Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > Bitget Freezes Withdrawals After $351.6 Million Hot-Wallet Breach
Bitget Freezes Withdrawals After $351.6 Million Hot-Wallet Breach
Read Time:3 Minute, 22 Second

Cryptocurrency exchange Bitget has suspended withdrawals after detecting unauthorized transfers involving parts of its online wallet infrastructure. The company estimates the exposure at approximately $351.6 million, making the incident one of the most consequential exchange security events of the year. Trading and deposits remain available, while investigators trace the transferred assets and examine how the attackers reached systems used to authorize transactions.

Bitget detected the activity at 18:31 UTC on September 24 and said its security team initiated emergency procedures within minutes. The affected environment was limited to portions of the exchange’s hot and warm wallets, according to the company. Offline cold wallets were not compromised, and customer account balances continue to display their recorded holdings.

Multiple assets moved as the exchange contained the breach

On-chain observers identified suspicious movements involving Ether, BNB, Avalanche, USDT and USDC. Initial outside estimates were substantially lower, ranging from roughly $174 million to $183 million, before Bitget placed the total exposure at $351.6 million. A definitive breakdown of the affected assets has not yet been published.

The exchange says it has flagged recipient addresses, contacted law enforcement and enlisted blockchain-security specialists. Those measures can help exchanges and stablecoin issuers monitor or restrict onward movement, but tracing does not guarantee recovery. Attackers frequently split funds across chains, swap assets and use intermediary addresses to complicate attribution and seizure.

Bitget’s decision to pause withdrawals is intended to prevent additional unauthorized transfers while its wallet architecture is reviewed. Such pauses can also become fertile ground for fraud: criminals often impersonate support personnel, offer fake reimbursement portals or ask customers to connect wallets during a high-profile incident.

Backend compromise is under investigation

Preliminary reporting indicates the transfers were initiated directly after access to Bitget systems, rather than through fraudulent withdrawal requests submitted through customer accounts. Investigators are considering whether a critical backend service, third-party component or supply-chain dependency allowed forged transfer instructions to reach authorized signing infrastructure.

Bitget has not said that private keys were stolen. That distinction is important because a compromise can occur upstream of the keys themselves: an attacker who controls a trusted transaction-building or approval component may be able to induce legitimate signing systems to approve malicious transfers. The precise entry point, persistence method and failed controls remain unknown pending a full incident report.

Chief executive Gracy Chen said preliminary indicators included VPN-like infrastructure resembling that used in earlier North Korean operations. The behavior has raised suspicion about the Lazarus Group, but Bitget has not formally attributed the attack. Infrastructure overlap and tactical similarities can guide an investigation, yet they are not conclusive proof of responsibility.

Protection fund faces its largest test

Bitget says the loss is covered by its User Protection Fund, valued at more than $464 million. On paper, that places the reserve about $112.4 million above the current loss estimate. Customers will nevertheless be watching whether the reserve is liquid, independently verifiable and available quickly enough to support normal withdrawals once the security review ends.

The incident highlights the operational risk of hot wallets, which remain connected so exchanges can process routine transfers. Cold storage reduces exposure but cannot eliminate the need for online liquidity. Strong designs limit hot-wallet balances, separate approval duties, impose transaction policies and use independent monitoring capable of halting abnormal movements.

What customers should do now

  • Use only Bitget’s official website and verified social accounts for updates.
  • Reject messages requesting credentials, seed phrases, wallet connections or “verification” payments.
  • Review account activity and preserve records of balances and transactions.
  • Revoke unfamiliar API keys and strengthen multifactor authentication where appropriate.
  • Wait for the promised incident report before treating early attribution or root-cause claims as settled.

Bitget has promised frequent updates and a report detailing the affected systems, root cause and corrective measures. Until withdrawals resume and that technical account is available, the central questions are whether any signing path remains exposed, how the protection fund will be used and how much of the stolen cryptocurrency can be contained.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on Bitget Freezes Withdrawals After $351.6 Million Hot-Wallet Breach, use the discussion on Forum.

>> forum community

Comments

Leave a Reply