Bitget Confirms $351.6M Hot Wallet Hack Touching Ethereum (ETH)

Bitget confirmed a $351.6M hot wallet hack touching Ethereum and stablecoins. Private keys were not leaked; the $464M protection fund covers all losses.

(02:42 AM UTC)
4 min read
AI SummaryAI
  • Bitget CEO Gracy Chen estimated hack losses at $351.6M on September 25.
  • Attackers drained Ethereum, USDC, USDT, BNB and AVAX, swapping below market prices and bridging chains.
  • Bitget's User Protection Fund holds over $464M and will fully cover the hack's losses.
  • Cold wallets were unaffected and additional unauthorized outflows have been blocked.
d2mv6ykl

Hot Wallet Drained Across Chains

Bitget, one of the largest global cryptocurrency exchanges, has lost more than $350 million after attackers breached its hot wallets — the internet-connected wallets an exchange keeps online to process withdrawals and settlement, and the standard first target in exchange breaches. On-chain monitoring tools flagged the first abnormal movements in the early hours of September 25, showing over $180 million in assets leaving exchange-controlled addresses for wallets with no identified owner. The running total of traced outflows subsequently climbed past $351 million, a breach first caught by external on-chain analysis rather than the exchange's internal monitoring. The stolen holdings spanned Ethereum (ETH), the stablecoins USDC and USDT, BNB and AVAX. On-chain data shows the attackers converted those assets at prices well below prevailing market rates — an extreme demonstration of slippage — before moving the proceeds to other blockchains through bridge protocols to complicate recovery efforts. Failed withdrawal requests reported by users followed within minutes of the suspicious outflows. Bitget chief executive Gracy Chen confirmed the incident publicly on Thursday and put the estimated damage at approximately $351.6 million. She stressed that customer funds are safe and that the entire loss falls within the coverage of the exchange's User Protection Fund, which currently holds more than $464 million — enough to absorb the breach in full. Bitget halted withdrawals immediately after detecting the attack and said services will resume only after a complete security review. Chen also disclosed that IP addresses traced during the investigation may be associated with a DPRK-linked group, while emphasizing that the connection has not been definitively established.

Backend Compromise, Keys Untouched

Bitget's official follow-up on September 25 narrowed the root cause. In the security team's preliminary findings published by Chen on her X account, the intruder penetrated the core backend system of the exchange's wallet service, forged transfer information and triggered the approval signing procedure to push funds to external addresses — instructions that resembled the platform's normal transfer order types. Critically, no evidence indicates the wallet's private keys were compromised. Chen stated that a key leak has been ruled out, “which means a more severe risk scenario has been eliminated,” and that containment is complete, with no further possibility of unauthorized funds leaving the platform. Bitget's three-tier wallet architecture kept its cold wallets entirely unaffected, according to the company's own assessment. How exactly the attacker penetrated the backend remains under investigation; Bitget said it will publish a full technical report as soon as the intrusion method is identified. The emergency response team swung into action immediately after the incident, identified and reported the addresses that received abnormal funds, and notified law enforcement agencies and on-chain security firms working the case. A backend intrusion of this kind is harder to catch than a leaked key, because the attacker operates inside infrastructure the exchange itself trusts. Withdrawals remain suspended while multiple technical teams run system recovery and security hardening in parallel. Chen declined to commit to a restart timeline, saying Bitget would announce a date the moment one is confirmed and would not “hastily promise a schedule it cannot keep.” Readers tracking the market in real time can follow live spot and futures prices on Gate.

$464M Fund Puts Resumption in Focus

Read together, the two disclosures frame this breach as an operational-security failure rather than a cryptographic one: private keys stayed intact, yet the signing pipeline itself could be manipulated from inside the backend. On-chain tracing of the roughly $351.6 million in drained funds, verifiable transaction by transaction, will decide how much can be frozen or clawed back before the attackers finish bridging. The official post-mortem to date attributes the loss to the backend intrusion, with remediation details still pending. Coverage pools such as Bitget's $464 million fund — now standard across venues from Bitget to Coinbase Global (COIN) — have become a survival requirement for exchanges, and for traders weighing venue risk our guide to best crypto exchanges breaks down how custody models differ. The next catalysts: the withdrawal-resumption notice and the technical report.

COINOTAG News Desk

COINOTAG News Desk

COINOTAG's editorial and research desk.

How our News Desk works
AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.