24 hours covering the root cause and corrective measures. That report should clarify whether the breach remained confined to hot and warm wallets and whether the $351.6 million estimate changes. The reopening of withdrawals, together with any disclosed recoveries or paid claims, will offer a concrete measure of how far the customer impact has been contained. Those disclosures would connect the cause and scope of the breach with the amount recovered and the period during which customers could not move assets off the exchange.
Latest Updates · 1
- Notable·
Update: Bitget CEO Gracy Chen confirmed the breach took place at 18:31 UTC on September 24, 2026. Chen stated that the attackers converted the stolen digital assets into Ethereum immediately after siphoning them from the exchange's wallets.