Bitget Confirms $351.6M Wallet Breach and Suspends Withdrawals

Ledger



Bitget has confirmed approximately $351.6 million in unauthorized transfers from portions of its wallet infrastructure after detecting abnormal activity at 18:31 UTC on September 24.

The exchange said the $351.6 million incident was contained to parts of its hot and warm wallet layers under a three-tier custody system. Its cold wallets were not affected.

Bitget activated its emergency response process within minutes, identified and flagged addresses connected to the transfers and notified law-enforcement agencies and onchain security firms.

Withdrawals Paused During Security Review

Bitget suspended withdrawals while its security team reviews the affected infrastructure.

Deposits and regular trading remained available under the exchange’s initial operational notice. Bitget later said its separate Onchain trading service had also been temporarily affected by the security review and was unavailable early September 25.

The exchange said withdrawal services will resume after the review is completed. No restoration time had been announced in its latest public support notices.

The shutdown follows other recent crypto services taking precautionary action after security incidents. Blink temporarily paused services after unauthorized withdrawals from custodial accounts, while Swiss Bitcoin Pay took its servers offline following suspected unauthorized access to internal systems.

Protection Fund Exceeds Reported Loss

Bitget said the entire loss falls within its User Protection Fund, which held more than $464 million when the incident was disclosed.

The fund was created separately from the exchange’s reserves to provide an additional financial protection layer for users. Bitget has committed to keeping its valuation above $300 million.

A September 17 Proof of Reserves report recorded a 135% aggregate reserve ratio across 19 covered assets. The snapshot was published one week before the breach and marked Bitget’s 46th monthly reserve update since December 2022.

Bitget said user account balances remain accurate and that affected assets will be covered through the protection mechanism.

Bitget Has Not Published an Attacker Attribution

Bitget has not publicly identified the attacker or confirmed the technical method used to initiate the unauthorized transfers.

Its incident notice specifically states that the exchange will not speculate about the attack vector before the investigation is completed.

Bitget also has not attributed the breach to North Korea’s Lazarus Group in its published security notice. Any attribution will require separate evidence from the exchange, law enforcement or investigators directly involved in tracing the incident.

Bitcoin coin symbol


$84.112

price

green chart
increase symbol0.38547%

price change














TRADE NOW

A full incident report covering the root cause and corrective measures is scheduled for publication within 24 hours of Bitget’s initial disclosure. Withdrawals remained suspended at the latest official update while the security review continued.



Source link

Changelly

Be the first to comment

Leave a Reply

Your email address will not be published.


*