Bitget says it detected unauthorized transfers from some hot wallets at 18:31 UTC on September 24 and estimates the affected assets at approximately $351.6 million. The exchange temporarily suspended withdrawals while leaving deposits and trading operational. Bitget security notice, BleepingComputer.
The company says cold wallets were not affected and that its User Protection Fund, reported at more than $464 million, will cover the loss. Those are Bitget's statements during an active investigation. They do not replace a completed reconciliation or an independent assessment of the fund's liquidity and claims process.
Bitget has notified law enforcement and onchain security firms. Its initial notice does not identify the attack vector and promises a fuller incident report. Attribution claims circulating around the event should remain separate from the confirmed wallet movements until investigators publish supporting evidence.
Customers should rely on the exchange's saved official address and support center for withdrawal updates. Incident periods attract impersonation messages, fake reimbursement forms and requests for seed phrases. An exchange support team does not need a user's wallet recovery phrase to restore account withdrawals.
The key follow-up points are the root cause, a complete asset reconciliation, restoration of withdrawals and evidence that affected users were made whole. Until those are available, the protection-fund commitment remains a stated response rather than a completed recovery.