Bitget has suspended withdrawals after unauthorized transfers drained about $351.6 million from a limited number of its hot and warm wallets.
The crypto exchange detected the transfers at 18:31 UTC on Sept. 24 and activated its emergency response procedures within minutes, Chief Executive Officer Gracy Chen said. Bitget’s cold wallets and most assets held on the platform were unaffected.
Chen said customer balances remain accurate and the losses are covered by Bitget’s User Protection Fund, which currently holds more than $464 million. Deposits and trading continue to operate normally while withdrawals remain paused pending a security review.
“The full amount of this loss falls within the coverage of Bitget's User Protection Fund.”
The exchange has identified and flagged addresses connected to the transfers and notified law enforcement agencies and on-chain security firms. It has yet to disclose how the wallets were compromised and said it would not speculate on the attack vector while the investigation remains underway.
Bitget plans to provide hourly updates and publish a full incident report within 24 hours, including the root cause and corrective measures.
The breach comes during Bitget’s eighth-anniversary campaign, which the exchange launched this month as it expands beyond crypto into equities, foreign exchange and other markets under its Universal Exchange strategy.
It also makes an already expensive month for crypto security even more costly.
DeFiLlama had recorded about $331 million in losses across 17 September incidents before the Sept. ai exploit . Subsequent attacks pushed that figure above $342 million, with most of the damage linked to a roughly $320 million incident involving Liquid Network .
Source link







