Bitget Loses $351.6M to Hackers, Vows User Funds Are Safe
African crypto traders can breathe easy. Bitget, one of the world's biggest cryptocurrency exchanges, has confirmed that hackers made off with a whopping $351.6 million from its wallets. But the exchange is already fighting back, and it says every single user dollar is protected.
The breach happened on Thursday, September 24, at 18:31 UTC. Bitget's security systems flagged unauthorized transfers from some of its hot wallets, triggering an immediate emergency response. The attack hit parts of the exchange's hot and warm wallet layers, but cold wallets, the fortress of crypto storage, stayed locked down tight.
In a statement, Bitget CEO Gracy Chen broke the news with confidence: “Estimated funds affected: approximately $351.6 million.” But she quickly followed up with the reassurance that matters most: “User funds are safe. The full amount of this loss falls within the coverage of Bitget's User Protection Fund, which currently holds over $464 million.”
That fund is the shield. With $464 million in reserve, Bitget has more than enough to cover the $351.6 million hit. Deposits and trading never stopped. Withdrawals were paused briefly as a precaution, but the exchange is working around the clock to get everything back online.
How Did the Hackers Get In?
Chen didn't hold back on the details. The attackers didn't crack the private keys, which would have been a disaster. Instead, they pulled off something more cunning.
“The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out,” she explained.
That's a sophisticated play. By spoofing transaction data, the hackers tricked the system into approving transfers it shouldn't have. But Bitget's team moved fast. “Private key compromise has been ruled out, this excludes the more severe risk scenarios. Loss containment is confirmed. No further unauthorized transfers are possible,” Chen said.
The investigation into the exact method is still ongoing, and Bitget promises a full technical report once the findings are locked in.
What Was Stolen?
The stolen assets were a mixed bag: ETH, XRP, BNB, AVAX, USDT, USDC, and other tokens spread across major networks like Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base. But here's the key line: “All on-chain cold wallets have been confirmed secure and unaffected,” Chen said during a livestream with users.
Bitget has already contacted the foundations behind these blockchain networks. Some have confirmed they're freezing wallet addresses linked to the attackers. That's the global crypto community closing ranks.
North Korean Hackers in the Crosshairs
So who's behind this? Chen pointed the finger with evidence in hand. “Based on IP behavior patterns and on-chain analysis, the attack method in this incident is highly consistent with known patterns of North Korean hacker organizations,” she said.
This isn't just speculation. The IP patterns and on-chain trail match the playbook of North Korean hacking units, groups that have been blamed for some of the biggest heists in crypto history. Bitget has reported the matter to relevant institutions and is cooperating with a global investigation.
One thing to note for anyone using Bitget Wallet: you're clear. “Bitget Wallet operates completely independently from Bitget exchange infrastructure, and this incident has no impact on it whatsoever,” Chen confirmed.
When Will Withdrawals Resume?
That's the question on everyone's lips. Bitget isn't rushing to give a timeline it can't keep. “Our goal is to complete a full recovery as soon as possible. We will announce the specific time window immediately upon confirmation. We will not commit to timelines we cannot deliver on,” Chen said.
Multiple technical teams are on the job, handling system remediation and security hardening. Law enforcement agencies and on-chain security firms have been notified. Bitget is pursuing every available channel to contain the incident and recover the assets.
The exchange has also promised hourly updates and a full incident report, including root-cause analysis and corrective actions, within 24 hours. That's transparency you can respect.
What This Means for African Crypto Users
For the growing crypto community across Nigeria and the continent, this is a moment to watch. Bitget has shown that even giants can be targeted. But it has also shown that strong protection funds and quick action can keep user funds safe.
The lesson is clear: security matters, and exchanges that invest in protection are the ones worth trusting. Bitget's User Protection Fund just proved its worth. African traders can keep their heads high and their wallets ready. The system held.
Frequently Asked Questions
Is my money safe on Bitget after the hack?
Yes. Bitget has confirmed that the full $351.6 million loss is covered by its User Protection Fund, which holds over $464 million. User funds are safe, and cold wallets were never compromised.
How did the hackers steal $351.6 million from Bitget?
The attackers compromised a critical backend system in Bitget's wallet infrastructure. They spoofed transaction data and triggered the authorization process to move funds out. Private keys were not compromised.
When will Bitget resume withdrawals?
Bitget has not announced a specific timeframe yet. The exchange says it will not commit to timelines it cannot deliver on, but multiple teams are working on system remediation and security hardening to restore withdrawals as soon as possible.