The cryptocurrency exchange Bitget disclosed that attackers accessed a subset of its hot-wallet infrastructure, moving an estimated $351.6 million in user assets. In response, the platform has temporarily blocked all withdrawal activity while it investigates the incident.

Scope of the breach

Monitoring tools flagged irregular activity at 18:31 UTC on Thursday, leading the exchange to isolate the compromised wallets. The intrusion was limited to certain hot and warm wallets; the cold-storage vaults that hold the majority of user funds were not affected. Early blockchain analysis captured a smaller loss figure, but the exchange later clarified that the attack extended beyond the Ethereum transactions initially observed.

The compromised assets span several major tokens, including Ether (ETH), XRP, USDT, USDC, Avalanche (AVAX), Binance Coin (BNB) and a USDT variant on Arbitrum. Correspondingly, the affected blockchain networks are Ethereum, the XRP Ledger, Avalanche, BNB Smart Chain and Arbitrum, with Ethereum accounting for the bulk of the stolen value.

Immediate response

Bitget’s security team activated its emergency protocols the moment the breach was detected. The company has frozen withdrawals to prevent further loss and is working with on-chain security specialists and law-enforcement agencies to trace the flagged addresses. According to the exchange’s leadership, the suspension is expected to be lifted within a matter of hours or days once safeguards are verified.

Impact on users and assets

Despite the theft, Bitget assures that user account balances displayed on the platform remain correct. Deposits and trading functions continue without interruption. The exchange’s User Protection Fund, which holds over $464 million, is sufficient to reimburse the affected customers in full.

CEO Gracy Chen indicated that the fund will cover the entire loss and that the company will provide hourly status updates. A comprehensive incident report, including a root-cause analysis and corrective measures, is slated for release within 24 hours.

Ongoing investigation and protection measures

The exchange has already marked the wallets involved in the unauthorized transfers and shared the information with relevant authorities. Bitget is also collaborating with external security firms to perform a thorough review of its hot-wallet architecture and to reinforce its defenses against similar attacks.

Why it matters

The episode underscores the persistent risk that centralized exchanges face from sophisticated attackers targeting hot-wallet pools, which are inherently more exposed than cold-storage reserves. Bitget’s swift containment and the existence of a sizable protection fund mitigate immediate financial damage for users, yet the incident may prompt broader industry discussions on best practices for wallet segregation, real-time monitoring and user compensation mechanisms. As regulatory scrutiny of crypto custodial services intensifies, exchanges will likely need to demonstrate robust risk-management frameworks to retain user confidence and comply with emerging oversight.