Bitget's $351.6M Hot Wallet Breach Drains Ethereum (ETH) and Stablecoins

Bitget confirmed a $351.6M hot wallet breach as attackers drained Ethereum. Withdrawals are paused and the $464M protection fund covers losses.

(03:29 AM UTC)
4 min read
AI SummaryAI
  • Bitget confirmed unauthorized transfers worth about $351.6 million from hot and warm wallets on September 25.
  • Bitget's User Protection Fund holds over $464 million and covers the breach losses.
  • The attacker address received roughly 24,373 ETH within about one hour, on-chain data shows.
  • About 19.67 million USDT0 was swapped for 7,111 ETH on Arbitrum within six minutes.
v3xn8bwc

Bitget Confirms $351.6M Breach

Bitget confirmed unauthorized transfers affecting roughly $351.6 million in assets after its security systems flagged abnormal outflows from a portion of its hot and warm wallet layers at 02:31 Beijing time on September 25. CEO Gracy Chen published the exchange's full security notice on X at 05:30, stating that cold wallets remained completely secure and user account balances were accurate. Deposits and spot trading stayed open, while withdrawals were suspended as a precautionary measure. The exchange said the losses fall within its User Protection Fund, which currently holds more than $464 million, and pledged to publish a complete incident report with root-cause analysis before 05:30 on September 26. An emergency response team was activated within minutes of detection, and the abnormal addresses were flagged and reported to law enforcement and on-chain security firms, according to the exchange's official announcement. Bitget explicitly declined to speculate on the attack path — whether it involved private-key compromise or an interface vulnerability — until the investigation concludes, committing to hourly updates through official channels. Notably, two figures currently coexist: the $351.6 million internal accounting and lower on-chain estimates of $178 million to $192 million tracked from publicly labeled addresses, a gap that may narrow as additional transfers surface or the final report lands.

On-Chain Trail Into Ethereum

On-chain data shows the attacker's consolidation began before the official disclosure. A newly created address, 0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee, received ETH, USDT, USDC, AVAX, BNB and XAUT from Bitget-labeled wallets, and Etherscan later tagged it Bitget Exploiter 1. In one striking maneuver, roughly 19.67 million USDT0 was pulled from a labeled hot wallet onto Arbitrum and swapped for about 7,111 ETH within six minutes through UniswapX and 1inch Fusion, with execution prices reaching up to 5% above market — slippage the thief was evidently willing to absorb, since issuers can freeze stablecoins but stolen ETH is far harder to intercept. Within roughly 30 minutes, the same address collected about 34.75 million USDT, 12.85 million USDC and 3,000 XAUT, followed by approximately 24,373 ETH over the next hour. The visible outflow window ran from 02:31 to 04:55, and a final transfer still left Avalanche at that cut-off, with funds then split to additional addresses and moved through cross-chain bridges. On-chain analysts initially tallied the visible outflows at $178 million, revised to $183 million, then to nearly $192 million across 15 transfers and seven assets, with ETH representing about 44.4% of the total.

Bybit's 2025 Hack Precedent

The scale places the Bitget breach into rarefied company, though still well short of the industry's largest loss. In February 2025, Bybit lost approximately 400,000 ETH — then worth $1.4 billion to $1.5 billion — from an Ethereum cold wallet during a routine transfer, the biggest single exchange theft on record. Investigators traced that attack to a malicious script injected into a Safe multisig interface, which showed signers an ordinary transfer while the actual signature swapped the wallet's implementation contract, and US agencies including the FBI attributed the operation to North Korea's Lazarus cluster. Notably, Bitget was the first exchange to help Bybit at the time, lending 40,000 ETH — about $105 million — from its own funds, unsecured and interest-free, to ease withdrawal pressure; Bybit returned the loan roughly three days later. Historical precedent offers a shortlist of causes: hot-wallet key compromise drove Coincheck's roughly $530 million loss in 2018, KuCoin's roughly $280 million in 2020 and Bitmart's roughly $150 million in 2021, while multisig and signing-interface bypasses underpinned Bitfinex in 2016 and WazirX in 2024. Which of these patterns applies to Bitget remains undetermined pending the official report. Readers tracking the market in real time can follow live spot and futures prices on Bitget.

Post-Mortem Due September 26

For our desk, the load-bearing evidence is already on-chain: the drained balances are verifiable at the attacker's labeled address, and the flow pattern — stablecoins first, rapid ETH conversion, cross-chain dispersal — matches a professional laundering playbook rather than opportunistic wallet draining. The root cause, however, is not yet established; Bitget's own post-mortem, due before 05:30 on September 26, is the authoritative document, and any private-key or insider theories should be treated as unconfirmed until it lands. The confirmed remediation stands as of writing: withdrawals paused, losses covered by the more-than-$464 million protection fund, and hourly official updates. The question now is whether the report confirms signing-infrastructure compromise — the 2025 Bybit pattern — or a simpler key-management failure.

COINOTAG News Desk

COINOTAG News Desk

COINOTAG's editorial and research desk.

How our News Desk works
AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.