Crypto Exchange Bitget Restricts Withdrawals Following $352 Million Security Breach
Major centralized cryptocurrency platform Bitget has temporarily halted customer withdrawals after detecting approximately $351.6 million in unauthorized transfers from its digital asset wallets. The incident, which unfolded late September, stands as one of the most substantial centralized exchange exploits of 2026, injecting renewed urgency into ongoing discussions surrounding digital asset security and institutional trust.
Chief Executive Gracy Chen addressed the security lapse via social media channels shortly after the breach was discovered. Chen assured customers that user funds remain secure and that the entirety of the financial loss falls within the coverage parameters of the company’s User Protection Fund. According to corporate disclosures, this dedicated reserve currently holds slightly more than $464 million, effectively matching the scale of the exploit.
Established in 2018 and registered in the Seychelles, Bitget expanded its global footprint rapidly following the 2022 collapse of FTX, as traders increasingly migrated toward surviving centralized trading venues. The platform currently claims a user base of 120 million registered accounts worldwide. However, the sheer volume of the recent exploit has triggered sharp warnings from market observers regarding the vulnerability of modern digital asset infrastructure.
Esme Pau, head of capital markets and policy at blockchain security firm CertiK, characterized the scale of the drain—which wiped out roughly three-quarters of the exchange’s protective reserve—as extending far beyond a routine security lapse. Pau described the incident as a critical crisis event and a severe wake-up call for the broader digital assets industry.
Blockchain analytics platform Lookonchain reported that the perpetrators rapidly swapped roughly $183 million of the stolen assets into Ether tokens following the initial transfer. In response to the breach, Bitget leadership outlined the structural layout of the company’s storage mechanisms, noting that the organization relies on a three-tier wallet architecture. Chen stated that the unauthorized activity was strictly confined to portions of the hot-wallet and warm-wallet layers, while offline cold storage systems remained entirely uncompromised.
While deposits and regular market trading activities have remained fully operational, withdrawal capabilities were paused as an immediate precautionary measure. Company representatives indicated that these functions would remain offline until a comprehensive security review reached completion. Furthermore, management committed to publishing a full incident report within 24 hours, detailing the root cause analysis and outlining necessary corrective actions.
Providing preliminary insight into the mechanics of the attack, Chen stated that perpetrators compromised a critical backend system and subsequently leveraged it to spoof transaction data. During a livestream broadcast on social media, Chen noted that the organization suspects state-backed involvement originating from North Korea. The stolen digital holdings span multiple major tokens, including Ether, XRP, BNB, AVAX, USDT, and USDC. In response, several foundational networks associated with the affected chains took steps to freeze the hackers’ designated wallet addresses to restrict the movement of funds.
Industry experts argue that the incident carries broader ramifications for market confidence. Aneirin Flynn, chief executive of cybersecurity technology firm FailSafe, noted that the breach effectively shatters the perception that major exchanges have completely mastered hot-wallet security. Flynn emphasized that even though corporate reserves adequately cover the financial deficit, an intrusion of this magnitude inflicts measurable damage on institutional trust in underlying crypto infrastructure.
Source: Insurance Journal