$351.6 Million Bitget Hack Exposes a New Weak Point in Crypto Exchange Security
Crypto exchange Bitget has suffered one of the largest digital asset security breaches of the year, with attackers moving an estimated $351.6 million after compromising part of the infrastructure behind the platform’s hot and warm wallets.
The incident forced Bitget to temporarily suspend withdrawals while keeping deposits and trading operational, but the scale of the attack is only part of the story. Early findings suggest the attackers did not need to steal the private keys protecting the wallets — instead, they appear to have compromised a critical backend system and manipulated the exchange’s own transaction authorization process.
That distinction could make the Bitget breach particularly significant for the wider crypto industry, shifting attention from protecting wallet keys alone to securing the systems that decide which transactions should be signed and executed.
Suspicious transfers appeared before Bitget confirmed the breach
The first signs of trouble emerged on-chain on September 24, when blockchain researchers began tracking unusually large transfers from addresses associated with Bitget.
Early estimates put the suspicious movements at more than $170 million, but the figure continued to rise as additional transactions across different networks were identified.
Bitget later confirmed that its security systems detected unauthorized transfers at 18:31 UTC on September 24, triggering emergency response procedures within minutes.
The exchange eventually estimated the affected assets at approximately $351.6 million.
Bitget operates a three-tier wallet architecture. According to the company, the breach was contained to portions of its hot and warm wallet layers, while its offline cold wallets remained secure.
Attackers appear to have targeted the machinery behind the wallets
Initial details released following the breach point to a more complex attack than simply obtaining a wallet’s private key.
Bitget CEO Gracy Chen said a private-key compromise had been ruled out and that the attacker instead compromised a critical backend system within the exchange’s wallet infrastructure.
The compromised system was then used to manipulate transaction data and trigger Bitget’s authorization process, allowing funds to be transferred out.
This changes the security question considerably. A private key can remain protected while an attacker targets the infrastructure responsible for telling a wallet what transaction it is supposed to authorize.
Bitget said the breach has since been contained and that further unauthorized transfers from the affected systems are no longer possible, although the precise method used to gain access to the backend infrastructure remains under investigation.
Withdrawals frozen while trading continues
Bitget temporarily halted withdrawals as a precaution while conducting a wider security review.
Deposits and trading remained available, and the exchange said customer account balances continued to display correctly.
Bitget has also identified and flagged addresses linked to the abnormal transfers and brought law enforcement agencies and blockchain security specialists into the investigation.
The company initially said it would publish a detailed incident report covering the root cause and corrective measures following its investigation.
A $464 million fund becomes Bitget’s financial safety net
The immediate financial question is whether the losses will ultimately reach customers.
Bitget says they will not.
Its User Protection Fund held more than $464 million when the incident was disclosed, exceeding the exchange’s initial $351.6 million estimate for affected assets.
The company said the entire estimated loss falls within the fund’s coverage and that customer assets remain protected.
That turns a reserve fund normally presented as an additional layer of customer protection into a real-world test of whether a crypto exchange can absorb a major cyberattack without passing the losses on to its users.
The bigger lesson may be beyond hot wallets
Crypto exchanges have traditionally treated cold storage as one of their strongest defenses, keeping large amounts of digital assets offline while maintaining smaller hot wallets for day-to-day transactions.
The Bitget incident did not invalidate that model — its cold wallets remained protected — but it highlights another potential attack surface.
As exchanges build increasingly automated systems to move assets across blockchains, manage liquidity and authorize transactions at high speed, the backend infrastructure controlling those operations can become as important a security target as the cryptographic keys themselves.
For the crypto industry, that may prove to be the most important consequence of the Bitget breach. The attack was not simply about hundreds of millions of dollars leaving a wallet; it demonstrated how attackers can potentially go after the decision-making infrastructure sitting behind the wallet.
