Cryptocurrency exchange Bitget says unauthorized transfers affecting about $351.6 million were detected in parts of its hot- and warm-wallet infrastructure on September 24, prompting the company to suspend withdrawals. Deposits and trading remained available, according to reports citing the exchange, but customers could not move assets off the platform while its investigation continued.
The reported figure would make this a significant exchange security incident, though it remains a preliminary estimate rather than a final audited loss total. Bitget has said its cold wallets were unaffected, customer balances remain accurate and its User Protection Fund exceeds $464 million. Those are assurances from the company, not conclusions independently verified by a public forensic report.
What Bitget has disclosed
Yellow’s report on the withdrawal suspension said Bitget detected the activity at 18:31 UTC on September 24 and activated emergency procedures. The exchange said it identified or flagged abnormal transfer addresses and had notified law enforcement and on-chain security firms. A separate TechFlow account citing a Bitget regional executive similarly reported the roughly $351.6 million estimate, the service restrictions and the company’s claim that its protection fund could cover the estimated exposure.
Bitget chief executive Gracy Chen said, as reported by Crypto News, that private keys for the exchange’s cold, warm and hot wallets were not leaked. The same report said an initial investigation pointed instead to a compromise involving a core backend wallet service. In that account, false transfer data could have reached the approval-and-signature process.
That description should not be mistaken for a completed technical explanation. Bitget had not publicly released the underlying evidence, a transaction-by-transaction reconciliation or a full root-cause report in the published coverage. Nor does the preliminary finding establish who entered the systems. Chen reportedly said some observed patterns resembled previous North Korean operations, but no attribution to North Korea has been confirmed.
Several numbers describe different parts of the event
The $351.6 million number is Bitget’s reported internal estimate of assets affected by unauthorized transfers. It is not identical to figures produced by outside blockchain observers. Crypto News reported that Lookonchain valued a tracked portfolio at roughly $356.8 million at the time of its update, including 102.93 million XRP then valued at about $157.48 million.
There was an earlier, lower public view as well. Yellow reported that external monitors initially traced more than $170 million in transfers. The gap does not by itself show that either number is wrong. An exchange may identify wallets, assets or internal movements before all relevant addresses are publicly labeled, while an on-chain estimate can vary with the addresses included and the moment used to price volatile tokens. But no public transaction-level accounting in the reports reconciles the $170 million, $351.6 million and $356.8 million figures.
That distinction is practical rather than semantic. The final amount transferred, the amount frozen or recovered, and the amount that remains beyond Bitget’s control will determine the actual financial impact. Chen said some funds had been recovered, according to Crypto News, but neither a recovery amount nor supporting details were disclosed.
Withdrawal halt is the immediate customer test
For exchange users, the operational consequence is less abstract than competing estimates: withdrawals were paused. The exchange’s claim that trading and deposits continued does not restore a customer’s ability to transfer assets to another venue or to self-custody. The reports do not indicate that Bitget Wallet, the company’s separate self-custodial wallet product, was part of the affected exchange infrastructure; that separation, too, is based on the exchange’s account.
Crypto News reported that Bitget posted an initial security notice at 21:39 UTC on September 24 and promised a detailed incident report within 24 hours. As of that outlet’s September 25 report, withdrawals remained suspended and Bitget had not announced a reopening time. Coverage published the following day repeated the suspension and the company’s estimate, without documenting a public final technical report or a restoration schedule.
Bitget’s protection-fund assertion is likely to receive close scrutiny if the preliminary estimate holds. A fund reported at more than $464 million would exceed the company’s stated $351.6 million exposure by about $112.4 million, or roughly 32 percent. That arithmetic does not establish that the reserve is liquid, segregated, available for this event, or sufficient once the incident is finally counted. None of those questions can be answered from a stated balance alone.
A breach claim without the usual public evidence
Bitget’s preliminary account narrows one possibility by saying private keys were not leaked, but it raises a more difficult systems question: how an approval workflow could accept fraudulent transfer information. In a well-designed custody environment, critical actions are meant to require controls that remain effective even if an adjacent service is compromised. The public reporting does not say what checks operated here, which failed, or whether the implicated service could influence multiple wallet tiers.
Those details matter before drawing conclusions about the scale of the compromise or Bitget’s recovery prospects. The facts presently established in published accounts are narrower: the exchange reported unauthorized transfers, set a preliminary affected-asset estimate near $351.6 million, halted withdrawals and began an investigation. The rest—including the intrusion path, final accounting, recovery total and reopening date—remains unresolved.
