NextFin News - Crypto exchange Bitget said it lost $351.6 million in unauthorized transfers from some of its hot wallets on Thursday, even as CEO Gracy Chen insisted that user funds remain safe because its cold wallets were never touched. The breach drained wallets labeled as Bitget's across six blockchain networks in roughly two and a half hours, and the attacker immediately converted freezable stablecoins into ether and scattered the proceeds through cross-chain bridges - the same laundering sequence that has made large crypto thefts nearly impossible to recover since the $1.5 billion Bybit heist in February 2025.
The Breach: What Happened, and What Bitget Says
The outflows began shortly after 2:31 p.m. ET on Thursday, when a newly created address started pulling assets from wallets labeled as Bitget's. By 4:55 p.m. ET, more than $180 million had moved, according to on-chain records reviewed by multiple trackers. Etherscan now tags the receiving address as "Bitget Exploiter 1."
Chen announced the $351.6 million figure in a post on X later that day. She said the exchange's cold wallets - the offline vaults designed to hold the bulk of customer assets - remained fully secure, and that Bitget operates a three-tier wallet architecture in which the breach "contained only a portion of the hot wallet and warm wallet layers."
"Cold wallets remain fully secure. Bitget operates a three-tier wallet architecture — the breach contained only a portion of the hot wallet and warm wallet layers," Chen said in the post. "Unauthorized transfers from some of our hot wallets."
Deposits and spot trading stayed online, but the exchange temporarily paused withdrawals on all 4,930 asset-network entries in its public API while it completed a security review. Chen promised an incident report within 24 hours.
The mechanics are the story. The first suspicious move came from a hot wallet - the internet-connected reserve exchanges use to process everyday withdrawals. An address beginning with "0xe410" spent $19.67 million of USDT0, a cross-chain version of Tether's dollar-pegged stablecoin, to buy 7,111 ether in six minutes on Arbitrum, paying as much as 5% above the prevailing market price through decentralized exchanges UniswapX and 1inch Fusion. Additional wallets tagged as Bitget's then sent ether, BNB, AVAX, USDC, USDT and XAUT - a token backed by physical gold - to the same destination.
By 5 p.m. ET, roughly 48,800 ETH, worth about $131 million, sat across four addresses Etherscan tags as Bitget exploiters. An Arkham tracker grouping 13 linked addresses showed about $183.8 million arriving from Bitget wallets across six networks, including Arbitrum and BNB Chain, with funds hopping between chains through bridges such as Stargate and Celer's cBridge.
The exchange's defense rests on its user protection fund. Chen said the fund held more than $464 million at the time of the breach - enough, on paper, to cover the $351.6 million loss roughly 1.3 times over. The fund was launched at $200 million in 6,000 bitcoin and 80 million USDT, with Bitget pledging to secure its value for three years. Its reported peak value exceeded $382 million in August.
That is the surface story: a mid-sized exchange lost money from its hot wallets, says its cold storage is intact, and claims a reserve big enough to make users whole. The deeper question is whether the industry's post-Bybit defenses - stablecoin freezes, cross-exchange cooperation, blockchain forensics - are losing their bite.
The Attacker Was Not Stealing; They Were Laundering in Real Time
The most telling detail in the Bitget breach is not the size of the loss. It is the sequence.
The attacker did not simply drain wallets and hold the assets. The first move converted $19.67 million of USDT0 - a freezable, centrally issued stablecoin - into 7,111 ETH within six minutes, accepting up to 5% slippage to do it. That is the signature of an operator who knows exactly what comes next: stablecoin issuers can and do freeze stolen funds at the contract level, but ether cannot be frozen by any issuer. Once the value is in native ETH, the only remaining defenses are exchange-level blacklisting at the point of deposit and law-enforcement action - both of which require time the attacker had already spent.
