Bitget disclosed that a security incident on Sept. 24 resulted in the unauthorized transfer of roughly $387.5 million to attacker-controlled addresses, while the exchange kept deposits and trading active but halted withdrawals.
Scope of the breach
The exchange first reported the loss at about $351.6 million, noting that the attackers accessed portions of its hot and warm wallet layers. A follow-up update expanded the figure to $387.5 million after accounting for Zcash and TRON movements. Cold storage remained untouched, and Bitget said it had identified and patched the vulnerability with assistance from Mandiant and SlowMist.
Sygnum’s Protect service as a backstop
On the same day, Swiss bank Sygnum announced that Bitget’s institutional clients could trade on the platform while keeping their collateral in the bank’s custody rather than in Bitget’s wallets. The service, called Protect, requires clients to onboard with Sygnum, sign a contractual framework, open a dedicated portfolio and pledge assets before receiving exchange margin.
The bank lists Bitcoin, Ethereum, various stablecoins and US Treasuries among the eligible assets. Once pledged, the collateral sits in segregated accounts that are bankruptcy-remote under Swiss banking law, meaning it is intended to stay outside Bitget’s estate should the exchange encounter financial distress.
Operational implications for traders
Although the pledged assets are held off-exchange, trading on Bitget still depends on the platform’s order-matching, margin and settlement mechanisms. A mirrored trading balance does not give users immediate access to withdraw the underlying collateral, and the public materials do not clarify how quickly pledged assets can be released if Bitget’s withdrawal function stays disabled.
For ordinary Bitget users, the breach left their on-exchange balances exposed. The exchange pointed to its User Protection Fund, valued at over $464 million in BTC terms, and said the loss fell within the fund’s coverage. Claims will be assessed on a case-by-case basis, but the exact amount frozen or recovered has not been disclosed.
Open questions
Sygnum’s announcement does not reveal how many Bitget clients have actually moved collateral to the bank, nor whether any of the assets held at Sygnum were implicated in the hack. The terms governing the release of pledged assets during an exchange outage also remain opaque, leaving institutional traders to rely on the bank’s legal protections while still being subject to Bitget’s operational status.
Why it matters
The incident highlights the limits of off-exchange custody solutions: while segregated collateral can shield assets from a wallet breach and from an exchange’s insolvency, it does not eliminate dependence on the exchange’s trading infrastructure. For institutional participants, the option to keep margin at a regulated Swiss bank provides an additional layer of protection, but the effectiveness of such arrangements hinges on clear contractual terms and the ability to retrieve assets promptly when an exchange’s services are disrupted.




