Bitget Hot Wallet Incident Involves Approximately $351.6 Million; Cold Wallets and Most Platform Assets Reportedly Unaffected

更新于 2026年9月25日

Bitget Hot Wallet Incident Involves Approximately $351.6 Million; Cold Wallets and Most Platform Assets Reportedly Unaffected

A security incident involving several Bitget hot wallets has become one of the most closely watched events in the cryptocurrency market. The exchange said that abnormal transfers were detected during the early hours of September 25, with the affected assets initially estimated at approximately $351.6 million.

Bitget has stated that its cold wallets and the overwhelming majority of platform assets remain intact. The exchange also said that user account balances are accurate and that the reported loss falls within the coverage of its user protection fund, which currently exceeds $464 million.

The investigation is still underway. Until the technical cause is confirmed, the incident should be understood as an evolving security event rather than a finalized post-mortem.

What Happened Inside Bitget’s Wallet Infrastructure?

Bitget reported that its security monitoring system identified unusual transfers from a number of hot wallets at approximately 2:31 a.m. on September 25. The platform activated its emergency response process within minutes and formed a dedicated incident response team.

A hot wallet is an online wallet used to support routine deposits, withdrawals, and operational liquidity. Because it remains connected to the internet or to online signing infrastructure, it is generally more exposed to unauthorized access than an offline or isolated cold wallet.

Based on the exchange’s public updates, the incident involved only part of its hot wallet environment. Bitget said that:

  • Its cold wallet assets were not affected.
  • Most platform assets remained secure.
  • User balances remained accurate.
  • The estimated loss is fully covered by the user protection fund.
  • Withdrawals were temporarily suspended as a precaution.
  • Deposits and trading continued to operate normally.
  • Abnormal addresses were identified, flagged, and reported to relevant security and law enforcement organizations.

Bitget has also said that it plans to publish regular progress updates and issue a more complete incident report containing a root-cause analysis and remediation plan. Until that report is released, the company has stated that it will not speculate about the exact attack method.

Readers should refer to Bitget’s official news and announcement channels for the latest operational updates.

On-Chain Activity Shows a Complex Flow of Assets

Blockchain monitoring reportedly identified transfers from multiple addresses associated with Bitget. The assets involved included ETH, BNB, AVAX, USDT0, USDC, USDT, and XAUT.

The funds were initially consolidated into a principal address before being distributed across at least six additional addresses. This type of movement can make attribution more difficult, particularly when the attacker uses multiple chains, decentralized exchanges, and newly created wallets.

On-chain observers also identified a newly created address that received approximately 19.67 million USDT0 from a Bitget hot wallet. Within roughly six minutes, the address used UniswapX and 1inch Fusion to purchase approximately 7,111 ETH.

Some of the reported executions were around 5% above the prevailing spot price. Several factors could contribute to this type of outcome, including intense time pressure, fragmented liquidity, automated routing, and the attacker’s willingness to accept poor execution in exchange for rapidly converting assets.

Blockchain explorers such as Etherscan and BscScan can provide a public record of transaction movement. However, an address label alone does not establish who controls a wallet or prove the precise mechanism behind a transfer. Attribution requires additional evidence from exchange records, signing infrastructure, access logs, and forensic analysis.

Why Early Estimates May Differ

Earlier monitoring reports placed the value of the transferred assets in the range of approximately $180 million to $183 million, while Bitget’s preliminary internal assessment later cited approximately $351.6 million.

A difference between early on-chain estimates and an exchange’s internal estimate does not necessarily indicate contradictory reporting. The figures may reflect different asset groups, valuation times, wallet categories, or later-discovered transactions. Prices can also move significantly during a fast-moving incident, especially when large orders are executed through decentralized markets.

The final amount will depend on several questions:

  1. Which transactions are confirmed to be unauthorized?
  2. Which wallets were directly affected?
  3. How were assets valued at the time of the incident?
  4. Were any assets recovered, frozen, or redirected?
  5. Did the incident involve only private-key compromise, or were additional systems involved?

A formal incident report should clarify these points.

Why the Cold Wallet Statement Matters

The distinction between hot and cold wallets is central to this event.

Hot wallets are designed for speed and operational convenience. Exchanges need them to process customer activity, maintain liquidity, and support trading infrastructure. Cold wallets, by contrast, are typically kept offline or behind additional procedural and technical controls. They are commonly used to store a larger portion of long-term reserves.