The second move compounded it. Funds were bridged across six networks through Stargate and Celer's cBridge. Each chain-hop forces trackers to rebuild the trail from scratch and multiplies the number of jurisdictions and intermediaries that must cooperate to freeze anything. In the Bybit case, that coordination worked - but it worked partly because the theft was a single, massive, highly visible ETH transfer that sat relatively still while exchanges and investigators organized. Bitget's attacker appears to have learned the lesson: move fast, fragment early, and convert to assets no single issuer controls.
This is the transmission channel that turns an exchange breach into a near-total loss: hot-wallet compromise → instant conversion to unfreezable assets → cross-chain dispersal → recovery odds collapse. The industry spent 2025 building the first two links of defense - freeze powers and information sharing. Attackers spent the same year attacking the middle two.
Bitget's "User Funds Are Safe" Claim Is Narrow - and That Is the Point
Chen's reassurance is technically precise in a way that should make readers pause. She did not say "no user funds were lost." She said cold wallets are secure, that the breach was contained to "a portion" of the hot and warm layers, and that the protection fund - at $464 million - exceeds the loss.
That is a solvency argument, not a security argument. It says: even if every dollar taken from the hot wallets belonged to customers, the exchange can cover it. For a $351.6 million incident at an exchange with a $464 million fund, that math holds. It is the same arithmetic that let KuCoin survive its roughly $281 million hack - the exchange recovered about $239 million and covered the remaining $45.55 million from its insurance fund.
But the three-tier architecture Chen describes is also an admission of what the industry has quietly accepted: hot wallets are sacrificial. They must be internet-connected to process withdrawals quickly, which makes them inherently exposed. The "warm" layer - a middle tier between hot and cold - is meant to limit blast radius. Bitget's claim that only "a portion" of these layers was breached suggests the attacker had access to some signing credentials but not all of them. That is a meaningful containment outcome. It is also, by design, a recurring one.
The uncomfortable implication: exchange security has shifted from "prevent the breach" to "limit and absorb the breach." That works as long as losses stay smaller than the protection fund. It stops working the moment they do not.
The Second-Order Risk Is Not This Hack - It Is the Erosion of the Freeze Defense
The market's reaction to the Bitget news is itself a data point. As of 10 a.m. ET on Thursday, bitcoin traded at $83,942.62, down 2.03% from the prior day, while ether was at $2,666.12. Bitget's own token, BGB, fell roughly 6.45% on the day. But the broader crypto market did not seize up: bitcoin held near $84,000 rather than cascading, and there was no broad exchange-token rout.
Compare that with the aftermath of the Bybit theft. After North Korea's Lazarus Group stole $1.5 billion in ETH from Bybit on February 21, 2025, bitcoin fell roughly 20% from its January all-time high and dropped below $90,000 as global jitters combined with the security shock. Investors have, in effect, become more tolerant of periodic exchange hacks - pricing them in as a recurring operating cost of the crypto system rather than a systemic event.
That tolerance is the second-order risk. The conventional read is that hacks are cyclical shocks: painful, contained, mean-reverting. Exchanges get hit, funds are frozen or recovered, users are made whole, confidence returns. The Bybit episode reinforced exactly this story - unprecedented cooperation among exchanges, blockchain-intelligence firms and law enforcement produced recoveries and even the swift dismantling of sanctioned venues.
But the Bitget breach points to a structural shift underneath the cycle: the specific defenses that made Bybit containable are being engineered around. Tether reported freezing around $3.3 billion of USDT between 2023 and 2025; Circle froze about $109 million of USDC in the same window. Those freeze powers are the industry's emergency brake. Bitget's attacker did not try to outrun the brake - they disconnected it, swapping into ETH before any issuer could act, then fragmenting across bridges where no single issuer has reach.
If that playbook becomes standard, the recovery rate on exchange hacks falls structurally, not cyclically. Consider the record: of the eleven largest crypto hacks on record, only two - Poly Network and Wormhole - ended with victims fully made whole. The KuCoin model, in which most stolen funds are recovered and only a residual gap of $45.55 million needs covering, assumes recoveries are the norm. Bitget's $464 million fund covers this incident. It would not have covered Bybit's $1.5 billion. And if the freeze defense continues to erode, total-loss sizing - not net-of-recovery sizing - is the direction of travel.
