Bitget Suspends Withdrawals After Wallet Breach Affecting an Estimated $351.6 Million
Key Facts
Bitget temporarily suspended withdrawals after unauthorized wallet transfers, estimating the assets affected at about $351.6 million. Chief Executive Officer Gracy Chen said the incident was confined to parts of its hot and warm wallet systems, while the company's cold wallets remained secure, according to Bitget. The exchange kept deposits and trading available during a security review for which it gave no completion time. Customers can therefore transact on the platform but cannot move assets out until withdrawals resume. That distinction puts immediate attention on access to customer assets and on whether the protections the company has described work as intended.
Bitget said its systems detected the transfers at 18:31 UTC on September 24, 2026, and activated emergency procedures. Before the company spoke, a report tracking wallets associated with the exchange identified more than $170 million moving to a new address, while leaving open whether a breach had occurred. The company's subsequent estimate of approximately $351.6 million in affected assets was higher than that initial observation. The earlier figure captured activity visible at an early stage; Bitget's number was its estimate after its security response began. The $351.6 million remains a company estimate, not a final accounting of recovered assets or settled customer losses.
The types of wallets involved help explain why withdrawals stopped while other services continued. Hot wallets allow an exchange to move assets quickly, and warm wallets serve an operational role within the architecture Bitget described; the company said its cold wallets were unaffected. When unauthorized transfers involve wallets used for routine movement, pausing withdrawals can limit further outflows while the systems are examined. Continued deposits and trading do not give customers a way to move assets off the exchange, because withdrawal is a separate function. The scope of the compromised wallets and the effectiveness of their isolation are therefore central to assessing the operational impact.
Bitget said it identified and flagged addresses linked to abnormal transfers and notified law enforcement and blockchain security firms. Those steps may help trace assets, but they do not establish that funds have been recovered or that investigators have identified the cause. The exchange has not disclosed how the affected wallets were accessed and said it would await its investigation before describing the attack method. The value of affected assets and the source of the security failure are distinct questions: one is a financial estimate, while the other requires a technical explanation. That explanation will show whether the containment measures address the entry point used in the incident.
The $351.6 million figure describes the value of assets Bitget said were affected, not the amount of compensation paid to customers. It also differs from the more than $170 million observed in early transfers from wallets associated with the exchange. That early observation captured known movements at a particular time, while the company's later estimate described a broader scope after the review began. Recovering assets could change the eventual loss without changing the value of transfers that took place. Assessing the final financial burden therefore requires knowing what can be recovered, whether further transfers occurred and how customer claims will be handled.
Chen said Bitget's User Protection Fund held more than $464 million and that the estimated loss fell within its coverage. Compared with the $351.6 million estimate of affected assets, the fund's stated value exceeds the estimate by more than $112.4 million. Comparing the announced values does not mean compensation has already been paid or that every individual claim has been decided. Bitget's published fund terms say claims involving compromised accounts or lost assets are subject to its investigation. For customers, how the company carries out its coverage pledge and handles claims will matter more than the arithmetic gap between the fund and the estimated loss.
Bitget's August 2026 fund report provides a dated comparison for the value Chen cited after the breach. The company reported an average fund value of $382 million that month and a peak above $441 million, then said after the incident that the fund exceeded $464 million. Its fund page lists a holding of 5,500 BTC, helping explain why the fund's dollar value changes with bitcoin's price. Values measured on different dates can therefore differ even if the listed number of BTC does not change. The comparison helps put the stated reserve in context, but it does not explain how Bitget will use it for this incident.
In a September 2026 update, Bitget reported an aggregate reserve ratio of 135% across 19 assets. That ratio describes reserves relative to balances covered by the update, while the protection fund is intended for specified losses; they serve different purposes when assessing customer protection. The reserve ratio alone does not show what happened to affected wallets after the update's measurement date. Likewise, the fund's stated size does not establish when withdrawals will resume or how claims will be paid. Both disclosures need to be read alongside the investigation's findings and the steps taken to restore service, rather than treated as a final verdict on the breach.
For customers holding assets at Bitget, the immediate risk is being unable to withdraw them during the review, even though deposits and trading remain available. Anyone assessing the exchange must weigh the scope of the affected wallets, its ability to contain transfers and how it applies fund coverage. The reported breach of exchange wallets does not, by itself, indicate a fault in the BTC network; it concerns custody and the operation of withdrawals. Loss estimates may change if assets are recovered or the review identifies further transfers, but Bitget's initial disclosure was not a final accounting. Separating custody risk from a coin's market price is essential when judging the incident.
Bitget pledged hourly updates and a full report on the cause and corrective measures within 24 hours of its September 24, 2026 announcement. It said withdrawals would resume after the security review, without giving a specific reopening time. The promised report will test whether the $351.6 million estimate aligns with the wallets and transfers the company identifies. The return of withdrawals will provide a practical indication of whether containment measures are sufficient to operate the service again. For customers, the decisive test of the asset-protection pledge will be how the fund's coverage is applied to affected accounts.
Latest Updates · 1
- Notable·
Update: The exchange disabled withdrawals across 4,930 asset-network entries as a precautionary measure on September 24, 2026. Bitget confirmed that deposit services and spot trading remain fully operational and are unaffected by the withdrawal restrictions.