Wichtige Erkenntnisse:
- Bitget confirmed a $351.6 million security breach, with withdrawals suspended during the investigation.
- Bitget says its $464 million-plus Protection Fund is sufficient to cover the reported losses while user funds remain protected.
- The incident adds to a recent run of major crypto hacks involving exchanges, protocols, and crypto wallets.
Bitget confirmed a security breach of approximately $351.6 million in funds on Sept. 24, following the discovery by its security systems of unauthorized transfers from some of its hot wallets at 18:31 UTC.
The exchange stated it would activate its emergency response procedures and temporarily suspend withdrawals until its investigation concluded.
The incident involved some of Bitget’s hot and warm wallet layers, stated CEO Gracy Chen. The exchange affirmed that its cold wallets are secure and that user account balances and assets are preserved.
The scale of the disclosed loss places the incident among major crypto hacks involving a centralized exchange. However, Bitget stated that the entire estimated loss is covered by its User Protection Fund, currently holding more than $464 million.
Bitget Freezes Withdrawals After Breach Detection
Bitget stated that its security team detected the unauthorized transfers and activated an emergency response within minutes. The exchange has also identified and flagged abnormal transfer addresses and notified relevant parties. Law enforcement agencies and on-chain security firms have been notified and are participating in the investigation.

Withdrawals remain temporarily suspended as a precaution during the security review. Deposits and trading, however, continue to take place, according to the exchange.
Bitget has not disclosed the attack vector. Chen stated the company would refrain from speculating on how the breach occurred until the investigation was complete.
This distinction is notable at this juncture. The exchange has confirmed unauthorized transfers and an estimated loss. However, it has not publicly attributed the incident to a particular vulnerability, technique, or attacker.
$464M Protection Fund Covers Reported Loss
Bitget stated that its User Protection Fund currently holds more than $464 million. That exceeds the estimated $351.6 million affected by the incident by more than $112 million.
The exchange stated that the entire loss amount is covered by the fund. It confirmed that its three-tier wallet architecture limited the incident to the hot and warm wallet layers.
Cold wallets, per Bitget, are completely secure. The exchange has also stated that customer account balances are accurate and that user assets remain protected. Withdrawals are to resume after the completion of the security review.
Bitget plans to publish hourly updates via its official channels. The exchange has stated that a full incident report, including a root cause analysis and corrective actions, will be published within 24 hours.
Bitget Joins a Run of Recent Crypto Security Incidents
The incident follows several significant events in the crypto security space. On Sept. 19, The Coin Republic reported that a North Korea-linked activity known as WaterPlum had infected more than 30,000 devices. The activity affected more than 100 countries and regions between Dec. 2025 and July 2026.
Authorities stated that information relating to more than 7,000 crypto wallets was stolen. Meanwhile, controlled wallets received at least $10.71 million in cryptocurrency.
Revolut also saw attention earlier this September, as hackers reportedly exposed some user data and demanded a 10,000 BTC ransom, according to The Coin Republic. Other events involve direct protocol exploits. On Aug. 31, Cronos ceased block production after an attack targeted lending protocol Tectonic.
Independent researcher Weilin Li estimated that approximately $75 million in assets were affected. About $60 million remained on Cronos after validators halted further block production. Maya Protocol experienced a separate incident on Aug. 18, following an attacker exploiting six linked software vulnerabilities.
The Coin Republic reported approximately $1.7 million in losses by the attacker and a withdrawal of 48.87 million CACAO after manipulation of the pool accounting. This case of Bitget exchange is distinct in both scale and structure. The exchange has confirmed the reported loss, but the investigation into how the unauthorized transfer took place is ongoing.
Der Beitrag Breaking: Bitget Confirms $351.6M Security Breach, Pauses Withdrawals erschien zuerst auf The Coin Republic.





