Bitget announced that it detected unauthorized transfers worth approximately $351.6 million, prompting it to temporarily suspend withdrawals while investigating the security incident.
The company said its security systems detected the transfers at 18:31 UTC on Thursday, and that the incident affected a limited number of hot wallets, necessitating immediate activation of emergency response measures.
In an official statement, the CEO, Gracy Chen, said that the scope of impact was limited to part of the hot and warm wallet layers, while the cold wallet remained safe and unaffected.
Chen further explained that the affected assets included Ether (ETH), XRP (XRP), USDt (USDT), USDC (USDC), Avalanche (AVAX), BNB (BNB), and USDT0 (USDT0) on the Arbitrum network. She also noted that the affected networks included Ethereum, the XRP Ledger, Avalanche, BNB Smart Chain, and Arbitrum, with the bulk of the observed stolen funds concentrated on the Ethereum network.
The company added that some initial on-chain reports showed a smaller amount than what was later announced, because the incident was not limited to the Ethereum activity flagged in the early analysis, but instead extended to a wider range of transfers.
According to Bitget, withdrawals will remain temporarily on hold until the security review is completed. Chen said she expects withdrawals to be reopened within hours or days, without specifying a firm deadline.
Meanwhile, the platform confirmed that it has identified the addresses associated with the transfers and has contacted law enforcement agencies and specialized security firms to trace assets on-chain.
Bitget also emphasized that users’ balances remained accurate, and deposits and trading are still operating normally. It said the affected funds are nearly fully covered through its User Protection Fund, which is worth more than $464 million.
The company said it will publish hourly updates, along with a complete report on the incident within 24 hours, including an analysis of the root cause and corrective actions.
For users, the focus now remains on monitoring official announcements, checking for any unusual activity in accounts, and taking standard protective measures such as reviewing security permissions and enabling available insurance tools.
