Crypto exchange Bitget confirmed overnight that unauthorized transfers had occurred from hot wallets. CEO Gracy Chen said the security system detected abnormal outflows from some hot wallets at 18:31 UTC on September 24. Preliminary accounting put the affected funds at about $351.6 million. Officials said cold wallets remain secure, user account balances were not rewritten, and losses can be covered by a user protection fund of more than $464 million. The platform has paused withdrawals; deposits and trading remain open. It pledged to publish a full incident report including root-cause analysis before 21:30 UTC on September 25.

Before the official statement, on-chain analysts had already observed wallets labeled Bitget sending about $178 million to $190 million in assets to newly created addresses. Two figures currently coexist: $351.6 million is the exchange’s internal accounting; roughly $180 million is the on-chain tally of publicly labeled addresses.

The on-chain anomalies and the official detection time largely coincide. Unchained recorded the visible outflow window as 18:31–20:55 UTC on September 24. During that period, a newly created address withdrew about 19.67 million USDT0 from a Bitget-labeled hot wallet and, on Arbitrum, swapped it via UniswapX and 1inch Fusion into about 7,111 ETH in roughly six minutes, at prices as much as about 5% above market. On-chain observer DCF GOD was the first to flag that swap. Stablecoins can be frozen by issuers; converting them to ETH makes interception harder.

Multiple Bitget-labeled wallets then transferred ETH, USDT, USDC, AVAX, BNB, and XAUT into the same new address. Etherscan later tagged it Bitget Exploiter 1. Funds were then split to other addresses, with cross-chain bridging observed. Unchained also recorded that within about 30 minutes the same address received about 34.75 million USDT, 12.85 million USDC, and 3,000 XAUT; about an hour later it received about 24,373 ETH from multiple labeled addresses. At 20:55 UTC there was still an outflow from Avalanche.

At 20:24 UTC, Arkham Intelligence analyst Emmett Gallic posted an initial figure of about $178 million, updated at 20:35 UTC to about $183 million, saying three hot-wallet and one cold-wallet labeled addresses were involved, with multi-chain aggregation. The “cold wallet” here comes from browser and analyst labels and does not automatically match Bitget’s internal hot / warm / cold classification. At 21:06 UTC, Bubblemaps issued an alert that about $180 million across chains had been sent to the same address, updated at 21:33 UTC to about $190 million. CryptoSlate, citing those figures, said 15 transfers involved nearly $192 million across seven assets, with ETH accounting for about 44.4%.

At 21:30 UTC, Gracy Chen posted a full security notice on X; the official website published the announcement at the same time. The company confirmed about $351.6 million affected and stressed that only part of the hot and warm wallets were hit; cold wallets are fully secure. User balances are accurate; deposits and trading continue as normal; withdrawals were paused as a precaution. Bitget said it activated an emergency team within minutes of detection, tagged and reported the abnormal addresses, and notified law enforcement and on-chain security firms. Officials said they would not speculate on the attack path before the investigation is complete and would update hourly through official channels.

If the $351.6 million figure is confirmed, Bitget would rank among the larger centralized-exchange thefts on record, but still well below the February 2025 Bybit hack.

At that time, Bybit’s Ethereum cold wallet was drained of about 400,000 ETH during a routine transfer, then worth about $1.4–1.5 billion — the largest single exchange theft on record. Later investigation pointed to a targeted malicious script injected into the Safe multisig wallet frontend: signers saw a normal transfer on screen but actually signed a transaction that replaced the implementation contract, handing over control of the cold wallet. The FBI and other agencies later attributed the attack to a North Korea Lazarus-related cluster. Bybit covered the loss with its own funds, continued operating normally, and user funds were not affected.

After the February 2025 Bybit cold-wallet theft, Bitget was one of the first exchanges to offer public help. The platform sent 40,000 ETH of its own funds to Bybit — then about $105–106 million — to ease a withdrawal run. The loan was unsecured, interest-free, and had no fixed repayment date. Bybit CEO Ben Zhou later said in interviews that Bitget was the first to help and that they did not even sign a contract. Bitget also blacklisted related addresses and said it could provide further support. About three days later, Lookonchain monitored Bybit sending the 40,000 ETH back; Gracy posted confirming the funds had been returned.

In public post-mortems of centralized-exchange hacks, the most common cause is compromise of hot-wallet private keys or signing authority. Coincheck 2018 (~$530 million), KuCoin 2020 (~$280 million), and Bitmart 2021 (~$150 million) all pointed to loss of connected hot-wallet keys. Another class is multisig and signing-interface bypass: Bitfinex 2016 related to the then-current multisig scheme; WazirX 2024 involved takeover of multisig control; Bybit February 2025, and others. There are also supply-chain and operations failures, such as signer devices, wallet vendors, or internal privileges being abused.

As of publication, Bitget said it would follow up on the investigation hourly. The specific attack path (for example whether it involved private-key leakage or an interface vulnerability) awaits disclosure in the official full report.

Follow us

Twitter: https://twitter.com/WuBlockchain

Telegram: https://t.me/wublockchainenglish