Bitget's $351.6M Hot-Wallet Hack: Stolen Funds Swept Into Ethereum (ETH)

Bitget confirmed a $351.6M hot-wallet breach detected Sept 24 at 18:31 UTC. On-chain data shows stolen XRP and ETH consolidated into 67,982 ETH.

(03:38 PM UTC)
4 min read
AI SummaryAI
  • Bitget detected unauthorized hot-wallet transfers worth $351.6 million at 18:31 UTC on September 24.
  • Bitget's user protection fund holds over $464 million, exceeding the estimated loss by about $112 million.
  • Attackers compromised a backend wallet component and forged transaction data; private keys were not stolen.
  • Stolen assets include 102.93 million XRP worth $157.5 million and 31,890 ETH worth $85.8 million.
v3xn8bwc

Bitget Confirms $351.6M Hot-Wallet Breach

Bitget confirmed that unauthorized transfers drained roughly $351.6 million from part of its hot wallets, an incident the exchange detected at 18:31 UTC on September 24 and contained within minutes through emergency protocols. Its security systems flagged the outflows as they were being executed, after which suspicious addresses were locked down, law enforcement was contacted and on-chain security firms were engaged. Withdrawals were suspended as a precaution, while deposits and trading — including contract trading — remained live, and customer balances continue to reflect users' actual holdings.

The breach touched only the hot and warm wallet layers of the platform's three-tier custody structure; its cold wallets, which hold the bulk of assets, were untouched. In its own account, the exchange states that private keys were not stolen: the attacker compromised a key backend component inside the wallet infrastructure and used it to falsify transaction data, deceiving the normal authorization and signing flow into approving transfers that should have been rejected. The distinction matters — the keys themselves may remain cryptographically intact while the pipeline feeding instructions to them failed. CEO Gracy Chen confirmed in the exchange's official announcement that user assets are fully protected and that the platform's user protection fund, holding more than $464 million, covers the estimated $351.6 million loss with roughly $112 million to spare. “We will not shirk responsibility,” the exchange stated, pledging full accounting of “every dollar and every decision.” She also stressed that Bitget Wallet, the separate self-custody product, was not affected. Blockchain researchers, with analyst Conor Grogan among those endorsing the theory, have linked initial routing indicators to North Korea's Lazarus Group — a claim Bitget has not officially confirmed. The exchange also separated this event from an April 2025 incident involving roughly $100 million tied to market-making, bot and arbitrage activity, calling the two episodes mechanically unrelated.

On-Chain Trail: 102.9M XRP, 31,890 ETH

Before Bitget said anything publicly, on-chain observers were already tracking eight-figure flows out of wallets labeled with the exchange's name, with early estimates of $150 million to $170 million that nearly doubled as the mapping widened. On-chain data shows the stolen basket was unusually broad: about 102.93 million XRP valued at $157.5 million, 31,890 ETH worth $85.8 million, $34.75 million in USDT, $21.05 million in USDC, $19.67 million in USDT0, 3,000 XAUt in tokenized gold, 12,719 BNB, 821,012 AVAX and 20.59 million TRX on the TRON network. A large share of the EVM-compatible assets was rapidly consolidated and converted into Ethereum, with trackers estimating the attacker's ETH position reached roughly 67,982 ETH. The gap between the roughly $183 million visible to public trackers and Bitget's $351.6 million figure reflects the exchange's broader accounting — chiefly the large XRP position plus additional chains — meaning the early on-chain alarms caught only part of the fire. Recovery odds now split along asset lines. Issuers can freeze stablecoins such as USDT and USDC through their own contracts as long as the tokens stay identifiable, while native Ethereum parked in fresh wallets is far harder to claw back — which is why the rapid conversion into ETH is the most consequential on-chain signal so far. In a follow-up update on X, Chen said the incident is contained, no further unauthorized transfers are expected, and Bitget is working with Mandiant and Slowmist, publishing hourly updates, with a full report covering root cause and corrective measures due within 24 hours. No timeline for restoring withdrawals has been committed, though deposits and trading remain open in the meantime. Readers tracking the market in real time can follow live spot and futures prices on Gate.

Post-Mortem Due Within 24 Hours

This breach lands in a year defined by escalating exchange risk: roughly $1.1 billion was stolen across 212 security incidents in the first half of 2026 alone. Our reading of the on-chain trail is that the attacker optimized for speed and permanence — sweeping everything convertible into native ETH to escape issuer freezes, the one recovery lever that reliably works. The backend-forgery vector also resets the industry's security benchmark: private keys held firm, yet funds still left, meaning signing infrastructure — not key custody alone — is now the perimeter to judge when comparing best crypto exchanges. For users, the pending disclosure matters more than the attribution speculation feeding FOMO across social feeds: the full post-mortem, due within 24 hours of first notice, should state the root cause and its remediation, including whether transaction-policy checks could have rejected the forged flows.

COINOTAG News Desk

COINOTAG News Desk

COINOTAG's editorial and research desk.

How our News Desk works
AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.