Bitget is investigating a major security incident that affected approximately $351.6 million in cryptocurrency, with CEO Gracy Chen providing a more detailed update after a lengthy livestream with users. Bitget’s official security notice says unauthorized transfers were detected from some hot wallets at 18:31 UTC on September 24, triggering an emergency response and a temporary suspension of withdrawals.
The exchange says its cold wallets remained secure and that the affected amount falls within its User Protection Fund, which currently holds more than $464 million.
Bitget Incident Spans Multiple Blockchain Networks
According to Chen’s latest update, the affected assets include ETH, XRP, BNB, AVAX, USDT, USDC and several other cryptocurrencies. The incident spans Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Smart Chain and Base, making it a multi-chain security event rather than an isolated problem involving one blockchain or token. Chen said cold wallets across the affected networks had been confirmed secure and unaffected, while the unauthorized activity was contained to parts of Bitget’s hot and warm wallet infrastructure.
XRP appears to account for the largest single-chain portion of the incident. Independent on-chain tracking identified approximately 102.93 million XRP, valued at about $157.5 million at the time of reporting, among the assets associated with the breach. Other blockchain activity identified by security researchers included ETH, USDT0, USDC, AVAX and BNB, with the initial publicly observed movements totaling about $183 million before Bitget provided its broader $351.6 million estimate.
The difference between the early on-chain observations and Bitget’s final estimate is important. Blockchain researchers initially tracked assets moving from a limited number of wallets, while Bitget subsequently assessed the total amount affected across its wallet infrastructure. The exchange has said it identified and flagged the relevant transfer addresses and formally contacted law-enforcement agencies and blockchain security firms as investigators work to reconstruct the full sequence of transactions.
Related: Duelbits Hit by $7M Crypto Hack as Stolen Funds Move Into ETH
Bitget has not publicly established the precise technical mechanism responsible for the breach in its initial security notice. The exchange said it would not speculate about the attack vector while the investigation was continuing and committed to publishing a full incident report covering the root cause and corrective actions. That distinction matters because the existence of unauthorized transfers is confirmed, while the precise method used to gain control over the affected wallet operations remains under investigation.
The latest comments from Chen add another layer to the investigation. She said that IP behavior and on-chain signatures were consistent with techniques associated with DPRK-linked hacker groups and that Bitget had notified relevant authorities. This is an attribution assessment from Bitget rather than a completed public finding by law enforcement, so the claim should be treated as part of the ongoing investigation until independent authorities or investigators establish the responsible actors.
Bitget Says User Funds Remain Covered
Bitget has maintained that customer balances remain protected despite the size of the incident. Its official notice states that the full estimated loss is covered by the exchange’s User Protection Fund, which holds more than $464 million, while Chen additionally said Bitget has more than $1 billion in its own assets outside that fund. Bitget has therefore framed the incident as a platform security loss rather than a shortfall in customer account balances.
The exchange’s immediate response has been to suspend withdrawals while keeping other services operating. Bitget says deposits and trading remained available in its initial incident notice, although a separate update later said its Onchain trading service was temporarily unavailable during the security review. The company has not committed to a specific withdrawal restoration time, saying it will announce the window once security checks are complete.
Chen said Bitget would not provide a withdrawal deadline that it could not guarantee. That approach leaves users waiting for confirmation that the exchange’s affected infrastructure has been secured before normal withdrawals resume. The company has also urged users to follow official communications as the investigation progresses, particularly because major security incidents can create opportunities for phishing attempts and fake recovery offers.
The incident has also prompted Bitget to distinguish its centralized exchange infrastructure from Bitget Wallet. Bitget Wallet said its self-custodial wallet operates on separate infrastructure and that its own security review found no impact from the exchange incident. Because assets in a self-custodial wallet remain under the user’s on-chain control rather than being held within Bitget Exchange’s custodial wallet architecture, the company says the exchange breach did not compromise Bitget Wallet users or their assets.
Related: XRP Healthcare Wallet Hack Drains 267,664 XRP and Millions of XRPH
For Bitget, the next stage will be focused on identifying exactly how the unauthorized transfers were initiated, tracing the affected assets and determining whether any funds can be frozen or recovered. Chen said some foundations on affected networks had already frozen hacker-controlled addresses after Bitget contacted them. The ability to freeze assets varies by blockchain and token, particularly where centralized stablecoins are involved, but coordination between exchanges, foundations, issuers and security firms can potentially limit further movement.
The size and multi-chain nature of the incident make the investigation significant for the wider crypto market. The affected infrastructure included several major networks, while the stolen or unauthorizedly transferred assets ranged from large-cap cryptocurrencies such as ETH and XRP to stablecoins and other altcoins. At the same time, Bitget’s claim that its cold wallets were untouched shows that the incident was concentrated within specific layers of its wallet architecture rather than representing a compromise of every asset held by the exchange.
For now, Bitget users are waiting for two major developments: the restoration of withdrawals and the exchange’s promised full incident report. The latter should provide a clearer explanation of the root cause, the precise wallet infrastructure involved, the final loss calculation and the security measures introduced afterward. Until that report is published, the confirmed facts are that unauthorized transfers affected approximately $351.6 million, withdrawals were suspended, cold wallets remained secure according to Bitget, and the exchange says its protection fund is sufficient to cover the estimated loss.















