Bitget Confirms $351.6M Hot Wallet Hack With Ethereum (ETH) Drained On-Chain

Bitget confirmed $351.6M in unauthorized transfers from hot wallets, halted withdrawals, and said its $464M protection fund covers the full loss.

(11:25 PM UTC)
4 min read
k7rq2fdm

$351.6M in Unauthorized Transfers

Bitget, the sixth-largest crypto exchange by trading volume, confirmed that roughly $351.6 million in digital assets left its hot wallets without authorization on September 24, in what security researchers describe as a suspected hack. The Seychelles-based platform, which processes more than $1.1 billion in daily volume according to CoinGecko data, suspended withdrawals as an emergency measure, while deposits and trading remained fully operational. On-chain security firms flagged the suspicious movements hours before the exchange issued its own confirmation, and the scale of the incident has put hot-wallet exposure — keeping user funds in internet-connected infrastructure for liquidity rather than offline cold storage — back at the center of the security debate.

Chief Executive Gracy Chen confirmed the breach in a statement posted to X, writing that Bitget's security systems detected unauthorized transfers from a limited number of hot wallets at 18:31 UTC on September 24. She said emergency response protocols were activated immediately and that cold wallets were untouched. Bitget operates a three-tier wallet architecture, and the compromise, per Chen, was contained to part of the hot and warm wallet layers, leaving user assets protected. Addressing customers directly, Chen wrote that the exchange has navigated multiple market cycles and 'will not run from this,' promising every dollar and every decision would be accounted for transparently.

Funds Consolidated Into a Single Address

On-chain data shows the attacker swept assets across multiple blockchains and consolidated them into a single newly created address. The drained assets included Ethereum (ETH), BNB, Avalanche (AVAX) and USDT0, the omnichain version of Tether built on LayerZero. Analysts tracked one fresh address using roughly 19.67 million USDT0 from Bitget's hot wallet to buy 7,111 ETH on Arbitrum in just six minutes, paying up to 5% above spot through DeFi app protocols UniswapX and 1inch Fusion. The aggressive buying briefly pushed the WETH/USDC pool price to around $2,870, as stablecoin balances were steadily converted into ETH — a laundering pattern designed to shift stolen value into the market's most liquid asset.

The loss estimate escalated sharply over the course of the day. Early tracking put suspect outflows between $170 million and $183 million, but later disclosures covering additional wallets pushed the confirmed total to $351.6 million. Analysts noted the affected Bitget wallets still held about $530 million in assets, keeping traders on alert for further movements. Neither the exchange nor security firms have disclosed the attack vector, and speculation linking the incident to North Korean actors remains unverified. Bitget has said it will not speculate on the method until its investigation concludes.

Protection Fund Covers the Full Loss

In its official announcement, the exchange confirmed the $351.6 million outflow and said it has flagged the addresses involved, notified the relevant counterparties, and formally engaged law enforcement and on-chain security firms in the investigation. Chen stated that the User Protection Fund, holding more than $464 million, can cover the entire loss. Withdrawals remain paused until the security review is complete, while deposits, trading and account balances are unaffected and verified as accurate. The company committed to hourly updates and a comprehensive incident report within 24 hours covering the root cause, the method used and the corrective measures to follow.

Largest Exchange Breach Since Bybit

The breach is the largest at a centralized exchange since Bybit lost approximately $1.4 billion in February 2025, and it lands in a year already marked by wallet-level failures. In July, hackers exploited a firmware bug in the Coldcard bitcoin hardware wallet to steal nearly $120 million in user funds, and earlier this month purported white-hat attackers pulled about 4,000 BTC — worth roughly $320 million at the time — from the federation wallet of Blockstream's Liquid sidechain. Separately, Bitget had already announced in August the wind-down of services for Japan residents after receiving a warning from the country's regulator over unregistered operations. Readers tracking the market in real time can follow live spot and futures prices on Bitget.

Post-Mortem Report Due Within 24 Hours

The decisive test now is the promised post-mortem. The drained total and the single-address consolidation are already verifiable on-chain, so the 24-hour report must reconcile its official figure with what block explorers show and disclose whether private keys were compromised or a signing-infrastructure flaw was exploited — neither has been indicated so far. For users, the $464 million protection fund should keep balances whole, but the episode illustrates how fast an exchange breach transmits into market microstructure: the attacker's premium-priced ETH purchases moved the WETH/USDC pool within minutes. Until withdrawals resume, Bitget's credibility rests on the transparency of that report.

COINOTAG News Desk

COINOTAG News Desk

COINOTAG's editorial and research desk.

How our News Desk works
AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.