The Counter-Thesis - and What Would Prove It Wrong
The strongest case against a structural read is straightforward: Bitget's three-tier architecture did exactly what it was designed to do. Cold wallets were untouched. The loss was capped at the hot/warm layer. The protection fund covers the loss 1.3 times over. Withdrawals are paused temporarily, not indefinitely. Within days, this could look like a contained operational incident - the crypto equivalent of a bank branch robbery, not a bank failure.
That argument has real force, and it is backed by the industry's own track record. Exchanges have repeatedly absorbed six- and seven-figure hot-wallet losses without systemic contagion. Bitget itself reported blocking more than 150 million malicious requests over the past year - the attack surface is enormous, and perfect defense is impossible. On that view, the appropriate response is not to reprice the sector but to verify the incident report and move on.
But the counter-thesis rests on one assumption: that the freeze-and-recover machinery will keep working at historical rates. The falsifying signal is specific and observable. If Bitget resumes withdrawals within 48 hours with no customer shortfall, and its promised incident report shows cold wallets untouched and a clear path to recovering a meaningful share of the $351.6 million, then the cyclical, contained-incident read is confirmed and the structural alarm is overblown. If, instead, withdrawals remain suspended beyond 48 hours, the incident report is vague about cold-wallet integrity, or recovered funds fall below 20% of the loss, then the erosion-of-defenses thesis strengthens - and the protection-fund model across the industry needs re-pricing.
Watch that 48-hour window. It is the difference between a branch robbery and a run on the bank.
What Comes Next
The immediate impact of the Bitget breach lands on three groups. First, Bitget users: withdrawals are paused, and while the protection fund math supports full reimbursement, "made whole eventually" is not the same as "accessible now." Second, competing exchanges: any breach at a rival is a short-term acquisition opportunity for platforms that can prove their reserves are larger and their custody cleaner. Third, stablecoin issuers and bridge operators: the attacker's conversion-and-fragmentation playbook puts pressure on both. Issuers face demands to freeze faster; bridges face demands to build halt mechanisms that do not themselves become single points of failure.
Split by horizon, the picture diverges. In the short term, this is sentiment and liquidity: withdrawals paused, users anxious, competitors circling. If Bitget executes a clean, fast restart with a transparent report, the episode closes with a whimper. Over the medium term, the fundamentals matter: protection funds across the industry will be scrutinized against realistic worst-case loss scenarios, not historical recovery rates. Exchanges with thin reserves relative to daily withdrawal volume will face a trust discount. Over the long term, the structural question is whether the hot-wallet model itself survives. Every contained breach validates the containment strategy - and every contained breach also reminds users why self-custody exists.
Three scenarios frame the next week. The base case: Bitget publishes a detailed incident report, resumes withdrawals within 48 to 72 hours, and covers any shortfall from the protection fund - a contained incident that fades from headlines. The upside case for Bitget: the exchange recovers a meaningful share of the ETH through cooperation with bridges and over-the-counter desks, turning a loss into a case study in effective response. The downside case: the incident report reveals deeper credential compromise, withdrawals stay suspended, and the $464 million fund is tested by further outflows - at which point the story shifts from "hot-wallet breach" to "solvency stress."
The central judgment: Bitget's loss is a cyclical event with a structural lesson. The breach itself will likely be absorbed. What will not revert on its own is the shrinking half-life of the industry's freeze-and-recover defenses. Attackers are no longer trying to move faster than investigators; they are moving into assets investigators cannot freeze at all.
Bitget's cold wallets are safe - but the industry's warm confidence that stolen crypto can still be caught is the thing that just got breached.
Explore more exclusive insights at nextfin.ai.

