Bitget lost approximately $351.6 million on September 24 after attackers breached part of its hot and warm wallet infrastructure and forged transaction data to trick the exchange’s own authorization systems into approving unauthorized transfers, CEO Gracy Chen said.
Bitget’s security systems detected unauthorized transfers at 18:31 UTC on September 24, prompting the exchange to activate its emergency response procedures.
The incident immediately drew attention from blockchain researchers monitoring unusual movements from wallets associated with the exchange. However, the details disclosed by Chen indicate that the Bitget hack was not a conventional private-key theft.
Bitget hack affects hot and warm wallet layers
The Bitget hack involved parts of the exchange’s hot and warm wallet architecture, according to the company. Hot wallets remain connected to internet-facing systems so exchanges can process deposits, withdrawals and other transactions efficiently.
Warm wallets provide an intermediate layer between those online wallets and cold storage, which is designed to keep assets and signing infrastructure isolated from internet-connected systems.
Bitget said the breach did not compromise its cold wallets. The exchange operates a three-layer wallet structure, and the company stated that only a portion of its hot and warm wallet layers was affected.
Authentication systems, transaction-generation software, internal authorization mechanisms and backend infrastructure can all become potential attack surfaces.
According to the company, the unauthorized transfers were identified and the addresses involved were flagged. Bitget also notified law-enforcement agencies and blockchain security firms as investigations continued.
Bitget said it would provide a fuller technical explanation after investigators establish the root cause.
Bitget hack triggers withdrawal suspension
Following the Bitget hack, the exchange temporarily suspended withdrawals while its security team conducted a review. Deposits and trading remained operational, according to the company’s official security notice.
Bitget said customer account balances remained accurate and that user assets were protected. It also stated that the entire estimated loss fell within the coverage of its User Protection Fund, which it valued at more than $464 million at the time of the incident.
The exchange’s decision to pause withdrawals reflects a standard containment measure following a major security incident.
Keeping withdrawals disabled can give investigators additional time to identify affected systems, review transaction authorization processes and secure wallets that may have been exposed.
Bitget also said abnormal transfer addresses had been identified and reported, while external security specialists and law-enforcement authorities had been brought into the investigation.
Exchange users may be unable to move assets off-platform until the security review is completed and withdrawal services are restored.
What the Bitget hack means for crypto investors
The Bitget hack illustrates why exchange security cannot be assessed solely by asking whether private keys are stored offline. Modern cryptocurrency platforms rely on multiple layers of infrastructure to determine which transactions are legitimate and which are authorized.
In this case, Bitget’s account of the incident points toward a compromise of the systems responsible for preparing or presenting transaction information rather than direct theft of the keys used to authorize wallet transactions.
Independent blockchain monitoring also helped bring the incident into public view. Earlier reporting identified unusual movements involving assets associated with Bitget wallets, while subsequent company statements confirmed that unauthorized transfers had taken place.
The Bitget hack also puts renewed attention on exchange transparency. Bitget has committed to publishing a detailed incident report covering the root cause and corrective actions.
Until that report is released, several technical questions remain open, including exactly how the attacker entered the backend environment, which controls were bypassed and what changes will be made to prevent a repeat.
The episode reinforces the importance of understanding how exchanges protect assets across hot, warm and cold storage, as well as how they authenticate withdrawals and monitor unusual transaction activity.
The immediate outcome is clearer: Bitget says the unauthorized outflows have been contained, cold wallets were not compromised, and the affected amount is covered by its stated protection fund.