Bitget suspended withdrawals on September 24, 2026 after attackers made unauthorised transfers worth an estimated $351.6 million from its wallets.

The exchange detected the transactions at 18:31 UTC and activated emergency security measures within minutes.

Bitget said the transfers affected parts of its hot and warm wallet infrastructure, while its cold wallets remained secure.

Bitget responded by stopping withdrawals but kept its deposits and trading available on the platform.

The exchange also flagged wallet addresses linked to the transfers and contacted law enforcement agencies and blockchain security firms.

Bitget said the affected transactions did not change the account balances of its customers.

CEO Gracy Chen later addressed the incident during a live Q&A and provided more details about the attack.

Chen said the attackers did not obtain private keys from Bitget’s hot, warm, or cold wallets.

Instead, the attackers accessed Bitget’s internal systems and transferred assets without using customer withdrawal requests.

Chen said Bitget’s preliminary investigation pointed to a compromised backend wallet service.

According to her account, attackers introduced false transfer information into the exchange’s approval-signature process.

Chen said Bitget had not identified evidence showing that an insider caused the transfers.

The exchange also addressed the potential impact on customers after estimating the loss.

Chen said Bitget’s User Protection Fund held more than $464 million and could cover the reported $351.6 million loss.

Bitget has not announced when it will restore withdrawals while its security review continues.

Bitget

Hacker Converts $183M Into Ether as Stolen Assets Emerge

While Bitget investigated the breach, blockchain researchers began tracking where the stolen assets moved.

Lookonchain reported that the attacker converted about $183 million of the stolen funds into Ether, the novel token of Ethereum.

The swaps showed that the attacker began moving the assets soon after taking them from Bitget-linked wallets.

Lookonchain later identified 102.93 million XRP worth about $157.48 million among the stolen assets.

The tracked wallets also contained 31,890 ETH worth about $85.75 million, according to the blockchain analytics platform.

Researchers also found 34.75 million USDT, 21.05 million USDC, and 19.67 million USD₮0 in the tracked wallets.

The portfolio also included 3,000 XAUt, 12,719 BNB, 821,012 AVAX and 20.59 million TRX.

Lookonchain valued the tracked assets at about $356.8 million, while Bitget estimated the loss at $351.6 million, creating a difference between the exchange’s figure and the blockchain estimate.

Bitget said investigators had recovered some of the stolen assets during the recovery effort. However, the exchange has not disclosed how much it recovered or provided a verified recovery figure.

Bitget Probe Examines Possible North Korean Link

Bitget is examining a possible North Korean connection after investigators identified internet protocol (IP) addresses linked to virtual private network (VPN) services associated with a DPRK hacking group.

CEO Gracy Chen said the activity showed similarities with patterns linked to previous North Korean operations.

However, Bitget has not identified the attackers or confirmed that a North Korean group carried out the transfers.

The cryptocurrency exchange plans to publish a detailed incident report covering the investigation’s findings.

The report will outline the root cause and the corrective measures that Bitget plans to implement.

The exchange has not announced when it will release the report beyond its stated 24-hour timeline.

Share.
Leave A Reply