NextFin

Bitget Confirms $351.6 Million Breach and Suspends Withdrawals as Protection Fund Takes the Hit

Summarized by NextFin AI
  • Bitget confirmed unauthorized transfers hit limited hot wallets, affecting ~$351.6 million, suspending withdrawals while deposits and spot trading continued normally.
  • CEO Gracy Chen stated the loss is fully covered by the User Protection Fund, which holds over $464 million, implying a coverage ratio of about 1.3x on paper.
  • The breach is confined to hot and warm wallet layers, with cold wallets untouched, contrasting with Bybit's larger $1.46 billion cold-wallet theft in February 2025.
  • The real test is behavioral, not accounting: withdrawal resumption, the root-cause report, and fund composition will determine whether the post-FTX self-insurance model survives a potential bank run.

NextFin News - Crypto exchange Bitget confirmed on Thursday that unauthorized transfers struck a limited number of hot wallets, affecting approximately $351.6 million in assets, and temporarily suspended withdrawals while it investigates. The company said its security systems flagged the transfers at 18:31 UTC and activated emergency response procedures; deposits and spot trading were left running normally. CEO Gracy Chen said the full loss sits inside Bitget's User Protection Fund, which she put at more than $464 million. The central question is no longer whether Bitget can pay — on paper, the fund covers the loss about 1.3 times over — but whether the crypto industry's post-FTX promise, "we insure hacks from our own balance sheet," survives contact with a real bank run.

Layer 1: The Situation — A Hot-Wallet Breach, Not a Cold-Storage Collapse

Bitget's breach is confined to the part of a centralized exchange's stack designed to be sacrificial. Hot wallets hold the liquidity needed for day-to-day withdrawals; they are online, connected, and therefore exposed. Cold wallets keep the bulk of customer assets offline, signed in air-gapped hardware, and are the vault. Bitget said the breach was contained to a portion of its hot and warm wallet layers, that cold wallets were not touched, and that user account balances remained accurate.

The size and location of the loss are both smaller than the industry's worst case. In February 2025, Bybit lost roughly $1.46 billion — about 401,346 ether and related staked tokens — from a single offline cold wallet, in what remains the largest theft in cryptocurrency history. That breach forced Bybit to take bridge loans to keep withdrawals flowing and triggered more than $4 billion in net outflows within days, according to reporting on the incident. Bitget's loss is roughly a quarter of Bybit's, and it sits in the layer exchanges treat as expendable.

Chen said the exchange has flagged the addresses linked to the transfers, contacted law enforcement and on-chain security firms, and would not speculate on the attack vector while the investigation is ongoing. She committed to hourly updates and a full incident report — including a root-cause analysis and corrective actions — within 24 hours of the incident.

"The full amount affected falls within Bitget's User Protection Fund," Chen said, adding that the fund currently holds more than $464 million.

That sentence is doing more work than it appears to. A protection fund larger than the loss converts a solvency scare into a liquidity pause. But the arithmetic is only the first layer, and crypto markets have a habit of stress-testing the second.

Layer 2: The Analysis

The Coverage Ratio Passes on Paper; the Run Risk Has Not Been Tested

Bitget's User Protection Fund stands above $464 million against a $351.6 million loss — a coverage ratio of about 1.3x. In its most recent monthly proof-of-reserves report, published in late August, the exchange reported a 122% reserve ratio across user assets, its 45th consecutive monthly disclosure since the program began in December 2022. The fund grew into the breach; the loss did not outrun it.

This is the intended architecture of the post-FTX exchange. After the collapse of FTX revealed that "proof of reserves" could be gamed and that customer assets could be rehypothecated, the surviving platforms built a three-part promise: publish reserve attestations, maintain a self-insurance fund, and make users whole without taxpayer or creditor involvement. Bitget's numbers pass that test on paper. The harder test is behavioral, and it arrives the moment withdrawals reopen.

When Bybit suspended withdrawals after its cold-wallet theft, users did not wait politely for the bridge loan to land. They pulled more than $4 billion in a matter of days — a run that dwarfed the original $1.46 billion loss and forced the exchange to buy $574 million of ether over the counter to repay borrowed funds. The lesson of 2025 is that the size of the hack is not the risk; the size of the panic is. Bitget has left trading open and deposits flowing, which caps the immediate pressure, but withdrawals remain frozen until the security review clears. The coverage ratio will then be tested against actual user behavior, not accounting ratios.

There is also a composition question the exchange has not answered. A protection fund is only as good as the assets inside it. If the fund is held largely in the exchange's own token or in illiquid positions, covering $351.6 million in stolen assets could require fire sales that move markets against the very users being reimbursed. Bybit's playbook shows the mechanics: it offered a 10% bounty for recovered funds — roughly $140 million at the scale of the theft — and awarded early bounties to Binance, on-chain analyst ZachXBT and the Mantle network, while repaying bridge lenders through OTC purchases. Bitget has not yet disclosed the fund's composition or its reimbursement mechanics, only that the loss "falls within" it.

Second-Order Effect: The Breach Is Priced; the Insurance Premium Is Not

The first-order effect of any exchange hack is mechanical and familiar: stolen assets are swapped into ether, stablecoins or bitcoin and dispersed across thousands of addresses to obscure the trail. On-chain analysts typically track the laundering in real time, and the market absorbs the selling over days rather than hours. Bitget's own token, BGB, trades in the low-$2 range across market-data vendors, with a market capitalization near $1.5 billion — a valuation that already discounts a crowded, competitive exchange market, but not necessarily a reimbursement drag if the protection fund must be liquidated into a weak market.

