The-Onchain-Take

Bitget Hit by $351M Hack, Withdrawals Frozen as Probe Begins

Bitget Hit by $351M Hack, Withdrawals Frozen as Probe Begins

$351.6 Million Spoofed, Not Stolen

 How Bitget Got Hit

I had a small balance sitting on Bitget when the alerts started hitting my feed Thursday evening. Nothing large, the kind of amount you leave on an exchange out of laziness rather than strategy. Watching the number climb in real time, from an initial $170 million estimate to a confirmed $351.6 million, was the kind of thing that makes you open your own exchange app and just stare at the balance for a minute.

Bitget's systems flagged unauthorized transfers at 18:31 UTC on September 24. What started as scattered on-chain reports of $170 to $183 million moving out of Bitget-labeled wallets turned into a confirmed loss of $351.6 million by the time CEO Gracy Chen posted the full update. The stolen assets spanned ETH, XRP, BNB, AVAX, USDT, and USDC across several blockchains, with XRP accounting for the single largest chunk on any one chain.

The scariest part of this hack wasn't the size. It's that nobody's private key had to be stolen for it to happen.

Spoofed Transactions, Not Stolen Keys, and That Distinction Should Worry You More

Here's the detail that actually changes how I think about exchange risk. Chen confirmed the attacker compromised a critical backend system within Bitget's wallet infrastructure, used it to spoof transaction data, and triggered the exchange's own authorization process to move funds out. Private key compromise was explicitly ruled out. Run that logic through: if you don't need someone's keys to drain a wallet, you just need to trick the system that approves transactions into thinking a fake request is real, then the entire "not your keys, not your coins" wisdom stops being the only line of defense. The exchange's own internal trust system became the weapon.

$464 Million Against a $351.6 Million Hole, a 75.8% Hit to the Safety Net

Bitget says its User Protection Fund holds more than $464 million, enough to cover the entire loss with room to spare. Do the math yourself: $351.6 million divided by $464 million comes out to about 75.8%. That means three-quarters of the entire safety fund got consumed in a single incident, leaving roughly $112.4 million in buffer for whatever comes next. A fund surviving one hit this size is reassuring. A fund built to survive exactly one hit this size is not the same thing as a fund built to survive two.

Cold Wallets Untouched, Which Is the One Piece of Good News Worth Sitting With

Bitget confirmed its offline cold wallets weren't touched, only portions of the hot and warm wallet layers. That distinction matters more than it sounds like it should. Cold storage, kept offline and disconnected from the systems an attacker can spoof, survived completely intact while the actively connected layers got hit. It's the same lesson every major exchange hack teaches and the same lesson most people ignore anyway: anything connected to the internet is eventually reachable by someone determined enough.

How to Actually Protect Yourself Before the Next One

I moved the rest of my exchange balance to a hardware wallet within an hour of reading Chen's first update, and here's the checklist I went through doing it. Keep only what you're actively trading on any exchange, treat the rest as already at risk. Move long-term holdings to a hardware wallet you control, where the private keys never touch an internet-connected system. Spread meaningful balances across more than one custody method instead of trusting a single point of failure, exchange or otherwise. Check whether the platforms you use disclose the size of their protection fund relative to their total holdings, because a fund that only covers 75% of one incident's worth of losses isn't a fund built for a repeat. And treat "the hack didn't touch cold wallets" as the entire argument for why cold storage exists, not as a reassuring footnote to skim past.

North Korean state-linked actors are suspected based on IP patterns and on-chain analysis, though Bitget hasn't named a specific group. Attribution matters for investigators. For the rest of us, it changes nothing about what to do next: assume any exchange can be the next headline, and structure your holdings so that headline doesn't include your balance.

Thanks for reading this one all the way through. Here's my question for you: if a $464 million safety fund can get 75% wiped out in one incident, how much of your own portfolio is still sitting somewhere that isn't actually yours?


Just received another NunoAi affiliate payout.

I referred a couple people recently and woke up to $150 sitting on my account.

Total Earned: $250 in USDC Next target: $500

Withdrawal is 100% verified.

Btw this is the limited time affiliate campaign opened for early supporters, you can still join. Affiliate opportunity still available: http://getnuno.com/affiliates (limited time)

The NunoAi affiliate program is straightforward: you refer someone, they sign up and pay, and you take 50% as your reward based on their spend. Simple. If you're already using it and like it, this is a chill way to stack a little extra while sharing something useful.

Join the Telegram help group: https://t.me/+uK1G5_ONzgwxNzA9

Thanksss, NunoAi team

How do you rate this article?

4


TroZan
TroZan

crypto and web3 through my lens market moves new projects ipo news big launches and the trends worth paying attention to. breaking down what’s happening without making it unnecessarily complicated.


The-Onchain-Take
The-Onchain-Take

crypto and web3 through my lens market moves new projects ipo news big launches and the trends worth paying attention to. breaking down what’s happening without making it unnecessarily complicated.

Publish0x

Send a $0.01 microtip in crypto to the author, and earn yourself as you read!

20% to author / 80% to me.
We pay the tips from our rewards pool.

Page not displaying correctly?