Bitget’s $351.6m Breach: The Hours After the Alarm

Bitget says $351.6 million left its exchange wallets without authorisation. The uncomfortable question is not merely how the money moved, but how much could still move after the alarm sounded.

The exchange detected suspicious transfers at 18:31 UTC on 24 September, according to its security notice. Withdrawals were temporarily suspended; deposits and trading remained open. Bitget says its cold wallets were untouched and customer balances are protected. Those assertions now face the only test that matters: a documented containment timeline and the eventual restoration of withdrawals.

What Bitget has actually confirmed

The $351.6 million is Bitget’s preliminary estimate of affected funds, not an independently audited final loss. The company says only part of its hot- and warm-wallet infrastructure was affected, an emergency team was activated within minutes and suspicious addresses were flagged. It has notified authorities and on-chain security firms, but has not identified the attack vector.

Chief executive Gracy Chen’s initial statement put the reported User Protection Fund above $464 million. On those company figures, the incident equals about 75.8% of that stated fund floor, leaving a theoretical buffer greater than $112.4 million. This is arithmetic, not proof that assets are immediately available, legally earmarked for every affected customer or sufficient for any further losses.

Comparison of Bitget's $351.6 million estimated affected funds and its stated protection fund of more than $464 million
Company-reported figures; the remaining difference is a simple lower-bound calculation, not verified available liquidity. Source: Bitget security notice, 24 September 2026.

The distinction matters. A protection fund is not the same thing as a real-time reconciliation of every customer liability, and a proof-of-reserves snapshot is not an incident-response report. Bitget’s promise that ‘user funds are safe’ deserves to be tested against withdrawals, asset movements and a full account of what the fund actually covers.

The clock after the warning

Forbes examined labelled on-chain wallets and reported a small transfer at 18:31:11 UTC, followed by larger movements at 18:58:59 and shortly after 19:01. It also identified a further 223.2 ETH transfer at 21:23:11. Forbes says Chen’s public notice appeared at about 21:30 UTC. Those are independently reported observations of labelled addresses, not a complete forensic reconstruction of the incident.

If the attribution and timings stand, a transfer remained visible almost two hours and 52 minutes after the exchange’s stated detection time. That does not prove its responders did nothing: shutting down wallet infrastructure across multiple chains without compounding damage is complex. It does, however, put containment — not just detection — at the centre of the story.

On-chain visibility also has limits. Bitcoin Magazine reported that blockchain researchers initially spotted suspicious movement before Bitget’s announcement, while Bitget’s own $351.6 million estimate spans infrastructure and chains beyond any one public dashboard. Neither a single wallet label nor a dramatic transaction screenshot can establish the final loss. The company needs to publish the affected address set, network-by-network outflows and a reconciliation methodology.

A safety net is not a substitute for access

The exchange describes a three-tier architecture: cold wallets, warm wallets and hot wallets. Its assurance that cold storage was untouched narrows the stated scope of compromise but does not answer whether signing permissions, deployment systems or operational controls failed. Bitget explicitly says it will not speculate on the attack vector before its investigation concludes. Others should resist doing so as well.

What is already plain is the asymmetry facing customers. Trading can continue while withdrawals are paused, but an account balance on a screen is not the same as an asset that can leave the platform. The pause may be prudent security practice; it is also the point at which operational trust becomes measurable. Publishing a restart plan, with any staged limits and exceptions, would be more useful than another general reassurance.

Timeline showing Bitget's stated 18:31 UTC detection and subsequently reported on-chain movements up to 21:23 UTC
Detection from Bitget; wallet movements and public-notice timing reported by Forbes. Address attribution and the total loss remain subject to investigation.

Forbes also reported that the attacker rapidly converted some potentially freezable assets into ether. That interpretation rests on its analysis of specific transactions and should not be mistaken for a confirmed account of the intruder’s identity or strategy. The broader question is whether exchange controls can quarantine compromised signing routes fast enough when transfers traverse several networks.

The evidence the next update must provide

Bitget says it will publish further investigation updates. A serious update should state when each affected wallet was disabled; separate detected, attempted, completed and recovered transfers; disclose which networks and assets were involved; and explain how the protection fund would be deployed. It should also say when customers can withdraw again and whether any additional screening will slow that process.

There is no reason to treat a provisional $351.6 million figure as either a final audit or an invitation to panic. Nor should the reported fund balance end the scrutiny. The company has made three testable claims: the breach was contained to portions of hot and warm storage, the fund covers the loss, and customer assets remain protected. The public evidence for each must catch up with the speed of the money.

This story is developing. The figures, wallet attribution and withdrawal status may change as Bitget releases verified updates.

This article is for information purposes only and should not be considered trading or investment advice. Nothing herein shall be construed as financial, legal, or tax advice. Bullish Times is a marketing agency committed to providing corporate-grade press coverage and shall not be liable for any loss or damage arising from reliance on this information. Readers should perform their own research and due diligence before engaging in any financial activities.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top