Newsroom
25 September, 2026 / News / AI / Tags: bitget, warm, wallets, cold, withdrawals

Bitget says unauthorized transfers from a limited portion of its hot and warm wallets affected roughly $352 million, with cold storage fully intact and the platform's protection fund covering the loss
On September 24, 2026, blockchain monitoring tools spotted unusual transfers leaving wallets labeled with Bitget's identity. Roughly $183 million in assets, including Ether, USDT, USDC, AVAX, BNB and other tokens, moved to a newly created address within about an hour.
The movements began with a fresh wallet that received $19.67 million in USDT0 and used it to acquire 7,111 ETH on Arbitrum in just six minutes. The trade executed through decentralized swap services, with fees reflecting a premium for speed. Additional outflows followed from other labeled addresses, spanning multiple chains.
Early alerts from on-chain analysts noted the activity but captured only part of the full scale. Bitget's own analysis later aligned with a reported total of approximately $352 million affected across networks including Ethereum, the XRP Ledger, Avalanche, BNB Smart Chain and Arbitrum.
Bitget activated emergency protocols once its security systems detected the transfers at 18:31 UTC. The exchange confirmed the incident involved only select hot and warm wallet layers, with cold wallets remaining completely secure.
CEO Gracy Chen stated that user funds stayed intact and that deposits and spot trading continued without interruption. Withdrawals were temporarily suspended across all asset-network combinations to allow a full investigation, though the exchange expected them to resume within hours or days.
The platform flagged the outgoing addresses, notified law enforcement and reached out to on-chain security firms. It also committed to releasing a complete incident report, including root-cause details and corrective steps, within 24 hours.
Bitget has long maintained a dedicated user protection fund designed specifically to address losses from hacks, thefts and similar events. The fund now exceeds $464 million, providing coverage beyond the reported incident.
This incident adds to a series of security challenges facing centralized exchanges. In February 2025, rival platform Bybit reported a $1.4 billion theft linked to a signing screen spoof, the largest on record at the time. Across the broader industry, annual losses from exchange and protocol hacks reached $2.72 billion in the previous year.
The distinction between hot wallets—used for immediate trading and withdrawals—and cold wallets—kept offline—remained central to Bitget's explanation. Only the online layers were affected, leaving the majority of reserves protected.
With deposits and trading fully operational, the exchange stayed functional for active users even as withdrawals faced restrictions. The temporary halt applied uniformly across 4,930 asset-network entries listed in its public API, covering every combination rather than individual tokens.
Earlier on-chain reports aligned closely with the final figure, though the full impact extended beyond initial Ethereum-focused activity. Bitget noted that account balances for users remained accurate, reinforcing that platform funds were not compromised.
The swift response—detecting issues within minutes and suspending outflows while preserving trading—limited further exposure for most participants. The exchange plans hourly updates during the review period to keep stakeholders informed.









