-
Bitget reported unauthorized transfers worth about $351.6 million from parts of its hot and warm wallet infrastructure.
-
A track on the attacker showed they converted much of the stolen EVM-based assets into about 67,982 ETH.
-
Bitget suspended withdrawals during its investigation and says its cold wallets and User Protection Fund remain secure.
Bitget cryptocurrency exchange has revealed unauthorized transactions, nearly $351.6 million, from some of the funds on its wallet platform. According to on-chain data, the unauthorized person has swapped many crypto assets belonging to the EVM platform to Ethereum.
Lookonchain noted that the unauthorized person swapped approximately 67,982 ETH, equivalent to around $183 million. Currently, Bitget has halted all withdrawals from its portals to streamline the investigation of the situation.
Bitget Detects Unauthorized Wallet Transfers
The security systems of Bitget detected unusual transfers at 18:31 UTC on September 24. The exchange quickly activated its emergency response process after identifying the activity. The company said the incident affected part of its hot and warm wallet layers. Its cold wallets remained secure, according to the initial security notice.
Bitget uses a three-tier wallet structure for asset management. Hot wallets connect to online systems, while warm wallets provide another layer between online operations and cold storage. The firm has not revealed the entire method of the attack.
In any case, Bitget stated that it has excluded the theory about the violation of private keys. The exchange identified and flagged the addresses that took part in the dubious transfers, using its approach. It also reported to law enforcement authorities and several security companies about the situation.
At the same time, Bitget has suspended withdrawals temporarily. Deposits and trading transactions are still available even though the company is busy with security checks. It said that it was planning to share a comprehensive report on the incidents. That report will include the discovery of the cause and the corrective steps it will take after the investigation.
Attacker Converts Stolen Assets into ETH
The movement of the stolen funds has added another layer to the incident. Lookonchain tracked the attacker as the wallet moved assets from several EVM-compatible networks. The attacker swapped a large portion of those assets into ETH. The resulting balance reached about 67,982 ETH, with a reported value near $183 million.
That conversion changes the composition of the stolen funds. Rather than using many different currencies, the criminal chooses to use one dominant crypto coin for a large part of the value. On-chain analysts can see this happening in the public blockchain, since the blockchain reveals wallet transfers. Investigators can therefore monitor the addresses associated with the breach and track subsequent transactions.
Nonetheless, tracking the funds will not lead to identification of the criminal or group. While the blockchain shows the movement of the assets, it does not necessarily give information on the owner of the receiving wallet. The stolen assets reportedly included cryptocurrencies from several networks. XRP formed one of the largest portions of the reported loss, while ETH and stablecoins also featured among the affected assets.
The rapid conversion also creates challenges for investigators. Attackers can move assets between networks and swap tokens through decentralized exchanges. However, each transaction leaves a public record. Security companies can use those records to flag addresses, follow fund movements, and help exchanges or authorities identify suspicious transfers.
Bitget Says User Funds Remain Protected
Bitget has stressed that the incident did not affect its entire wallet system. The company said its cold wallets remain secure and that user funds remain protected. The exchange also pointed to its User Protection Fund. Bitget says the fund currently holds more than $464 million, which exceeds the estimated $351.6 million loss.
That fund could cover the reported loss under the current protection arrangements of Bitget. The company has also said customer account balances remain accurate. Still, the temporary withdrawal suspension affects users who need to move assets away from the exchange. Bitget says it will restore withdrawals after the security review reaches a safe stage.
The company has kept deposits and trading services available. It later issued a separate notice about some Onchain trading services, which it temporarily suspended during the wider security review. Bitget has also said its self-custodial Bitget Wallet operates separately from the affected exchange infrastructure. Reports indicate that the wallet service did not suffer the same incident.
The differences between these cases are important, given that the breach of certain hot wallets does not mean that all assets on a particular exchange are in danger. The losses, however, indicate that the incident is important for the broader crypto industry. Exchanges work with a large number of digital assets within systems and must keep the balance between safety and speed of transactions.
Investigation Continues as Fund Movements Remain Under Watch
Bitget has not yet published its complete technical explanation for the breach. The company has said investigators need more time before they can confirm the exact attack vector. That approach leaves several questions open. Investigators still need to establish how the attacker entered the affected infrastructure and how the system authorized the transfers.
Bitget has ruled out private-key compromise in its preliminary assessment. However, the exchange has not released the complete evidence behind that conclusion. The investigation also involves external security firms and law enforcement agencies.
Law enforcement agencies have also taken part in broader efforts to track and seize assets linked to cybercrime, including the INTERPOL operation seizing $1.7 million in cybercrime assets across the MENA region. Their work can help trace the stolen assets and examine the systems involved.
On-chain monitoring will remain important during that process. Investigators can watch the wallets of the attacker for further swaps, transfers, or attempts to move funds through other networks.
For now, Bitget continues its security review while the cryptocurrency industry tracks the stolen funds. The reported conversion of 67,982 ETH gives investigators a clear pool of assets to monitor.
The incident also highlights the risks surrounding hot and warm wallet infrastructure. Exchanges must protect online systems while allowing users to trade and move assets quickly. Bitget says its emergency response remains active. The company expects to provide further updates as investigators establish the root cause and complete the security assessment.