How Did the Bitget Breach Reach $351.6 Million?

Crypto exchange Bitget has confirmed that approximately $351.6 million in digital assets were affected by unauthorized transactions from portions of its hot and warm wallet infrastructure, sharply increasing the estimated scale of an incident first detected through unusual on-chain transfers.

Bitget said its systems identified the unauthorized activity at 18:31 UTC on September 24 and activated emergency procedures shortly afterward. Withdrawals have been temporarily suspended while the exchange conducts a security review, although deposits and trading remain available.

CEO Gracy Chen said Bitget’s cold wallets were not compromised and that customer account balances remain accurate. The exchange also said the estimated loss falls within its User Protection Fund, which it currently values at more than $464 million.

Early blockchain tracking initially identified more than $170 million moving from Bitget-labeled addresses into newly created wallets. Subsequent analysis pushed the visible transfers above $180 million before Bitget disclosed the substantially higher $351.6 million estimate for the full incident.

Assets involved included ETH, USDT, USDC, AVAX and BNB. In one notable transaction on Arbitrum, a newly created address used roughly $19.67 million of USDT0 to acquire about 7,111 ETH through decentralized trading systems including UniswapX and 1inch Fusion.

Can Bitget’s Protection Fund Cover the Loss?

Bitget says its Protection Fund is currently worth more than $464 million, placing its stated value above the estimated loss. The fund was established in 2022 as a separate financial backstop and is distinct from the exchange’s proof-of-reserves system.

Bitget’s August disclosure showed the fund holding 5,500 BTC, with an average monthly valuation of approximately $382 million. Its value ranged between roughly $345 million and $441 million during the month as Bitcoin prices fluctuated.

The exchange also reported a 135% total reserve ratio in its September proof-of-reserves update. However, proof of reserves and a protection fund answer different questions. Reserve disclosures attempt to show whether customer assets are backed at a specific point in time, while the protection fund is intended to absorb extraordinary losses.

Investor Takeaway

The $464 million Protection Fund gives Bitget a stated financial buffer larger than the estimated breach. The more important test is whether that protection can be deployed without disrupting customer withdrawals or creating a new shortfall elsewhere in the exchange’s operational liquidity.

Why Are Withdrawals the Critical Test?

Temporarily freezing withdrawals after detecting unauthorized wallet activity is a standard containment step. The exchange needs time to identify compromised infrastructure, rotate credentials or signing systems and reconcile customer balances before reopening asset flows.

The difference is that prolonged withdrawal restrictions can quickly turn a security incident into a confidence problem. Recent withdrawal delays at WOO X showed how quickly users scrutinize exchanges when assets remain inaccessible, even when no insolvency has been established.

Bitget has not disclosed how the attacker gained access and said it would avoid speculation until its investigation is complete. Chen promised a full incident report covering the root cause and corrective actions within 24 hours.

That report will be important because compromises involving hot and warm wallets can originate from several places, including private-key exposure, signing infrastructure, internal permissions or application vulnerabilities. Recent crypto infrastructure attacks have shown that identifying the exact access point is necessary before determining which controls failed.

Does the Breach Create a Solvency Risk?

A $351.6 million security loss does not automatically mean Bitget is insolvent. The distinction depends on whether the exchange still has sufficient assets to meet customer liabilities after accounting for the stolen funds and whether its Protection Fund is available as described.

That distinction matters in a market where withdrawal interruptions are closely watched following previous exchange failures. Broader concerns around centralized exchange insolvency risk tend to focus on reserve shortfalls, hidden liabilities and persistent inability to return customer assets rather than on a security breach by itself.

Bitget has so far made three central claims: its cold wallets remain secure, customer balances are protected and its Protection Fund is large enough to absorb the estimated loss.

The next evidence will be operational. Investors will be watching how quickly withdrawals reopen, whether the $351.6 million loss estimate changes after reconciliation and whether the incident report explains how an attacker gained access to both hot and warm wallet infrastructure.

Until those questions are answered, Bitget may have demonstrated that it has a financial backstop, but the effectiveness of that backstop under real-world stress has yet to be fully tested.