The number first visible onchain was already substantial. Bitget's own estimate is much larger. Public monitoring initially tracked more than $170 million moving from addresses associated with the exchange before Bitget confirmed that approximately $351.6 million was affected by unauthorized transfers.

The company says its security systems detected the activity at 18:31 UTC on September 24 and activated emergency procedures. Addresses linked to the abnormal transfers were flagged, while law enforcement and onchain security firms were brought into the investigation.

Hot and warm infrastructure was affected, Bitget says cold storage was not

The wallet architecture is now the most important technical distinction in the incident. Bitget describes a three-tier system and says the breach was contained to part of its hot and warm wallet layers. Its cold wallets, the more isolated storage layer intended to keep assets away from systems involved in routine online operations, remained secure according to the exchange.

Early public reporting was messier. Blockchain data providers had labels suggesting that unusual transactions originated from addresses assigned to several Bitget wallet categories. The exchange later stated that its actual cold-wallet layer was not compromised.

The difference is a useful warning about treating third-party address labels as an exact map of an exchange's internal architecture. An analytics platform can associate an address with Bitget without necessarily knowing how Bitget classifies that wallet operationally.

There is still no final technical explanation for the intrusion. Bitget says it will not speculate about the attack vector while the investigation is ongoing and has promised a full incident report containing a root-cause analysis and corrective actions within 24 hours.

For users, the withdrawal freeze is still the immediate consequence

Withdrawals were suspended as part of the security review. In a notice posted at 23:30 UTC, Bitget still described withdrawal services as temporarily unavailable while deposits and its main trading services continued to operate.

The disruption also spread to another part of the platform. At 01:32 UTC on September 25, Bitget said its Onchain trading service was temporarily unavailable during the comprehensive security review and would return after that process was completed.

That distinction matters. Keeping the core trading engine online is not the same as having the whole platform back to normal. Until the security review is completed and withdrawals are restored, the operational response remains in progress.

The protection fund is moving from marketing line to real-world test

Bitget says customer balances remain accurate and that users are protected from the affected amount. Its main financial backstop is the User Protection Fund, which the company says is currently worth more than $464 million, above the approximately $351.6 million involved in the incident.

That figure should not be read as a fixed pile of cash. Bitget's August report said the fund was supported by 5,500 BTC. Its average valuation during that month was $382 million, it peaked at $441.5 million and ended August at roughly $432 million. The dollar value of the protection pool therefore moves with the market.

This turns an abstract safeguard into a fairly direct test. Having a fund whose reported market value exceeds the incident estimate is one part of the response. How that pool is actually used, how much is required and what the exchange's balance sheet and reserves look like afterward are separate questions.

Bitget's Proof of Reserves is another layer, not the same pool. A September 17 update reported an overall reserve ratio of 135% and expanded its verification coverage to 19 assets. Proof of Reserves is intended to show backing for customer assets; the protection fund is an additional buffer. Neither pre-incident figure substitutes for the post-incident accounting that has yet to be published.

The $351.6 million figure is confirmed, the attack path is not

The tempting next step is to turn every technical theory circulating around the transactions into a root cause. External researchers are already reconstructing how assets moved across networks and how individual transactions were executed. Bitget has not yet released a final explanation of what was compromised.

The confirmed core remains narrower: unauthorized transfers reached part of Bitget's connected wallet infrastructure, the exchange estimates approximately $351.6 million was affected, withdrawals were suspended and Bitget says its cold wallets remained secure.

The most useful next disclosure will therefore be the promised incident report rather than another running total. It needs to explain how the authorization path behind the hot and warm wallet layer allowed transfers of this scale, which controls failed and what has changed before Bitget restores all affected services.