The exchange says attackers manipulated transfer data inside a wallet backend rather than stealing private keys. Withdrawals remain paused while the company investigates and repairs its systems.
Bitget is investigating a security breach that led to the loss of approximately $351.6 million in digital assets. The exchange detected unauthorized movements from some of its hot wallets at 18:31 UTC on September 24. In a subsequent explanation, CEO Gracy Chen said the attackers gained access to a critical system behind the exchange's wallet operations and submitted falsified transfer data through its authorization process.
How the transfers passed through the system
According to Chen, the evidence so far does not point to stolen private keys. Those keys are the cryptographic credentials used to authorize movements of digital assets. Instead, the alleged intrusion targeted a backend component that prepares or handles transaction information before a transfer is approved. This distinction helps explain the reported mechanism, although Bitget has yet to publish a full technical account of how the attackers entered the system.
The immediate security question is how falsified transfer data reached the authorization process.
Incident analysis based on Bitget's public account
The incident extended beyond hot wallets, which stay connected to support day-to-day transactions, into Bitget's warm-wallet layer. Warm wallets sit between frequently used online funds and offline storage. Chen said the exchange's cold wallets were unaffected and that it had stopped any further unauthorized outflows. The company has not yet disclosed the precise method used to compromise the backend.
Withdrawals paused during the review
Bitget has kept deposits and trading available but suspended withdrawals while technical teams review and strengthen the affected systems. Chen did not provide a date for withdrawals to resume, saying the exchange would announce a timeline once it could confirm one.
The company says its User Protection Fund contains more than $464 million and is sufficient to absorb the reported loss. Bitget also says customer account balances remain accurate and assets are protected. These are the exchange's statements; the public has not yet seen the promised technical report explaining the breach in detail.
What the investigation still needs to establish
The central unanswered issue is the path into the wallet backend and the controls that allowed fabricated transaction data to be processed. A complete incident report should clarify the affected systems, the sequence of unauthorized transfers and the changes made before withdrawals reopen. Until then, the distinction between intact private keys and compromised transaction infrastructure describes Bitget's current findings, rather than a final independent assessment.