Cryptocurrency exchange Bitget reported a security breach involving approximately USD 351.6 million in assets, after its systems detected unauthorized transfers from a limited number of hot wallets on September 24, 2026. The exchange said the incident was detected at 18:31 UTC and that its security team moved quickly to contain the activity.
Bitget said the breach affected parts of its hot and warm wallet infrastructure, while its cold wallets remained secure. The company also said customer account balances remain accurate and that the incident is covered by its User Protection Fund, which it said holds more than USD 464 million.
Bitget CEO Gracy Chen said the incident did not involve a compromise of private keys. Instead, the attacker gained access to a critical backend system within the exchange’s wallet infrastructure, manipulated transaction information and triggered the authorization process used to move funds.
The specific method used to gain access to that backend system remains under investigation. Bitget has said it will publish a detailed incident report covering the root cause and corrective measures once the investigation is complete.
The company has also identified and flagged addresses linked to the suspicious transfers and notified law enforcement agencies and blockchain security firms.
As a precaution, Bitget has temporarily suspended withdrawals while its technical teams carry out a security review and strengthen affected systems. Deposits and trading remain operational, according to the exchange.
Bitget has not provided a fixed time for withdrawals to resume. The company said services will be restored after the security review confirms that it is safe to do so, rather than committing to a timetable before the checks are completed.
The exchange said no further unauthorized transfers were possible and that the incident had been contained.
Also Read: UAE Faces 800,000 Daily Cyberattacks as AI Accelerates Hacking Threats
The incident has drawn attention given the size of the affected assets and the way the attacker allegedly bypassed the normal transaction authorization process. Early blockchain monitoring had identified a smaller amount before Bitget revised the figure to approximately USD 351.6 million as additional transfers were identified.
Bitget said it will continue providing updates while the investigation proceeds. The company is working with law enforcement and on-chain security specialists to trace the affected funds and establish exactly how the backend system was compromised.