Particle.news

Bitget Loses $351.6 Million After Backend Breach Drains Hot Wallets

The exchange says attackers spoofed transfer data without stealing private keys and that its User Protection Fund will cover the loss.

Overview

  • Bitget detected unauthorized transfers at 18:31 UTC on Thursday after on‑chain researchers first flagged unusual outflows from wallets labeled as the exchange.
  • CEO Gracy Chen says attackers breached a backend wallet system to fake transaction data and trigger legitimate signing processes while cold wallets and private keys remained secure.
  • About $351.6 million moved across multiple chains and tokens, with large amounts of XRP and ETH among the assets tracked on public ledgers.
  • Withdrawals are paused during a comprehensive security review even as deposits and trading remain open, and Bitget has engaged Mandiant, SlowMist and law enforcement to trace and recover funds.
  • Bitget says its User Protection Fund, which it values above $464 million, plus additional capital will cover customer balances, a move that could substantially draw down reserves and test user confidence when withdrawals resume.