Bitget says unauthorized transfers drained $387.5 million from its hot wallets
Unauthorized transfers hit Bitget's hot wallets
Bitget, a crypto exchange where users buy, sell and store digital assets, said unauthorized transfers moved about $387.5 million out of some of its hot wallets. A hot wallet is a wallet connected to the internet so it can handle day-to-day transactions.
The exchange said the transfers were detected at 6:31 p.m. UTC on Sept. 24. Bitget suspended withdrawals, then identified and flagged the addresses involved.
Withdrawals were still suspended at the time of the latest update. Deposits and trading remained available, according to Bitget.
The amounts, the wallets and the timeline
- Bitget first reported about $351.6 million withdrawn through unauthorized transfers, then said onchain tracing confirmed $387.5 million after adding Zcash and Tron assets. The exchange said the higher figure does not reflect additional theft and that the incident remains contained.
- Bitget said its cold wallets were not affected. A cold wallet is storage kept offline.
- Private keys were not compromised, according to CEO Gracy Chen.
- Bitget Wallet, the company's separate self-custodial wallet product, was not affected. Self-custodial means the user holds the keys rather than the exchange.
- Bitget has launched a recovery bounty program and said it plans to announce a withdrawal resumption plan by Sept. 26 at 4 a.m. UTC.
What Bitget and its CEO said
Chen said the attacker compromised a critical backend system inside Bitget's wallet infrastructure. According to Chen, the attacker spoofed transaction data and invoked the authorization process to move funds out.
Chen said the loss "falls within the coverage" of Bitget's User Protection Fund, which she said currently holds more than $464 million.
Chen also wrote: "Bitget has navigated multiple market cycles. We will not run from this. Every dollar and every decision will be accounted for, transparently and in full. Updates will be posted here and across all official Bitget channels as they become available."
Bitget said the specific method used to get into the system is still being investigated. Mandiant and SlowMist are working with the exchange on the investigation, and law enforcement has been notified.
What The Block observed onchain
The Block observed hundreds of millions of dollars moving from Bitget-labeled wallets to a fresh address as the incident unfolded. Ether, USDT, USDC, AVAX and BNB were among the assets transferred, and the address later began swapping some of the funds onchain.
A Bitget spokesperson told The Block that the affected wallets were custodial wallets operated by Bitget's centralized exchange — meaning the exchange held the keys. Bitget Wallet runs on separate infrastructure, the spokesperson said.
What is confirmed
Bitget has confirmed that unauthorized transfers took place from some of its hot wallets, that it detected them at 6:31 p.m. UTC on Sept. 24, and that it suspended withdrawals while identifying and flagging the addresses involved. The exchange confirmed onchain tracing showing $387.5 million sent to attacker-controlled addresses, up from its earlier figure of $351.6 million.
Bitget also confirmed that its cold wallets and its separate self-custodial Bitget Wallet product were not affected, and that deposits and trading stayed open. The company said an investigation is under way with Mandiant and SlowMist and that law enforcement has been notified.
What is still unclear
Bitget said the exact method used to enter its systems is still being investigated. The exchange has not said when normal withdrawals will return, only that it plans to announce a resumption plan by Sept. 26 at 4 a.m. UTC.
The claim that the loss falls within the coverage of Bitget's User Protection Fund comes from CEO Gracy Chen. The source material does not show a completed reimbursement or a final determination on coverage.
Why the breach matters for exchange users
Hot wallets are used for routine exchange operations, so a breach there can affect customer assets directly. Withdrawals being paused means users cannot move assets off the exchange during that period, even though deposits and trading continue.
The funds were sent to addresses controlled by the attacker, and some were later swapped onchain, which can make recovery harder. Bitget's own figures show the reported total grew after more assets were traced, showing that early numbers in such incidents can change as tracing continues.
What happens next
Bitget said it plans to announce a plan for resuming withdrawals by Sept. 26 at 4 a.m. UTC. The exchange has also opened a recovery bounty program and said it will post updates through its official channels as they become available.