If Bitget’s statement is confirmed by subsequent audits and technical findings, the separation between its hot wallet operations and cold storage helped limit the scope of the incident. This illustrates an important principle of crypto custody: security is not based on a single protective measure. It depends on layered controls, including:

  • Segregation of hot and cold assets
  • Transaction limits and withdrawal policies
  • Multi-party approval processes
  • Hardware-backed key protection
  • Address allowlisting and risk screening
  • Real-time anomaly detection
  • Emergency suspension procedures
  • Independent audits and transparent proof-of-reserves practices

At the same time, keeping the majority of assets in cold storage does not eliminate all risk. Operational hot wallets remain attractive targets because they are connected to systems that must process transactions quickly. Exchanges therefore need to balance liquidity requirements with strict limits on the amount that can be accessed online.

What the Temporary Withdrawal Suspension Means

Bitget’s decision to pause withdrawals while keeping deposits and trading available reflects a common containment strategy during a suspected wallet compromise.

Stopping withdrawals can help prevent additional unauthorized outflows while the security team:

  • Reviews wallet permissions and signing infrastructure
  • Compares internal records with on-chain activity
  • Identifies potentially compromised addresses
  • Coordinates with blockchain analytics providers
  • Notifies law enforcement and other platforms
  • Checks whether suspicious funds are moving through centralized or decentralized venues

For users, however, the difference between “trading available” and “withdrawals available” is important. Assets shown in an exchange account are not immediately equivalent to assets held under the user’s exclusive control. During a withdrawal suspension, users should avoid making rushed decisions, sharing recovery phrases, or responding to unsolicited messages claiming to offer refunds or emergency withdrawals.

The Financial Action Task Force’s guidance on virtual assets also highlights the importance of risk-based controls, transaction monitoring, and cooperation between virtual asset service providers and relevant authorities.

Practical Security Lessons for Crypto Users

This incident offers several lessons for both retail and institutional participants in the digital asset market.

1. Exchange custody and self-custody are different risk models

Funds held on an exchange are managed through the exchange’s wallet architecture, access controls, and internal policies. In self-custody, the user controls the private keys but also assumes responsibility for protecting them.

Neither model is risk-free. The key difference is who controls transaction authorization and who is responsible for responding to a compromise.

2. Avoid keeping all assets in one location

Users with significant holdings may consider separating funds according to purpose:

  • Trading liquidity in a limited hot wallet
  • Long-term holdings in a secure cold-storage setup
  • A small operational wallet for decentralized applications
  • Separate accounts or devices for higher-risk activities

This approach can reduce the impact of a single compromised environment.

3. Verify every transaction before signing

Malicious contracts, phishing websites, and misleading token approvals can cause users to authorize transfers without fully understanding the transaction. Users should verify the destination address, network, asset, and transaction details before approving anything.

For wallet users, Ethereum’s security guidance provides a useful overview of phishing, private-key protection, and transaction safety.

4. Treat recovery phrases as the highest-value secret

A recovery phrase should never be entered into a website, shared with support personnel, uploaded to cloud storage, or photographed. Anyone who obtains it may be able to control the associated assets.

A hardware wallet can reduce exposure by keeping private keys isolated from internet-connected devices. For users who want to separate long-term holdings from exchange and application activity, OneKey offers hardware-based key storage and on-device transaction confirmation. The most important benefit in this context is not simply the device itself, but the ability to keep signing authority away from an exchange’s online wallet infrastructure and review transaction details before approval.

What to Watch for Next

The most important developments will be technical rather than speculative. Users and market participants should monitor:

  • Bitget’s complete incident report
  • The confirmed list of affected wallet addresses
  • Any evidence of private-key or signing-system compromise
  • The status of the protection fund and reimbursement policy
  • Whether withdrawals resume in stages
  • Asset freezes or recovery efforts by other platforms
  • Independent security assessments and proof-of-reserves updates
  • Changes to Bitget’s wallet architecture and withdrawal controls

Until the root cause is published, it would be premature to conclude whether the incident resulted from a private-key leak, compromised infrastructure, access-control failure, insider activity, or another attack vector.

The broader lesson is clear: transparency, wallet segregation, rapid containment, and verifiable recovery procedures are essential components of modern crypto security. As blockchain activity becomes more interconnected across exchanges, bridges, decentralized exchanges, and automated trading systems, both platforms and users must assume that a single compromised hot wallet can create rapid and complex on-chain consequences.

使用 OneKey 保护您的加密之旅

View details for 选购 OneKey选购 OneKey

选购 OneKey

全球最先进的硬件钱包。

View details for 下载应用程序下载应用程序

下载应用程序

只需邮箱, 即可快速开始全球资产交易。

View details for OneKey SifuOneKey Sifu

OneKey Sifu

即刻咨询,扫除疑虑。