Bitget Freezes Withdrawals After $351.6M Hack

Bitget confirms $351.6M in unauthorized hot wallet transfers, pauses withdrawals & says its $464M+ User Protection Fund can cover the losses.

Bitget Freezes Withdrawals After $351.6M Hack
Bitget Freezes Withdrawals After $351.6M Hack

Crypto exchange Bitget has confirmed one of the largest centralized exchange security incidents of 2026 after unauthorized transfers affected approximately $351.6 million across portions of its hot and warm wallet infrastructure.

According to Bitget, its security systems detected the suspicious transfers at 18:31 UTC on September 24, 2026, triggering an emergency response within minutes. The exchange subsequently suspended withdrawals while keeping deposits and trading operational.

Bitget Detects $351.6M in Unauthorized Transfers

Bitget said the incident began when its security systems identified unauthorized transfers from some of its online wallets. An emergency response team was activated within minutes, while addresses associated with the abnormal transfers were identified, flagged and reported.

The company operates what it describes as a three-tier wallet architecture. According to Bitget, the incident affected only portions of its hot and warm wallet layers, while its cold-wallet infrastructure remained secure.

Crypto security incidents throughout 2026 have shown that attackers do not necessarily need to compromise the underlying blockchain to access substantial amounts of capital. EtherWorld recently covered a Crypto RAT campaign linked to $235K in losses, where the concern centered on compromised devices and authenticated sessions rather than Ethereum itself.

Similarly, the Coinbase insider breach demonstrated how human access and operational systems can become attack surfaces even when core blockchain infrastructure functions normally.

At Bitget, the precise entry point remains unknown. The exchange has specifically said it will not speculate about the attack vector until its investigation is complete.

Early onchain monitoring initially produced smaller estimates as investigators tracked publicly labelled Bitget addresses. Bitget's later internal accounting placed the affected amount at approximately $351.6 million, highlighting why early hack estimates can change substantially as more wallets, chains and transactions are identified.

$464M Protection Fund Becomes Bitget's Main Backstop

The exchange states that its User Protection Fund currently holds more than $464 million, enough to cover the entire estimated amount affected by the incident. It has also told customers that account balances remain accurate and assets are protected.

A protection fund can provide an important financial buffer after a centralized exchange hack, but the coming days will show how Bitget applies that reserve in practice and whether additional losses emerge during the investigation.

Following major DeFi incidents, recovery may involve governance votes, frozen assets, protocol treasuries and coordination among multiple independent organizations. EtherWorld documented this process during the rsETH crisis, when the Golem Foundation joined an Aave-led recovery effort involving several ecosystem participants.

Other incidents have produced direct reimbursement commitments. After an exploit involving a wallet module, Gnosis committed to reimbursing affected Gnosis Pay users. EtherWorld's coverage of Carrot shutting down following the Drift exploit fallout showed how security failures can create second-order effects for projects exposed to compromised infrastructure or interconnected liquidity.

Withdrawals Paused While Trading & Deposits Continue

Bitget has temporarily suspended withdrawals while its security review continues. The company says deposits and trading remain fully operational, while withdrawals will return after security checks are completed.

No specific restoration time had been announced in the initial notice. Temporarily limiting asset movement is a common containment strategy during major blockchain security incidents because it gives operators time to identify compromised systems before additional capital leaves the platform.

When a security incident affected networks using shared Cosmos EVM infrastructure, several chains were advised to stop operations while developers investigated the issue. EtherWorld examined the broader implications in Cosmos EVM Security Incident Forces Chains to Halt.

Cronos also temporarily halted its network following an exploit affecting Tectonic, as covered in Cronos Halts After $75M Tectonic Exploit. Still, a security shutdown should not automatically be interpreted as evidence that every component of a system has been compromised.

EtherWorld previously highlighted this distinction during the Base Mainnet block-production halt, where service availability was disrupted even though the event was not itself a theft of user funds.

Self-custody presents a different set of risks. EtherWorld's analysis of the COLDCARD exploit showed that hardware security can also fail when weaknesses appear in wallet generation or operational processes. Likewise, legacy Ethereum wallets were drained of more than $800K after compromised private keys exposed long-dormant addresses.

Root Cause Report Will Decide What Comes Next

Bitget has promised to publish a full incident report within 24 hours of its original announcement, including a root-cause analysis and corrective actions. Until that investigation is complete, the exchange has said it will not speculate about the attack mechanism.

A recent Ethereum Safe incident initially appeared to involve the wallet itself, but subsequent analysis found that the problem was linked to an authorised third-party module rather than Safe's core multisig contracts. EtherWorld covered the distinction in $7.73M rsETH Lost in Ethereum Safe Exploit.

Even ordinary user devices can become part of that attack surface. EtherWorld recently reported that a Safari zero-day raised risks around sensitive information on Apple devices, while separate phishing campaigns have shown how attackers can bypass strong infrastructure by targeting users directly.

The industry will be watching for the compromised component, duration of unauthorized access, affected wallet architecture, asset recovery efforts, safeguards introduced afterward and how the User Protection Fund is ultimately used. Until those details are published, several conclusions remain premature.

What is confirmed is that Bitget detected unauthorized transfers affecting approximately $351.6 million, cold wallets were reported as unaffected, withdrawals were suspended, deposits and trading remained available and the exchange says its $464 million-plus protection fund can cover the loss.

With the root cause still under investigation, the next update may prove more important than the initial breach announcement itself. It will determine whether the incident was an isolated wallet compromise or evidence of a broader weakness in the operational security surrounding one of crypto's major centralized exchanges.


To promote your Web3 articles, events, and projects, you may reach out anytime via EtherWorld PR for submissions and collaboration.

Related Articles

To follow blockchain news, track Ethereum protocol progress, and read our latest stories, subscribe to our weekly today.

Join the EtherWorld & Avarch Internship Program and build your career in blockchain, content, social media, video, podcast editing, or operations. Send your resume and brief introduction to contact@etherworld.co.


Disclaimer: The information contained in this website is for general informational purposes only. The content provided on this website, including articles, blog posts, opinions, & analysis related to blockchain technology & cryptocurrencies, is not intended as financial or investment advice. The website & its content should not be relied upon for making financial decisions. Read full disclaimer & privacy policy.

To stay updated on blockchain news, Ethereum protocol progress, and our latest stories, subscribe to our weekly digest and YouTube channel for ELI5 content.

To promote your Web3 articles, events, project updates, and Press Releases, reach out anytime via EtherWorld PR for submissions and collaboration. For other queries, email contact@etherworld.co.

If you’d like to support our work, share the content and consider donating at avarch.eth.

Join our community on Discord and follow us on Twitter, Facebook, LinkedIn & Instagram.

Sponsored
ETHShala

Understand Ethereum. Shape the Future — learn EIPs with ETHShala.

Inviting Web3 projects to partner with EtherWorld and increase visibility across the Ethereum ecosystem.

EIPs Insight

Track Ethereum protocol upgrades, EIPs & governance — all in one place.

EtherWorld.co × Avarch

Gain hands-on Web3 experience with our internship program.

Subscribe to join the discussion.

Please create an account to become a member and join the discussion.

Already have an account? Sign in

Sign up for EtherWorld.co newsletters.

Stay up to date with curated collection of our top stories.

Please check your inbox and confirm. Something went wrong. Please try again.
0/5 free articles read this week
Sign up free