---
title: "Bitget Freezes Withdrawals After $351.6 Million Spoofed-Transfer Hack"
date: 2026-09-25
author: "Kathleen Kinder"
featured_image: "https://coinlaw.io/wp-content/uploads/2026/09/bitget-freezes-withdrawals-351-million-hack-1.jpg"
categories:
  - name: "Cryptocurrency"
    url: "/crypto.md"
tags:
  - name: "News"
    url: "/tag/news.md"
---

# Bitget Freezes Withdrawals After $351.6 Million Spoofed-Transfer Hack

Crypto exchange Bitget’s authorization system approved $351.6 million in forged transfers from its hot and warm wallets on Sept. 24, CEO Gracy Chen said. Attackers spoofed the transaction data from inside a wallet backend, and she said no private keys were stolen.

## The Brief

- Bitget lost $351.6 million after attackers pushed forged transfer data through the exchange’s normal approval process, CEO Gracy Chen said.
- Bitget’s User Protection Fund holds more than $464 million and will cover the full loss, according to Chen.
- XRP was the largest stolen asset, with almost 102.9 million tokens taken, based on on-chain data from Lookonchain.
- Withdrawals remain frozen pending a security review, though deposits and trading stay open and no restart date exists yet.

## Bitget’s approval system signed off on forged transfers

Chen laid out the attack in a post on X. “**The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out**,” she wrote. “**Private key compromise has been ruled out**.”

That detail changes the shape of the incident. A copied private key lets an attacker keep signing new transfers, and key thefts have driven some of the industry’s [biggest exchange hacks](https://coinlaw.io/most-expensive-crypto-exchange-hacks/). Bitget’s keys stayed put. What broke was the layer that tells the signer what to sign, so the approval step cleared paperwork that looked official and wasn’t.

> JUST IN: Bitget crypto exchange reportedly hacked with over $170,000,000 stolen.
> 
> — Watcher.Guru (@WatcherGuru) [September 24, 2026](https://x.com/WatcherGuru/status/2103231497683763662?ref_src=twsrc%5Etfw)

 Bitget’s systems flagged the first unauthorized hot-wallet transfers at 18:31 UTC on Sept. 24. The breach also reached the warm-wallet layer, a semi-connected buffer that refills hot wallets and moves excess deposits offline. Cold wallets, the exchange’s offline storage, “**remain fully secure**,” Chen said.

Chen said the outflow has stopped. “**Loss containment is confirmed. No further unauthorized transfers are possible**,” she wrote. She added that the intrusion method “**remains under active investigation**” and that a full technical report will follow.

Bitget has ruled out one attack path without yet naming the one the attackers used. The promised report will need to answer at least four questions:

- **How did the attackers reach the wallet backend in the first place?**
- **Why did the authorization process accept spoofed transaction data as genuine?**
- **How long did the attackers hold access before the first alert fired?**
- **When will withdrawals reopen, and under what conditions?**

## XRP leads the stolen haul as Lazarus draws early suspicion

[XRP](https://coinlaw.io/xrp-statistics/) made up the biggest slice of the theft by value. Lookonchain’s count put the XRP haul at almost **$158 million**, alongside about 31,890 ETH worth $86 million. The rest spanned USDT, USDC, USDT0, tokenized gold (XAUt), BNB, AVAX and TRX.

The attackers have since swapped a large share of the stolen funds on EVM chains into ETH. Nansen, the blockchain analytics firm, traced one of the main on-chain clusters to 40,000 ETH split evenly across four addresses.

Chen raised the attribution question herself during a livestream. She said some attack IP addresses matched VPN patterns tied to North Korea’s Lazarus Group, but stressed the link isn’t confirmed. Lazarus has been blamed for many crypto thefts, including [Bybit’s $1.5 billion hack](https://coinlaw.io/bybit-sues-north-korea-lazarus-group-1-5-billion-hack/) in 2025.

On-chain investigator Spector went further and pinned the attack on TraderTraitor. He argued the stolen XRP was bridged and ties directly to funds from the $24 million hack of AFX Trade, a decentralized perpetuals exchange. Neither claim amounts to confirmed attribution, and Bitget hasn’t named a culprit.

## What’s Next?

Account holders face a split picture for now. Chen said balances are accurate and wrote that “**User funds are safe,**” with the protection fund absorbing the loss. Trading works, but any crypto deposited today stays on the platform until the freeze lifts.

The next checkpoints are a withdrawal timeline and the full technical report, and Chen has put a date on neither. She said multiple technical teams are working in parallel on remediation and security hardening. Bitget, she wrote, “**will not commit to a window we cannot guarantee,**” which ties withdrawal access to a review with no public end date.

Definition of Blockchain. Link to full glossary entry follows the description.**Blockchain**A distributed digital ledger that records transactions across a network, with each block cryptographically linked to the previous one for security.

[Read more](https://coinlaw.io/glossary/blockchain/)

Definition of EVM. Link to full glossary entry follows the description.**EVM**The Ethereum Virtual Machine is the runtime environment that executes smart-contract bytecode across every Ethereum node, using a 256-bit stack architecture and [gas](https://coinlaw.io/glossary/gas-fee/)-metered computation.

[Read more](https://coinlaw.io/glossary/evm/)