Bitget Confirms $351.6 Million Hack, Pauses Withdrawals
Security

Bitget Confirms $351.6 Million Hack, Pauses Withdrawals

September 25, 20264 min read

Bitget confirmed a theft of roughly $351.6 million from its hot wallets and paused withdrawals while it investigates. For traders holding assets on the platform, that means a delay in reaching their money and another reason to think about how much to keep on an exchange versus in a personal wallet.

What happened to Bitget's wallets

Security systems flagged unauthorized transfers at 18:31 UTC on September 24. CEO Gracy Chen said the breach hit only part of the hot and warm wallet layers, while cold storage stayed untouched. Affected assets included Ether, XRP, USDT, USDC, Avalanche, BNB and USDT0 on Arbitrum. Most of the stolen funds moved through the Ethereum network, which is why the final total came in well above the first onchain estimates.

Analysts at Bubblemaps and Arkham spotted unusual activity before Bitget's official statement: nearly $183 million left wallets labeled as belonging to the exchange and landed on a fresh address within an hour. A newly created wallet starting with "0xe410" swapped $19.67 million in USDT0 for 7,111 ETH in six minutes through the decentralized services UniswapX and 1inch Fusion. To move that fast, the attacker paid up to 5% above market price. A premium that size usually means the attacker needed to get funds out of an asset that's easy to freeze and into one that's nearly impossible to seize.

Bitget quickly flagged the marked addresses and shared data with law enforcement and several blockchain security firms now tracking where the stolen funds move next. Chen promised hourly status updates while the review continues.

What it means for trust in exchanges

For the market, the Bitget hack is another reminder that hot wallets remain a weak point even at large centralized platforms. The last comparable case was Bybit in 2025, when $1.5 billion disappeared, and that memory still lingers among traders. Bitget says every loss will be covered by its User Protection Fund, which currently holds more than $464 million, enough to cover the full damage with room to spare.

Bitcoin is holding near $84,000 and Ethereum is trading around $2,670. There's no visible sell-off tied directly to the news so far, even though the Ethereum network absorbed most of the stolen funds and became the center of traders' attention.

Solvency on paper doesn't always save a reputation. After incidents like this, some users move funds to other platforms or into their own wallets, even when the exchange leaves nobody uncompensated. Trust comes back slower than an account balance does.

Impact: full coverage from a protection fund doesn't guarantee users stay on the exchange. The reputational hit often costs more than the hack itself.

What changes for traders and asset holders

Withdrawals from Bitget are on hold while the exchange runs its security review, though deposits and trading keep working normally. Chen promised withdrawals would resume within hours or days, depending on how fast the security team closes the gap. Anyone with a pending withdrawal request has to wait. That uncertainty bothers active traders more than the loss figure itself. Bitget promised hourly status updates during the pause, which is why some traders are choosing to wait it out instead of panicking.

Some crypto holders who normally sell USDT or Ethereum through exchanges like this one, to later convert into hryvnia or dollars, are shifting operations to other platforms for now. That way they don't depend on Bitget's withdrawal timeline and don't risk getting stuck with funds right when a rate needs locking in fast. For active traders, this looks like routine diversification rather than panic.

The risks of centralized custody

The Bitget case is a reminder of a few practical risks worth weighing for anyone keeping assets on an exchange:

  • Hot wallets stay connected to the network for fast payouts, which makes them the more frequent target compared to cold storage.
  • Concentrating large sums on one platform raises the potential damage from a single incident.
  • Compensation funds depend on the exchange's own solvency and aren't a universal guarantee going forward.
  • Hacking groups linked to North Korea have steadily ramped up activity against crypto exchanges in recent years.

None of these risks are new, but every fresh hack repeats them louder than the last, especially when the number involved runs into hundreds of millions of dollars.

What comes next

Chen said a preliminary probe found IP addresses matching VPN services tied to a North Korean hacking group. Similar patterns have shown up before in attacks on other major exchanges, including Bybit. Bitget plans to publish a full report with root-cause analysis and a corrective action plan within 24 hours of the incident.

For the market, the situation looks contained so far. Cold wallets weren't touched, the fund covers the loss, and trading never stopped. But every hack of this size nudges the balance a bit further toward hardware wallets and away from full trust in a single platform. How fast Bitget publishes its promised report and restores withdrawals will work as a test of its own, of whether giving the money back is enough to get trust back.

Comments

Your email address will not be published. Required fields are marked *

or verify by email