Bitget confirms over $350M breach and temporarily pauses withdrawals

1 hour ago 7

Bitget has confirmed a hot wallet security breach affecting approximately $351.6 million in crypto, while saying customer funds remain protected by its User Protection Fund.

[SECURITY NOTICE] Bitget Hot Wallet Incident — September 24, 2026

At 18:31 UTC on September 24, 2026, Bitget's security systems detected unauthorized transfers from some of our hot wallets. Our security team activated emergency response protocols immediately.

What we have…

— Gracy Chen @Bitget (@GracyBitget) September 24, 2026

The confirmation came from Bitget CEO Gracy Chen, who said in a security notice posted on X that the exchange detected unauthorized transfers from some hot wallets at 18:31 UTC on September 24 and activated emergency response procedures within minutes.

The incident was initially flagged through unusual onchain activity. DCF GOD, a pseudonymous crypto KOL and angel investor known for market analysis, said a fresh wallet bought 7,111 ETH on Arbitrum using 19.67 million USDT0 allegedly traced to a Bitget hot wallet, routing the trades through UniswapX and 1inch Fusion.

Further onchain data indicated that assets were transferred from several Bitget labeled hot and cold wallets across multiple chains into a single fresh address. The transfers included ETH, USDT, USDC, AVAX and BNB.

Early estimates placed the suspicious transfers at about $174 million before rising to roughly $183 million as additional transactions were identified. Chen later said the total amount affected by the incident was approximately $351.6 million.

Bitget said its cold wallets remain secure and that the breach was contained to part of its hot and warm wallet infrastructure.

Chen said the full loss is covered by Bitget’s User Protection Fund, which currently holds more than $464 million. The exchange said user account balances remain accurate and customer assets are protected.

Withdrawals have been temporarily suspended while Bitget conducts a security review. Deposits and trading remain operational.

The exchange said it has identified and flagged abnormal transfer addresses and notified law enforcement and onchain security firms.

Chen said Bitget will provide hourly updates and publish a full incident report, including the root cause and corrective actions, within 24 hours. The exchange has not yet disclosed the attack vector.

This is a developing story. More information will be added as the situation develops.

Disclosure: This article was edited by Estefano Gomez. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article