Cryptocurrency exchange Bitget confirmed on September 24 that approximately $350 million in assets was drained from its hot wallets following an unauthorized transfer detected at 18:31 UTC. On-chain data revealed that roughly $183 million in ETH, USDT, USDC, AVAX, BNB, and other tokens moved to a single address within an hour. A newly created wallet subsequently spent $19.67 million in USDT0 to purchase 7,111 ETH on Arbitrum via decentralized exchanges UniswapX and 1inch Fusion, paying up to 5% above market price. Users reported blocked withdrawals during the incident, which appeared to cease six minutes after the initial suspicious trade.
CEO Gracy Chen stated that cold wallets remained fully secure and that only hot wallets were affected. She confirmed that user funds are safe because the loss falls within the coverage of Bitget’s User Protection Fund, which currently holds over $464 million. This incident follows previous industry breaches, including Bybit’s $1.4 billion loss in February 2025, highlighting ongoing security risks for centralized exchanges despite internal insurance mechanisms.
The confirmation of a $350 million breach underscores the persistent vulnerability of hot wallets, which remain essential for liquidity but are inherently exposed to online threats. While Bitget’s assertion that cold storage remains untouched mitigates immediate systemic risk, the rapid conversion of stablecoins into volatile assets like ETH suggests attackers prioritized speed and obfuscation over value preservation. The use of decentralized exchanges to execute trades at a premium indicates a sophisticated attempt to launder funds quickly, bypassing traditional compliance checkpoints that might delay or freeze such transactions.
From an institutional adoption perspective, the reliance on a self-insured User Protection Fund rather than external regulatory frameworks presents both a strength and a potential credibility gap. The fund’s size, exceeding $464 million, provides a buffer against this specific loss, yet it does not eliminate counterparty risk for users who trust the exchange’s solvency and operational integrity. Market participants will likely scrutinize whether such internal reserves are sufficient to handle larger-scale exploits, especially given the historical precedent of significant losses across major platforms. The incident serves as a reminder that technical safeguards alone cannot fully insulate centralized entities from targeted attacks, necessitating continuous refinement of security protocols and transparent communication strategies.


