Bitget was suddenly hacked in the early morning: timeline review, officials say approximately $351.6 million was affected
Editor: Wu Says Blockchain, Grok, etc.
Cryptocurrency exchange Bitget confirmed unauthorized transfers from its hot wallet in the early hours of September 25. CEO Gracy Chen stated that the security system detected abnormal outflows from some hot wallets at 02:31 Beijing time on September 25, with preliminary estimates of affected funds around $351.6 million. The official statement claims that cold wallets remain secure, user account balances have not been altered, and losses can be covered by a user protection fund exceeding $464 million. The platform has suspended withdrawals, while deposits and trading remain open, and it has promised to release a complete incident report with root cause analysis by 05:30 on September 26.
Before the official announcement, on-chain analysts had already observed wallets tagged with Bitget transferring approximately $178 million to $190 million in assets to newly created addresses. Two sets of figures currently coexist: $351.6 million is the internal accounting of the exchange, while around $180 million is the on-chain statistics from publicly tagged addresses.
The on-chain anomalies coincide closely with the official detection time. Unchained recorded the visible outflow period as from 02:31 to 04:55 on September 25. During this time, a newly created address withdrew approximately 19.67 million USDT from addresses tagged with Bitget hot wallets, and within about 6 minutes on Arbitrum, it was exchanged for approximately 7,111 ETH via UniswapX and 1inch Fusion, with the transaction price peaking about 5% above the market price. On-chain observer DCF GOD was the first to point out this exchange. There is a possibility that the stablecoins could be frozen by the issuer, making it harder to intercept after being converted to ETH.
Subsequently, multiple Bitget tagged wallets transferred ETH, USDT, USDC, AVAX, BNB, and XAUT into the same newly created address 0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee. Etherscan later marked it as Bitget Exploiter 1. The funds were then split into other addresses, and cross-chain bridging occurred. Unchained also recorded that within about 30 minutes, the same address received approximately 34.75 million USDT, 12.85 million USDC, and 3,000 XAUT; about an hour later, it received approximately 24,373 ETH from multiple tagged addresses. At 04:55, there was still a transfer out from Avalanche.
At 04:24, Arkham Intelligence analyst Emmett Gallic posted, initially reporting about $178 million, which was updated to about $183 million at 04:35, stating that it involved 3 hot wallets and 1 cold wallet tagged address, with multi-chain aggregation. The term "cold wallet" here comes from browser and analyst tags and does not automatically equate to the official internal classification of hot, warm, and cold wallets. At 05:06, Bubblemaps issued an alert, stating that a total of about $180 million was deposited into the same address, updated to about $190 million at 05:33. CryptoSlate cited its statistics, stating that 15 transfers involved nearly $192 million across seven assets, with ETH accounting for about 44.4%.
At 05:30, Gracy Chen posted a complete security notice on X, with the official website simultaneously publishing an announcement. The official confirmation of the affected amount is approximately $351.6 million, emphasizing that this only impacted part of the hot and warm wallets, while cold wallets are completely safe; user account balances are accurate, deposits and trading are normal, and withdrawals are suspended as a precaution. Bitget stated that it activated an emergency team within minutes of detection, marking and reporting abnormal addresses, while also notifying law enforcement and on-chain security companies. The official statement clearly indicated that no speculation on the attack path would be made until the investigation was completed, and updates would be provided hourly through official channels.
If the $351.6 million is ultimately confirmed, Bitget will rank among the top amounts in the history of centralized exchange thefts, but it is still significantly less than the amount stolen from Bybit in February 2025.
At that time, Bybit's Ethereum cold wallet was hacked during a routine transfer of about 400,000 ETH, valued at approximately $1.4 billion to $1.5 billion, marking the largest single theft from an exchange on record. Subsequent investigations pointed to a targeted malicious script implanted in the front end of the Safe multi-signature wallet, where signers saw a normal transfer on the interface but were actually signing a transaction to replace the implementation contract, resulting in the control of the cold wallet changing hands. The FBI and other agencies later attributed the attack to the North Korean Lazarus group. Bybit used its own funds to compensate, resumed normal operations afterward, and user funds were unaffected.
After the theft of Bybit's cold wallet in February 2025, Bitget was one of the first exchanges to publicly extend a helping hand, transferring 40,000 ETH from its own funds to Bybit, valued at about $10.5 million to $10.6 million at the time, to alleviate withdrawal pressure. This loan was unsecured, interest-free, and had no fixed repayment deadline. Bybit CEO Ben Zhou later stated in an interview that Bitget was the first to help, without even signing a contract. Bitget also blacklisted the related addresses and stated that it could continue to provide support. About three days later, Lookonchain monitored that Bybit returned 40,000 ETH, and Gracy confirmed receipt.
Historically, the most common reasons for thefts from centralized exchanges in public reviews are the compromise of hot wallet private keys or signing permissions. Coincheck in 2018 lost about $530 million, KuCoin in 2020 about $280 million, and Bitmart in 2021 about $150 million, all pointing to the loss of keys from online hot wallets. Another category involves bypassing multi-signature and signing interfaces: Bitfinex in 2016 was related to its then multi-signature scheme; WazirX in 2024 saw control of multi-signatures compromised; and Bybit was hacked in February 2025, among others. Additionally, there are failures in supply chain and operational processes, such as compromised signer devices, wallet service providers, or internal permissions being exploited.
As of the time of publication, Bitget stated that it is following up on the investigation progress hourly, and the specific attack path (such as whether it involves private key leakage or interface vulnerabilities) awaits disclosure in the official complete report.













