Crypto exchange Bitget has suffered a major security breach that affected approximately $351.6 million in digital assets.
The exchange detected unauthorised transfers from some of its hot wallets on September 24. It then suspended withdrawals while its security teams investigated the incident.
Bitget says its cold wallets remain secure. The exchange also says customer funds are covered by its User Protection Fund, which holds more than $464 million.
Bitget Detects $351.6 Million Security Breach
Bitget’s security systems detected the suspicious transfers at 18:31 UTC on September 24.
The exchange activated its emergency response procedures within minutes. It then identified and reported the addresses involved in the transfers.
On-chain researchers had already spotted unusual activity from wallets linked to Bitget.
Initial data showed more than $170 million moving across several blockchain networks. Further investigation later put the affected assets at approximately $351.6 million.
Hack Targeted Bitget’s Wallet Infrastructure
Bitget initially described the incident as unauthorised transfers from part of its hot wallet infrastructure.
A later update provided more detail about the suspected attack method.
The exchange said an attacker compromised a critical backend system within its wallet infrastructure. The attacker then spoofed transaction data and triggered Bitget’s authorisation process to move funds.
Bitget said its investigation has ruled out a private-key compromise.
The precise method used to enter the backend system remains under investigation.
Several Crypto Assets Were Affected
The stolen assets moved across multiple blockchain networks.
These included:
-Ethereum
-XRP
-BNB
-Avalanche
-USDT
-USDC
-Other digital assets
The incident affected transactions across networks including Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Chain and Base.
XRP accounted for one of the largest portions of the identified losses. Lookonchain estimated that more than 102 million XRP, worth about $157 million at the time, was affected.
Bitget Suspends Withdrawals After the Hack
Following the breach, Bitget temporarily suspended customer withdrawals.
The exchange said deposits and trading remained operational while security teams worked on containment and system repairs.
Bitget has not provided a fixed time for restoring withdrawals.
Instead, the company said it would resume the service after completing its security review and confirming that it is safe to do so.
Bitget Says User Funds Are Safe
Despite the size of the breach, Bitget says customer balances remain accurate.
The exchange operates a three-tier wallet architecture. According to Bitget, the breach affected only part of its hot and warm wallet layers.
Its cold wallets remained unaffected.
Bitget also said the loss falls within the coverage of its User Protection Fund.
The fund currently holds more than $464 million, according to the exchange.
North Korean Hackers Suspected
Bitget CEO Gracy Chen has linked the attack to North Korean hacking groups.
The exchange said IP behaviour and on-chain analysis showed similarities with known North Korean cybercrime patterns. However, the broader investigation remains ongoing.
Bitget has notified law enforcement agencies and blockchain security firms.
The exchange is also working with cybersecurity specialists as investigators examine the attack.
Bitget Hack Raises Fresh Exchange Security Concerns
The incident highlights the security risks faced by centralised crypto exchanges.
Exchanges manage large amounts of digital assets through interconnected wallet, trading and backend systems. Therefore, attackers do not always need to obtain a customer’s private key to cause significant losses.
The Bitget incident shows how a compromised backend system can potentially trigger authorised processes and move assets.
That makes access controls, transaction monitoring and backend security just as important as protecting private keys.
Bitget Begins Security Review
Bitget says its teams are working on system remediation and additional security hardening.
The company also plans to publish a full incident report covering the root cause and corrective measures.
For now, the exchange says no further unauthorised transfers are possible.
However, withdrawals will remain paused until the security review is complete.
You may also like : Larry Cooke: African Regulators Should Treat Stablecoins Separately From Other Crypto Assets
Editorial Takeaway
The Bitget $350 million hack is another reminder that crypto exchange security extends beyond private-key protection.
In this case, Bitget says the attacker compromised a backend wallet system rather than directly stealing private keys.
The exchange has also stated that its User Protection Fund can cover the affected amount. Still, the incident puts renewed attention on how centralised platforms protect their wallet infrastructure.
For the wider crypto industry, the breach highlights a simple reality: strong wallet security is only one part of exchange security.
Backend systems, transaction approvals, access controls and real-time monitoring must also withstand sophisticated attacks.
As Bitget completes its investigation, the final root-cause report should provide a clearer picture of how the breach happened and what exchanges can do to prevent similar attacks.
