Overview
- Bitget detected unauthorized transfers from some hot and warm wallets on Thursday, September 24 at 18:31 UTC and later said roughly $351.6 million was exposed after attackers moved assets across multiple chains.
- The company froze withdrawals as a safety measure while keeping deposits and trading online during a security review to prevent further outflows.
- Bitget said its cold wallets were not affected and that the loss falls within its User Protection Fund, which the exchange says holds more than $464 million.
- Independent on‑chain analysts first flagged the activity after seeing about $170–183 million move to a single fresh address and rapid swaps that included a $19.67 million USDT0→7,111 ETH trade on Arbitrum, with estimates rising as more transfers were traced.
- Bitget has flagged receiving addresses, notified law enforcement and security firms, suggested a possible link to the Lazarus Group without publishing technical proof, and promised hourly updates plus a full incident report within 24 hours.