Bitget Pauses Withdrawals After $351.6 Million in Unauthorized Transfers
Key Facts
Crypto exchange Bitget said unauthorized transfers affected an estimated $351.6 million in assets held in some of its hot and warm wallets on September 24, 2026. It temporarily suspended withdrawals while conducting a security review, although deposits and trading continued, according to the company. The affected infrastructure belongs to the exchange and should be distinguished from Bitget Wallet, its self-custody product. Bitget said its cold wallets were unaffected and customer account balances remained accurate. The immediate operational consequence it disclosed was therefore a restriction on moving assets off the exchange, alongside the estimated loss in its managed wallet infrastructure.
Bitget’s security systems detected the transfers at 18:31 UTC on September 24, 2026, the company said. Its $351.6 million figure is an estimate of assets affected, rather than a final accounting of losses by customer or individual token. Bitget said the incident was confined to portions of its hot and warm wallet layers and that cold storage remained secure. That description locates where assets moved within its custody system, but does not establish how the attacker gained access. The root-cause investigation matters because it must explain both the path used to initiate transfers and the controls needed to prevent a recurrence.
Bitget describes a 3-tier custody architecture, making the distinction among the affected and unaffected wallets central to the story. Hot wallets support frequently used operations, warm wallets sit between active systems and cold storage, and cold wallets are kept away from routine transfers. An attacker who reaches a transfer-capable layer can move assets even if the cold layer remains intact. The condition of cold wallets alone therefore cannot measure the full damage; the assets leaving the other layers matter as well. Separating those layers gives customers a clearer way to assess the scope Bitget has reported and the questions its technical report must answer.
Bitget said it activated emergency procedures after detecting the transfers, identified and flagged the addresses involved, and reported them. It also said law enforcement and blockchain security firms had been notified and were assisting the investigation. Suspending withdrawals fits that response because further outgoing transfers before a security review is complete could make the vulnerable path harder to isolate. The exchange nonetheless kept deposits and trading available, so the withdrawal pause was not a shutdown of trading accounts. The timing of restored withdrawals depends on the security review Bitget announced, rather than on whether customers can continue placing trades on the platform.
Chief Executive Gracy Chen raised the possibility of a North Korea-linked group’s involvement, according to reports of her remarks. Those reports described preliminary similarities in internet-address and virtual-private-network patterns, not a conclusive identification of the attackers. Such similarities may guide investigators, but they require further evidence before responsibility can be assigned to a particular group. Bitget’s initial security notice did not establish the method of intrusion and said the company would await its investigation before determining it. Attribution and the entry point thus remain separate questions from the unauthorized transfers that the exchange itself has confirmed.
Bitget says its User Protection Fund holds more than $464 million and that the estimated loss falls within its coverage. Against the $351.6 million estimate of affected assets, the stated fund is larger by more than $112.4 million. That comparison uses figures provided by the company; it does not, on its own, set a timetable for recovering transferred assets or reopening withdrawals. Financial coverage addresses the exchange’s stated capacity to absorb a loss, while reopening withdrawals requires confidence in the transfer process. For customers seeking to move assets elsewhere, the size of the fund and the availability of withdrawal service are distinct issues.
For traders, continued trading means positions can still be managed within Bitget, while the withdrawal pause limits transfers to other destinations. That constraint matters most to strategies that depend on moving assets quickly between venues, even when order entry and trading remain available. Bitget says customer balances are accurate and funds are protected; the practical effect of that assurance will become clearer when withdrawals resume. Anyone assessing exposure to the exchange must also consider whether the infrastructure that allowed the unauthorized transfers has been secured. The disclosed facts alone do not establish a particular price move in any cryptocurrency.
Bitget said it would issue regular incident updates and restore withdrawals after completing its security checks. Its initial notice also pledged a report on the root cause and corrective measures within 24 hours, making that report the next source of detail on how the transfers occurred. The entry point, the precise scope of the affected wallet layers and the effectiveness of measures to stop further transfers will be central to its findings. Confirmation that the incident remained within the disclosed scope would make the loss estimate easier to assess against the stated fund. Additional affected assets or a prolonged withdrawal pause would change the assessment of operational risk.
The $351.6 million estimate remains the starting point for sizing the incident until Bitget publishes the findings of its investigation. The company distinguishes the hot and warm wallets it says were affected from cold wallets it says remained secure. That distinction directs attention to the transfer process, but it does not replace an explanation of how unauthorized transactions were approved. The preliminary suspicion of a North Korea-linked group likewise needs investigative findings before it can be treated as a settled attribution. For customers and markets, the restoration of withdrawals and the technical account of the breach will be clearer tests than the continued availability of trading alone.