Bitget has confirmed a security incident involving unauthorized transfers totaling approximately $351.6 million in assets. The exchange detected the activity at 18:31 UTC on Thursday, affecting a limited number of hot wallets, and subsequently activated emergency response procedures while temporarily suspending all withdrawals to conduct a comprehensive security review.
CEO Gracy Chen stated that the breach was contained to portions of the hot and warm wallet layers, with cold storage remaining secure. She emphasized that user account balances remain accurate and that deposits and trading continue to operate normally. Chen noted that the affected amount falls within Bitget’s User Protection Fund, which holds more than $464 million. The exchange has flagged associated addresses, contacted law enforcement and onchain security firms, and promised hourly updates alongside a full incident report including root-cause analysis within 24 hours.
The containment of this significant loss within Bitget’s existing User Protection Fund highlights the critical role of pre-funded reserves in maintaining operational continuity during acute security failures. By ensuring that cold wallets remained untouched and user balances were unaffected, the exchange avoided immediate insolvency or a bank-run scenario, demonstrating how robust capital buffers can absorb shocks without disrupting core trading functions. This incident underscores the industry standard where centralized exchanges rely on segregated storage architectures and dedicated insurance pools to mitigate the systemic risk posed by hot wallet vulnerabilities.
However, the suspension of withdrawals introduces substantial liquidity friction and reputational risk, even if solvency is technically preserved. The lack of disclosure regarding the attack vector creates an information vacuum that may fuel market speculation about internal control failures or sophisticated external exploits. Investors and users will likely scrutinize the forthcoming root-cause analysis for evidence of whether this was a technical flaw, a social engineering success, or an insider threat. The speed and transparency of the subsequent reporting will be pivotal in restoring trust, as prolonged opacity often exacerbates panic despite the presence of financial safeguards.


