Press "Enter" to skip to content

Bitget Freezes Withdrawals After Hackers Drain $351.6 Million From Hot Wallet, Reigniting Crypto Security Fears $BTC

  • Bitget reports unauthorized transfers of approximately $351.6 million from parts of its hot and warm wallet infrastructure.
  • The exchange says cold wallets were not compromised and customer balances remain accurate.
  • Bitget’s User Protection Fund, holding more than $464 million, is stated to cover the full estimated loss.
  • Withdrawals are temporarily suspended; deposits and trading remain available.
  • Bitget has flagged abnormal transfer addresses and contacted law enforcement and onchain security firms, promising a full incident report within 24 hours.

$351.6 $BTC

What Bitget Has Confirmed So Far

The exchange has been specific about the scope of the incident and equally specific about what it is not yet saying. According to Bitget, the loss estimate of approximately $351.6 million falls entirely within its User Protection Fund, which currently holds more than $464 million. That buffer is larger than the estimated loss, which is the basis for the company’s claim that customers will not absorb the hit. Bitget also says it has identified and flagged the abnormal transfer addresses tied to the incident and has contacted law enforcement and onchain security firms to assist with the review.

Notably, Bitget is deliberately withholding public speculation about how attackers gained access. The company has promised a full incident report, including a root-cause analysis, within 24 hours. Until that report arrives, the mechanism of the breach — whether through a compromised key, an internal control failure, or something else — remains unknown. That gap matters, because the root cause determines whether the affected wallets have truly been contained or whether the exposure is broader than the current estimate suggests.

Why the Protection Fund Is Now the Story

Exchange protection funds tend to sound reassuring when markets are calm. A major exploit is when they become meaningful. Bitget’s stated $464 million-plus fund exceeds the current $351.6 million estimate, which supports the company’s position that it can absorb the incident without passing losses to users. But a fund’s stated size and its actual, liquid availability under stress are not always the same thing, and the final loss figure or attack scope could still change as the investigation develops.

The Operational Problem Remains

Covering the loss does not remove the operational disruption. Withdrawals being paused means users temporarily cannot move assets off the platform, regardless of whether their balances are intact on paper. For an exchange, that is a trust event as much as a financial one. The breach also reinforces the long-standing distinction between exchange custody and self-custody: assets held in an exchange hot wallet depend on that exchange’s security systems, operational controls, and balance sheet. Bitget says its separate self-custodial Bitget Wallet infrastructure was not involved in the incident.

For now, the key questions are straightforward. How did the attacker gain access? Have all affected wallets been contained? And when can withdrawals safely resume? A $351.6 million loss is large enough that the promised root-cause report will matter well beyond Bitget’s own user base, serving as a reference point for how other exchanges assess their own hot and warm wallet exposure. Until that report is published, the exchange’s public posture is one of containment and disclosure without attribution — a reasonable stance, but not yet a complete answer.

More from CRYPTOMore posts in CRYPTO »

Comments are closed.

WP Twitter Auto Publish Powered By : XYZScripts.com