en
Back to the list

Bitget Hack Of $351.6 Million Triggers A Withdrawal Freeze

source-logo  forbes.com 6 h
image

Bitget confirmed on Thursday night that attackers took roughly $351.6 million out of its hot wallets, and suspended customer withdrawals while it investigates. Chief executive Gracy Chen put the notice out at 21:30 UTC. “At 18:31 UTC on September 24, 2026, Bitget’s security systems detected unauthorized transfers from some of our hot wallets,” she wrote. “Our security team activated emergency response protocols immediately.”

The blockchain agrees about 18:31. It disagrees about what happened next.

The three hours after detection

At 18:31:11 UTC, a wallet labelled “Bitget 6” on Etherscan, Arbiscan and BscScan sent 0.84 ether to an address created that day. That is the test send that precedes a large transfer, and it is the first movement of the breach. It lands in the same minute Bitget says its systems flagged the intrusion.

The money went after it. At 18:58:59 the same wallet sent 34,751,168 $USDT. At 19:01:20, on Arbitrum, it sent 19,668,851 USDT0. At 19:01:23, 12,852,046 $USDC. At 19:01:35, 7,130.86 ether. A second wallet, labelled “Bitget 35,” added 15,362 ether in three transfers. Another 223.2 ether followed at 21:23:11.

That last transfer is two hours and 52 minutes after the detection timestamp in Bitget’s own notice, and seven minutes before the notice was published. Across Ethereum and Arbitrum alone, $133.4 million left Bitget-labelled wallets, plus 3,000 Tether Gold tokens worth $12.8 million from a third address. The rest of the $351.6 million moved on other chains.

None of this means the response was slow in any ordinary sense. An exchange runs hot wallets on a dozen networks, and shutting each one without stranding customer withdrawals is not a single switch. Chen says cold storage was never touched. But the gap between detection and containment is measured in hours here, and it is where the money went.

The attacker sold everything that can be frozen

The choice of assets is the clearest signal of intent. Tether can freeze $USDT. Circle can freeze $USDC. Tether can freeze its gold token. Ether cannot be frozen by anyone.

Within six minutes of receiving them, the attacker pushed all three into 0x7c96279E, a router contract that fanned them across Uniswap V3 pools and the Uniswap V4 PoolManager and returned ether. DCF GOD, a pseudonymous analyst with 105,000 followers who spotted the Arbitrum leg before Bitget said anything, noted the buyer was “paying up to +5% over spot” and pushed one pool to $2,870 against a spot price near $2,688. “which makes no sense if someone was just trying to buy eth,” he wrote. It makes sense if the seller is racing an issuer’s freeze function.

What is left is ether, sitting in three wallets that had never transacted before: 10,000 at 20:13, 10,000 at 20:19, and 4,590 more at 21:41:11. That last one moved ten minutes after Chen’s notice went up, and a minute after Bitget’s own account told customers it had “identified and flagged the relevant transfer addresses.”

What Bitget says

“User funds are safe,” Chen wrote. “The full amount of this loss falls within the coverage of Bitget’s User Protection Fund, which currently holds over $464 million.” She described a three-tier wallet architecture in which “the breach contained only a portion of the hot wallet and warm wallet layers,” said deposits and trading are running normally, and promised a full incident report within 24 hours. “We will not speculate on the attack vector until the investigation is complete.”

That last line is the one that matters for anyone else running an exchange. Breaches of this shape rarely involve breaking cryptography. “Those are off-chain hacks that led to on-chain loss of funds,” Ido Sofer, founder and CEO of key management firm Sodot, said on the On The Margin podcast, describing the pattern behind the Bybit theft and its successors. “Developer credentials, deployment keys, API keys that are being stolen. And that provided access to moving funds on chain.” His blunter version: “There will be hacks. The question is, is it gonna be in your company or not?”

A $464 million fund against a $351.6 million loss is a thin but real cushion, and Bitget has published proof-of-reserves attestations for 45 consecutive months, most recently a 122% reserve ratio for August. The test of all of it is whether withdrawals reopen.

A second scam is already running

One warning for anyone following the addresses. Within hours, spoofed tokens began mimicking the attacker’s transfers: fake contracts named “ETH”, “$USDC” and “$USDT”, some spelled with invisible Unicode characters, broadcasting the same amounts to lookalike addresses that differ from the real ones only in the middle. Fourteen had appeared against this one wallet by 22:00. Anyone copying an address out of a block explorer right now can pick up a poisoned one.

This is the largest exchange loss since the Bybit breach, and it follows the $130 million Coldcard theft that reopened the argument over who should hold bitcoin’s keys and the $137 million November spree that rebuilt DeFi’s yield layer. As with the fresh wallets that made $1.2 million on Polymarket before the Iran airstrikes, the chain recorded it all in public while everyone argued about what it meant.

“Bitget has navigated multiple market cycles. We will not run from this,” Chen wrote. The incident report is due within a day, and 24,590 ether is sitting in three wallets waiting to move.

forbes.com