The second-order effect is what the market has not fully priced. Bitget's breach lands less than eight months after the $1.46 billion Bybit theft, in a sector where blockchain-analytics firm TRM Labs put total crypto theft at more than $2.72 billion in 2025. Each incident raises the implicit insurance premium users demand for leaving assets on any centralized platform. That premium does not appear as a line item on an income statement. It shows up as lower balances on exchanges, larger stablecoin holdings in self-custody wallets, and a persistent discount on exchange tokens relative to their fee revenue.

The structural shift underneath the cyclical shock is the move from "trust us" to "prove it, continuously." Exchanges that can produce real-time, on-chain attestation of both reserves and insurance-fund composition will capture flight-to-quality flows; those that cannot will pay a funding and user-acquisition premium. Bitget's promise of a root-cause report within 24 hours is a down payment on that expectation — but the report's value depends entirely on whether it names a specific failure, such as a compromised key, a vendor vulnerability, or an insider control gap, rather than resting on a generic "unauthorized access" placeholder.

The Cyclical-vs-Structural Call

This is a cyclical confidence shock layered on top of a structural shift that was already underway. The cyclical leg is the confidence hit to Bitget specifically: users pause, withdrawals queue, the token discounts, and — if the fund pays out cleanly and the root cause is narrow — sentiment mean-reverts. History supports that path. When KuCoin suffered a $281 million hot-wallet breach in September 2020, its token KCS fell 14% in an hour, the exchange said it would reimburse all affected users from its own resources, and it ultimately recovered about 84% of the stolen assets through on-chain tracking, contract upgrades and judicial recovery. The incident receded from the news cycle; the business continued.

The structural leg is different, and it will not revert on its own. The evidence for a regime change is that the attack surface is scaling faster than the defense model. The Bybit breach was not a hot-wallet smash-and-grab; it was a supply-chain compromise of a multisig-wallet developer machine that let attackers sign a cold-wallet transfer — the layer exchanges claim is untouchable. The FBI publicly attributed that theft to North Korea and associated "TraderTraitor" activity, commonly linked to the Lazarus Group. When the next wave of attacks targets the custody layer itself, coverage ratios shrink fast, because protection funds are sized for hot-wallet attrition, not cold-storage collapse. That is why the industry's center of gravity is shifting from periodic, static proof-of-reserves snapshots toward continuous, on-chain verification of reserves and fund composition. One is a marketing asset; the other is a control.

The Counter-Thesis: A Contained Incident, Not a Turning Point

The strongest case against reading this as a turning point is straightforward, and it deserves weight: hot-wallet breaches are a recurring, survivable operating cost in crypto, not a solvency event. Exchanges have been reimbursing users from protection funds for years. KuCoin in 2020 covered a $281 million breach from its own resources; its token fell 14% in an hour before stabilizing, and most funds were recovered. Bitget's loss is smaller than Bybit's, contained to hot wallets, fully covered by a fund that exceeds it, and met with hourly communication and a promised root-cause report. Withdrawals are paused, not canceled. Trading is open. On this read, the episode is a cyclical confidence shock that mean-reverts once withdrawals resume and the incident report closes the loop — and it is probably right for Bitget specifically.

But that argument does not generalize cleanly to the industry, and it rests on a fragile assumption: that protection funds will remain adequate as attack sophistication scales. The counter-thesis treats the last hack as the model for the next one. It is not. The falsifying signal for the "contained incident" view is specific and observable: if Bitget's root-cause report points to a compromise beyond the hot-wallet layer — a signing-key exposure, a third-party custody vendor, or an internal control failure — the market will reprice the exchange's entire balance sheet, not just the $351.6 million. A second falsifying signal is behavioral: if withdrawals resume and net outflows over the following week approach or exceed the loss itself, the 1.3x coverage ratio will prove to be accounting comfort, not liquidity reality.

Layer 3: Outlook and What to Watch

Three signals will separate a contained incident from a deeper problem. First, withdrawal resumption: the pace and completeness of restoration is the first behavioral test. A clean reopening with normal volumes supports the cyclical read; continued delays or new limits suggest the loss or the fund's liquidity is worse than stated. Second, the root-cause report, due within 24 hours of the incident: it must name the attack vector. A specific, fixable cause — a single compromised key, a phishing vector, a vendor patch gap — is reassuring; a vague or deferred explanation is not. Third, fund composition and reimbursement mechanics: if the fund is held in liquid, non-correlated assets and reimbursement is automatic, confidence recovers; if users must file claims or the fund must sell into a weak market, the overhang persists.

Short term, Bitget faces a liquidity and communications test, not a solvency one. The $464 million fund covers the $351.6 million loss with room to spare on paper, and keeping trading open limits the immediate run risk. Medium term, the exchange's reputation hinges on the root-cause report and the speed of withdrawal restoration — the two data points users will actually act on. Long term, this breach accelerates a structural change that was already underway: the market is moving from periodic, static proof-of-reserves snapshots toward continuous, on-chain verification of both reserves and insurance-fund composition.

Base case: Bitget publishes a specific root cause, restores withdrawals within days, and reimburses affected users from the fund without market disruption. The token and the brand absorb a temporary discount and recover as the incident recedes. Upside case: the exchange turns the response into a transparency benchmark — publishing wallet addresses, fund composition, and recovery progress in real time — and captures flight-to-quality flows from smaller competitors that cannot match that disclosure. Downside case: the root cause implicates the custody layer or the fund proves illiquid, triggering a run that exceeds the original loss, on the Bybit pattern.

The takeaway is narrower than the headlines suggest. Bitget's breach is a test of whether the crypto industry's post-FTX self-insurance promise works at scale. So far, the arithmetic holds. The behavior has not been tested yet.

Explore more exclusive insights at nextfin.ai.

Search
NextFinNextFin
NextFin.Al
No Noise, only Signal.
Open App