Crypto exchange Bitget temporarily suspended withdrawals after detecting unauthorized transfers from some of its wallets on September 24. The company estimates that approximately $351.6 million in assets were affected.
In a security notice, CEO Gracy Chen said Bitget's systems detected the transfers at 18:31 UTC and activated emergency procedures. She described the incident as affecting portions of the exchange's hot- and warm-wallet infrastructure, while saying its cold wallets remained secure.
Withdrawals paused while the cause is investigated
Bitget said deposits and trading continued to operate, but withdrawals were paused as a precaution during a security review. The exchange said it identified and flagged the relevant transfer addresses and brought in law enforcement and on-chain security firms.
The size of the suspected loss changed as researchers traced more activity. Reporting on the incident says early estimates of suspicious transfers rose from about $174 million to roughly $183 million before Chen announced Bitget's $351.6 million figure. That remains the company's estimate rather than a completed forensic accounting.
Chen said customer account balances remained accurate and that Bitget's User Protection Fund, which she valued at more than $464 million, would cover the full estimated loss. Those assurances come from the exchange; Bitget has not yet published the promised incident report or independent evidence establishing the final loss and recovery process.
The attack vector is still unknown
Bitget has not disclosed how the wallets were compromised. Chen said the company would not speculate while the investigation continued and promised hourly updates plus a report covering the root cause and corrective actions within 24 hours.
That report will be the first opportunity to compare the exchange's initial account with a fuller technical timeline, including which wallet controls failed, how the transfers were authorized and when withdrawals can safely resume.