The Bitget spoofed transfers hack saw $351.6 million removed from the exchange’s hot and warm wallets after unauthorized transfers were detected.
The breach surfaced when systems flagged unauthorized transfers at 18:31 UTC on Sept. 24, and Bitget says losses are covered by its User Protection Fund, which holds more than $464 million.
Deposits and trading remain open, while withdrawals have been frozen as a precaution pending a security review.
Attackers compromised a critical backend system within Bitget’s wallet infrastructure, used it to spoof transaction data, and triggered the authorization process to move funds out. They faked transfer requests to drain funds but did not steal private keys, and private key compromise has been ruled out. The breach surfaced when systems flagged unauthorized transfers at 18:31 UTC on Sept. 24.
The incident removed $351.6 million from the exchange’s hot and warm wallets. A hot wallet is connected to the internet and serves as a temporary liquidity hub for instant trades, deposits, and withdrawals. The breach also reached the warm-wallet layer; the cold wallets remained fully secure. As a precaution, deposits and trading remain open but withdrawals have been frozen pending a security review.
The breach has been described as the digital version of forged withdrawal slips through a bank’s teller window, and Bitget says the vault keys never left the building. Loss containment is confirmed and multiple technical teams are working on remediation and security hardening, with a full technical report to follow once confirmed.
After discovering the hack, Bitget immediately froze withdrawals as a precautionary measure pending a comprehensive security review; however, deposits and trading remain active. Multiple technical teams are now working diligently on the remediation and security hardening of the system. Meanwhile, Bitget has confirmed that despite the breach, loss containment has been successful, and no further unauthorized transfers are occurring. The detailed method of the system intrusion remains under investigation, with a full technical report to be published once the details are confirmed.
The User Protection Fund holds more than $464 million and covers the full loss. Bitget has stated that User funds are safe. The company also says Your account balances are accurate and your assets are protected.
Private key compromise has been ruled out. Cold wallets remained fully secure. The breach affected the exchange’s hot and warm wallets, but not cold storage.
Bitget says loss containment is confirmed and no further unauthorized transfers are possible. A full technical report will be published once the investigation confirms the details.
The Bitget spoofed transfers hack was a sophisticated breach that targeted a critical backend wallet system and moved $351.6 million out of the exchange’s hot and warm wallets without compromising private keys. Loss containment was confirmed through timely detection and response, and user assets are protected by Bitget’s User Protection Fund. Withdrawals remain frozen as security measures continue while investigation and remediation proceed and updates will be provided when available.


