Swiss bank shields Bitget institutions while retail funds freeze

Bybit
Bybit


Bitget says about $387.5 million in assets was transferred to attacker-controlled addresses during a Sept. 24 wallet breach. Its withdrawals remained suspended in notices issued through Sept. 25, even as deposits and trading continued.

On the day of the breach, Sygnum announced that Bitget’s institutional clients could trade against collateral held at the Swiss bank instead of placing that collateral in Bitget’s wallets.

The juxtaposition puts a question behind the promise of off-exchange custody: which assets sit beyond an exchange wallet breach, and what still depends on the exchange when trading or withdrawals are disrupted?

Sygnum’s route is for eligible institutional clients who onboard with its bank. The companies have not disclosed how many Bitget clients use it or whether any Sygnum-held collateral was connected to this incident.

Phemex

A breach alongside a new custody route

Bitget said its systems detected unauthorized transfers at 18:31 UTC on Sept. 24. Its initial notice placed the affected funds at about $351.6 million and said the breach reached portions of its hot and warm wallet layers, while cold wallets remained secure.

In a Sept. 25 update, Bitget raised the estimated assets transferred to attacker-controlled addresses to about $387.5 million after including Zcash and TRON transfers in a fuller accounting. It said the revision did not represent a fresh wave of unauthorized transfers.

The exchange said it identified and remediated the underlying vulnerability and contained the incident. Mandiant and SlowMist were assisting its investigation, according to Bitget.

Bitget’s withdrawal notice said withdrawals were temporarily unavailable while deposits and trading stayed operational. The exchange promised to announce a withdrawal plan or status by Sept. 26 at 04:00 UTC.

For a customer with an ordinary Bitget balance, a displayed balance and the ability to trade do not by themselves provide an exit while withdrawals are paused.

Sygnum said Bitget’s institutional clients can use its Protect service for spot and derivatives trading while pledged collateral remains in Sygnum custody in Switzerland. Bitget mirrors the balance as trading margin.

The bank lists Bitcoin, Ethereum, stablecoins and US Treasuries among the eligible collateral. Its published process requires a client to onboard with Sygnum, sign a contractual framework, open a Protect portfolio, and pledge assets before receiving exchange margin.

Under Sygnum’s description, the collateral is held in segregated accounts off the bank’s balance sheet and is bankruptcy remote under Swiss banking law. Keeping the pledged assets at the bank reduces direct custody exposure to Bitget’s own wallets.

It also addresses the concern that if an exchange faces financial distress, the collateral is intended to remain outside its estate. These are features of the arrangement as Sygnum describes it.

The announcement is dated Sept. 24 but does not state when Bitget client access became operational, nor that the integration preceded the 18:31 UTC breach or arose in response to it, nor does it identify any Bitget client who had completed onboarding, give a Bitget-specific collateral balance, or say whether Sygnum-held assets were involved in the incident.

Figures in the release for Protect’s total assets and the trading-volume share of all its integrated exchanges do not measure Bitget client uptake.