Bitget has paused withdrawals after unauthorized wallet transfers, while CEO Gracy Chen says its protection fund covers the affected amount and promises a report within 24 hours.

Bitget's exhibition stand in May 2025, before the incident. Photo: Harris de Weerd via Wikimedia Commons (CC BY-SA 4.0); resized and compressed. Source
Bitget confirmed on September 24 that unauthorized transfers affected approximately $351.6 million in assets and said it had temporarily suspended withdrawals. In its official security notice, the exchange said its systems detected the transfers at 18:31 UTC and that the incident involved a limited number of hot wallets.
Chief executive Gracy Chen gave a more specific description of the affected infrastructure. In a separate statement, she said the breach reached portions of Bitget's hot- and warm-wallet layers, while its cold wallets remained secure. The exchange said customer account balances remained accurate and deposits and trading were still operating normally.
Those statements establish Bitget's account of the incident and its service restrictions. The company has not yet disclosed the attack method or released the root-cause analysis Chen promised. Cointelegraph's report independently records the confirmed affected amount and withdrawal suspension, following earlier reports of unusual transfers.
Chen said Bitget's User Protection Fund held more than $464 million and covered the full affected amount. "The full amount of this loss falls within the coverage of Bitget's User Protection Fund," she wrote in the security notice.
The fund valuation and coverage assurance come from Bitget. Neither that notice nor the exchange's accompanying post provides a transaction-by-transaction account of recovered assets, a completed compensation distribution or a detailed explanation of how the fund would be applied. The announced coverage should therefore be distinguished from money already recovered from the recipient wallets.
The exchange's operational position is also specific: it says balances are accurate, deposits and trading remain available, and withdrawals are paused until the security review is complete. A displayed account balance and the ability to transfer assets off an exchange are separate matters. CoinDesk's coverage reports the same separation between continued trading and suspended withdrawals.
Bitget has not supplied a fixed time for reopening withdrawals in the statements reviewed for this report. Its official account says teams are working to restore the service as soon as it is safe to do so. Chen similarly tied restoration to completion of the security review.
Public warnings preceded the exchange's confirmation. Arkham analyst Emmett Gallic posted an initial estimate of $178 million and linked to a tracker for the recipient's fund flows. The Block's initial report, published before Chen's notice, described more than $170 million moving from Bitget-labeled wallets to a new address, followed by onchain swaps.
That early report named ether, USDT, USDC, AVAX and BNB among the assets observed. It also described source addresses carrying hot- and cold-wallet labels. Bitget's later statement says its cold wallets remained unaffected and places the compromise in portions of the hot- and warm-wallet layers.
The difference between those descriptions remains unresolved in the material reviewed. A blockchain analytics label identifies how a service categorizes an address; it does not by itself establish which part of an exchange's signing infrastructure was compromised. The promised technical report may explain the relationship between the labeled addresses and Bitget's internal wallet architecture.
The early $170 million and $178 million figures are observations from an earlier stage of reporting, not additional losses to add to Bitget's $351.6 million assessment. CoinDesk reports that researchers continued flagging movements as the incident developed. Bitget describes its own amount as an approximate current assessment.
Bitget says it identified and flagged addresses associated with the transfers and engaged law enforcement agencies and onchain security firms. The company statement does not identify an attacker, attribute the breach to a particular group or explain how access was obtained. It explicitly declines to speculate on the attack vector while the investigation continues.
Chen has committed to hourly updates through official channels and a full incident report within 24 hours of her notice. She said that report would include the root cause and corrective actions. At the time of the statements reviewed here, withdrawal restoration remained conditional on the security review, with no reopening time announced.