Bitget Hot Wallet Breach Drains Over $350M from Exchange Accounts
Highlights
On-chain monitors observed roughly $183 million in ETH, USDT, USDC, AVAX, BNB and other tokens move from wallets labeled as Bitget's into a single newly created address within about an hour. A fresh wallet converted $19.67 million in USDT0 to 7,111 ETH on Arbitrum in six minutes, paying up to ~5% above market price via UniswapX and 1inch Fusion — a pattern consistent with a rapid exploit. Bitget confirmed a security incident affecting hot wallets and said cold wallets remain secure; the company also stated user funds are covered by its protection fund. This quick, premium-priced swapping behavior was a clear indicator of an active theft intended to obfuscate and monetize stolen assets fast.
Sentiment Analysis
The overall sentiment around the incident is mixed to negative: users express concern over lost funds and blocked withdrawals, while the exchange's reassurances and a sizable protection fund temper the panic. Public on-chain sleuthing and rapid reporting intensified scrutiny and uncertainty across social channels. The emotional tone combines alarm at the scale of transfers with cautious relief from the exchange’s claim that cold storage and insurance-like coverage remain intact. Institutional confidence may be dented as the episode underscores ongoing hot-wallet risks for centralized platforms.
Article Text
On September 24, on-chain analytics flagged an unusual sequence of transfers tied to wallets publicly labeled as belonging to a major centralized cryptocurrency exchange, Bitget. Within roughly an hour, observers recorded approximately $183 million in various tokens moving from those wallets into a single destination address. The company later confirmed an incident involving unauthorized transfers from some of its hot wallets, while asserting that its cold wallets — which are held offline — remained secure.
The first notable transaction involved a newly created address that used about $19.67 million in USDT0 to buy 7,111 ETH on the Arbitrum network in a six-minute window. The trades routed through decentralized swap services such as UniswapX and 1inch Fusion, and the orders paid premiums of up to around 5% above prevailing market prices. Paying above-market rates in such a concentrated, time-compressed fashion is a common hallmark of attackers prioritizing speed over cost to convert stolen assets into harder-to-seize tokens.
Subsequent transfers included ETH, AVAX, BNB, USDC, USDT and even XAUT — a token backed by physical gold — all funneled toward the same cluster of addresses. On-chain investigators and pseudonymous researchers flagged the activity within minutes, calling attention to the destination addresses and the rapid dispersion of funds. The outflows appeared to slow and then stop after a short period, consistent with an exchange detecting abnormal behavior and freezing withdrawals while investigating the incident.
Bitget’s CEO announced the hack publicly and emphasized that the company’s cold storage holdings were unaffected. The CEO also stressed that the total loss falls within the exchange’s User Protection Fund, which the company said holds over $464 million — a reserve intended to cover customer losses in the event of theft or other security incidents. That assurance aims to provide restitution to users while the company and law enforcement追追追 pursue recovery and forensic analysis.
The event highlights the differential risk between hot and cold wallets. Exchanges keep a portion of assets in hot wallets to facilitate everyday withdrawals and trading; these wallets, being connected to the internet, are more exposed to compromise than offline cold wallets. The industry mantra "not your keys, not your coins" underscores that custody with a third party carries counterparty and operational risk absent government deposit insurance typical of traditional banks.
This incident is not unique in crypto’s recent history. Centralized platforms have previously suffered substantial losses from exploits, and the sector has seen high-profile breaches where attackers used social engineering, compromised signing procedures, or software vulnerabilities to move funds. Exchanges have responded by building internal protection measures, expanding insurance or protection funds, and increasing transparency around incident response. Nevertheless, each large event renews debate over custody best practices and the trade-offs users face between convenience and control.
Investigations typically proceed on multiple fronts: forensic blockchain tracing to follow the flows, internal audits to identify how keys or access were compromised, coordination with other exchanges and decentralized services to hinder laundering, and law enforcement engagement to pursue recoveries or arrests. Meanwhile, affected users often await formal reimbursements pending confirmation of balances and eligibility.
The key takeaway is that hot-wallet exposure remains an operational vulnerability for centralized platforms. Even with protection funds and rapid detection, breaches can result in material outflows and customer disruption, reinforcing the importance of layered security, transparent reserves, and user awareness of custody risks.
Key Insights Table
| Aspect | Description |
|---|---|
| Scale of Loss | More than $350 million reportedly drained; ~ $183 million moved on-chain within an hour to a single destination. |
| Affected Wallets | Hot wallets used for daily operations were compromised; cold wallets remain offline and secure per the exchange. |
| Conversion Strategy | Attackers rapidly swapped stablecoins for ETH via UniswapX and 1inch Fusion, paying up to ~5% premium to move funds quickly. |
| Exchange Response | Emergency protocols activated; withdrawals appeared paused; company claims user losses covered by a protection fund. |
Last edited at:2026/9/24
