A popular cryptocurrency eexchange platform, Bitget has disclosed that approximately $351.6m was lost after hackers gained unauthorised access to part of its wallet infrastructure.
The exchange said its security systems detected unauthorised transfers from some of its hot wallets at 18:31 UTC on Thursday, September 24, prompting it to activate its emergency response protocols.
In an initial security notice signed by Bitget CEO Gracy Chen on Thursday, the exchange said the breach was limited to part of its hot and warm wallet layers, while its cold wallets remained secure.
“Estimated funds affected: approximately $351.6 million,” Bitget said.
The exchange said withdrawals were temporarily suspended as a precaution, while deposits and trading remained operational.
It also assured users that the loss was covered by its User Protection Fund, which it said held more than $464m.
“User funds are safe. The full amount of this loss falls within the coverage of Bitget’s User Protection Fund, which currently holds over $464 million,” Bitget said.
In a subsequent update, Chen disclosed more details about how the attackers moved the funds, saying they had compromised a critical backend system within Bitget’s wallet infrastructure.
“The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out,” she said.
Chen said the investigation had ruled out a compromise of private keys and that further unauthorised transfers had been prevented.
“Private key compromise has been ruled out, this excludes the more severe risk scenarios. Loss containment is confirmed. No further unauthorized transfers are possible,” she said.
However, Bitget said the specific method used to gain access to the backend system remained under investigation, with a full technical report to be released once the findings were confirmed.

