Complete process of the Bitget hot wallet hack: how $352 million was lost, where the money went, and what users should do now—let’s make it clear in one sentence first: In the early hours of September 25 Beijing time, some of Bitget’s hot wallets/warm wallets saw unauthorized transfers. The official estimate of the amount affected is about $351.6 million; the cold wallets and users’ account balances claim not to have been impacted. Withdrawals have been suspended, while deposits and trading are still open. The official says the losses can be covered by the user protection fund of over $464 million.
This is not “one coin being stolen,” but rather multiple chains and multiple assets being drained at the same time. For on-chain tracking, the largest current hot wallet holder isn’t ETH, but XRP. First, the timeline: from the anomaly to the announcement—about 3 hours.
September 24, 18:31 UTC (Beijing time 25th 02:31): the official said its security system detected abnormal transfers from part of the hot wallets.
Then for about 2.5 hours: on-chain activity continued to see Bitget-labeled addresses send payments to new addresses; stablecoins were rapidly swapped into ETH, and some funds were split across chains. Early on-chain statistics at one point totaled only about $180–$190 million, a clear gap versus the official $351.6 million. That discrepancy came from addresses that weren’t all fully labeled yet, other chains, and differences in the internal bookkeeping scope.
Around 21:30 UTC: CEO Gracy Chen posted an announcement confirming the incident, pausing withdrawals, committing to release the complete incident report within 24 hours, and stating they would not guess the attack path before the investigation is finished.
In the early hours of the 25th: Bitget’s business side synchronized more detailed figures—an initial judgment is that it wasn’t a direct leak of private keys, but rather the wallet service backend was compromised. The attacker forged transfer information and invoked an already-authorized signing process to move the funds. They claimed losses were contained with no continued outflows. This is the official account; full technical attribution is still pending the report.
Even after detection, funds continue to leave parts of the network for several more hours—this is the core point of outside criticism of the response speed.
Two. Breakdown of what was stolen: the largest single item is the on-chain composition of $157 million, disclosed by XRPLookonchain (about $351 million in scale, close to the official numbers).
XRP: 102.93 million coins, about $157.5 million (largest single item)
ETH: 31,890 coins, about $85.75 million
USDT: 34.75 million
USDC: 21.05 million
USD₮0: 19.67 million
XAUt: 3,000 coins, about $12.82 million
BNB: 12,719 coins, about $9.88 million
AVAX: 821,012 coins, about $8.38 million
TRX: 20.59 million coins, about $7.07 million
After the stablecoins were transferred out, the attacker quickly swapped them for ETH in routes like Uniswap / 1inch, even willing to pay a premium to get the deal done. The purpose was very clear: to avoid freezes by the stablecoin issuer. This is a playbook that has been seen repeatedly in the industry after the 2025 Bybit incident. Three. What are hackers doing now? Most XRP, ETH, and BNB are still sitting at the attack addresses; there hasn’t been a one-time dump. Signs of “testing and cashing out” have appeared: about 33,500 XRP (roughly at the $50,000 range) were swapped into about 17 ETH via Bridgers / SWFT, then dispersed to three Ethereum addresses. Compared with the $157 million XRP holdings, this looks more like a bridge test than a main sell-off. Next, what will truly determine market impact isn’t “how much is missing,” but whether this batch will be sold on exchanges, whether it will be frozen, and whether it will remain stuck on-chain for a long time. Four. Is it “General Jin”? Right now it’s only suspicion, not a conclusion. The community and some media point at the North Korea Lazarus cluster for reasons including: cross-chain synchronization, layers of hot/tense wallets, instant swapping of stablecoins to ETH, and methods similar to the 2025 Bybit case where about $1.4–$1.5 billion was stolen. Bitget had also previously provided Bybit with unsecured ETH liquidity support.
But as of now, the official has refused to name the attacker. Until full evidence collection is complete, treating “General Jin” as a definite conclusion is too early. A more reliable way to phrase it is: the attacker obtained control of the wallet operations system, not the cold wallet private keys in a whole package. The cold wallet official insists it is intact. Five. Official commitments vs. three things that haven’t been fulfilled yet—those already clarified are:
Affected by about $351.6 million
Protection fund covers over $464 million; the book value can cover it
Cold wallet was not affected
The user ledger balance remains
Top-ups and trading continue; withdrawals temporarily suspended
Reported to law enforcement agencies and blockchain security companies
Not yet clarified—and this is what most affects trust:
Where exactly was the attack entry point: the supply chain, an internal system, a signing interface, or something else?
When will withdrawals be enabled, and will there be a small-amount verification first?
Proportion of stolen funds recovered/frozen
The protection fund is enough to cover losses, but it doesn’t mean trust automatically comes back. In exchange security incidents, what users fear is never “officially said the compensation will work,” but instead: “the money can’t be withdrawn for now, the announcements don’t match on-chain data, and phishing links are everywhere.” Six. Three layers of impact on the market. First layer: selling pressure. XRP and ETH are the key things to watch. If funds continue to move across bridges and into exchanges, there will be additional sell pressure in the short term; if they remain untouched for the long term or get frozen, the price shock will be much smaller. Second layer: Bitget itself. Pausing withdrawals is itself a stress test. As long as later you see things like “the restoration time keeps changing,” the report is vague, and new addresses keep bleeding out, then no matter how good the protection fund numbers look, it can’t hold back sentiment. Third layer: the entire CEX sector. This is another time, after Bybit, that hot/warm wallets worth several hundred million dollars have fallen. The more liquidity there is in a bull market, the more glaring the single-point risk of centralized custody becomes. This isn’t “which company was especially unlucky,” it’s an industry structural issue. Seven. What users should do now (first protect principal, then wait for verification)
Only go through official website/App entry points; refuse any private chat links like “compensation, migration, verifying wallet, signing补” (additional signature). These scams will explode within 1–2 hours after an incident.
Don’t top up more for now; save screenshots of your existing balance and order records yourself.
After withdrawals resume, first test with a small amount到账, then decide whether to reduce idle funds on the exchange.
Long term: set limits on a single platform for positions; keep large amounts in cold wallets / self-custody. Treat “funds can be withdrawn from an exchange” as daily rehearsal, not something you think about only after trouble happens.
Just watch three signals: the official notice about restoring withdrawals, whether the stolen XRP/ETH reach exchanges, and the freeze/recovery proportions.
Eight. Three possible follow-up paths (not predictions, but an observation framework)
Smooth restoration: the vulnerability is封上 + funds are made whole + withdrawals continue to arrive → trust slowly recovers.
Restoration delays: longer checks, queues, disclosures that don’t line up with on-chain data → uncertainty keeps going.
Risk expands: if new outflows or settlement/repayment anomalies appear again → credit pressure increases significantly.
If you’ve read this far, set your emotions aside and only focus on three sentences: the root cause must be made clear. The gap can be filled. Withdrawals keep arriving. Until all three conditions are met at the same time, any “it’s already fine” is still too early. Going forward, rely on Bitget’s official announcements and on-chain tracking; don’t trust screenshots and don’t click unknown links.
