Particle.news

Bitget Hack Drains $351.6 Million From Hot and Warm Wallets

A breach of a backend wallet service forced Bitget to pause withdrawals and rely on its user protection fund to cover customer losses.

Overview

  • Bitget detected unauthorized transfers from a limited set of hot and warm wallets on Thursday, Sept. 24 at 18:31 UTC and then suspended withdrawals while emergency protocols ran.
  • The exchange says attackers breached a core backend wallet service, spoofed transaction data to trigger legitimate-looking transfers, and did not obtain private keys or touch cold storage.
  • On‑chain analysts produced changing tallies as tracing continued, with Bitget’s internal estimate at $351.6 million and some outside counts rising toward $387.5 million, with XRP singled out as the largest single asset moved.
  • Bitget has flagged suspect addresses, notified law enforcement, engaged Mandiant and SlowMist for forensic work, said some addresses have been frozen or partly recovered, and affirmed its $464 million User Protection Fund covers the reported loss.
  • The incident leaves users unable to withdraw until the security review ends and raises fresh scrutiny of exchange custody controls, proof‑of‑reserves practices, and how quickly traced funds can be frozen or recovered.