Bitget Raises Confirmed Loss to $387.5 Million After Hot-Wallet Security Breach

Bitget raised its September 24 breach loss to $387.5 million after identifying additional transfers, while withdrawals stay suspended pending security checks.

Bitget Raises Confirmed Loss to $387.5 Million After Hot-Wallet Security Breach

Bitget on September 25 raised its confirmed loss from the previous day’s security breach to approximately $387.5 million, from an initial estimate of $351.6 million. The exchange said the increase came from additional Zcash and TRON transfers identified in its review, rather than a further wave of unauthorized withdrawals.

Withdrawals remain suspended while Bitget completes security validation, despite the company saying it has identified and remediated the underlying vulnerability.

Bitget revises breach total to $387.5 million

The revised figure adds $35.9 million to Bitget’s first estimate of assets transferred to attacker-controlled addresses during the September 24 incident. In its latest notice, the exchange said the higher total reflected additional transfers uncovered during the investigation.

That distinction is material to the chronology of the breach: Bitget characterized the adjustment as a more complete accounting of the original incident, not evidence of new unauthorized outflows after its initial disclosure.

Withdrawals remain suspended after remediation

Bitget said it had identified and remediated the vulnerability, while withdrawals remained suspended pending security validation; Mandiant and blockchain security firm SlowMist were assisting its investigation.

Reported wallet-infrastructure compromise

Bitget’s initial notice said it detected the breach at 18:31 UTC on September 24. The first reported total of approximately $351.6 million involved unauthorized transfers from portions of its hot and warm wallets, while cold wallets were unaffected, according to the initial disclosure.

The Block reported that an attacker compromised a backend wallet-infrastructure system and spoofed transaction data to invoke the authorization process. Bitget said its separate self-custodial Bitget Wallet product was not affected.

Investment Disclaimer

Share this story

X LinkedIn

Related Stories