Bitget paused withdrawals after unauthorized hot wallet transfers totaled $351.6 million.
Attackers compromised a backend system, but cold wallets remained entirely secure.
User funds are protected, covered fully by the exchange's protection fund.
Bitget paused withdrawals after unauthorized hot wallet transfers totaled $351.6 million.
Attackers compromised a backend system, but cold wallets remained entirely secure.
User funds are protected, covered fully by the exchange's protection fund.
Crypto exchange Bitget has temporarily suspended withdrawals after detecting unauthorised transfers from some of its hot wallets, with the exchange saying its security team activated emergency response measures.
Bitget CEO Gracy Chen, in a security notice posted on X, said the exchange’s security systems detected unauthorised transfers from some hot wallets at 18:31 UTC on September 24, or around 12:01 am IST on September 25. The exchange estimated that approximately $351.6 million in funds were affected.
Bitget said the incident was contained to a portion of its hot and warm wallet layers, while its cold wallets remained secure. The exchange said it had identified and flagged the addresses involved in the transfers and reported them to relevant parties. Law enforcement agencies and on-chain security firms were also notified.
Following the incident, Bitget temporarily suspended withdrawals while its security team reviewed the affected wallets and transactions.
“Withdrawals are temporarily paused and will be restored as soon as the security review is complete,” Chen said in the post on X.
Bitget initially said deposits and trading remained operational. However, a later update said its on-chain trading service was temporarily affected during the security review.
In a separate post on X on the morning of September 25, Chen said Bitget’s security team had made initial progress in tracing the source of the incident.
She said the attacker gained access to a critical backend system used by Bitget’s wallets, manipulated transaction data and used it to get the system to approve transfers.
Chen said a private key compromise had been ruled out and that loss containment had been confirmed, with no further unauthorised transfers possible.
Bitget said user balances remained accurate and that customer assets were protected. The exchange also said the estimated $351.6 million in affected funds falls within its User Protection Fund, which it said currently stands at more than $464 million.
On withdrawal restoration, Chen said multiple technical teams were working in parallel on system remediation and security hardening. She said withdrawal restoration was also being prepared, but Bitget would announce a timeline once one was confirmed.
Bitget is currently restricted from onboarding new users in India, while existing users can access the platform. However, the latest security incident could affect existing Indian users as withdrawals have been temporarily suspended during the security review.