Bitget has paused withdrawals after unauthorized wallet transfers that it estimates affected $351.6 million. The exchange says it detected the incident at 18:31 UTC on September 24. Its notice says deposits and trading remain available, cold wallets are secure, and its protection fund covers the loss. Those are Bitget’s statements, not an independent verification of repayment. The attack method remains undisclosed. [1]
A balance is not the same as access
For a customer trying to withdraw, the immediate problem is the difference between a number on an account screen and the ability to move those assets elsewhere. A protection-fund assurance does not itself complete a withdrawal. Nor does a platform-wide pause establish that an individual customer’s password or recovery phrase was stolen.
The incident notice does not provide a confirmed reopening time. Treat this as a developing incident: check the current announcement before acting, rather than relying on a copied status message. A later restoration notice would change the withdrawal situation; it would not by itself explain how the unauthorized transfers happened.
Verify the messenger before following the recovery instructions
An exchange incident can make an unsolicited “support” message seem timely. That is a reason to verify the sender, not evidence that a Bitget impersonation campaign has already been observed in this case. A message promising to bypass a platform restriction is asking you to trust a different person with your account or funds.
Open the Bitget app you already use or type the official website address yourself. Bitget’s verification guide explains how to check a webpage, email address or social account with its official channel tool and report an unrecognized result. Do not reach that checker through the suspicious message itself. [2]

The selector in Bitget’s example matters: checking an email address and checking a website are different searches. A familiar display name or copied logo is not the item being verified. Even a channel check is not permission to disclose a secret or approve a transaction you do not understand.
If you already answered a suspicious message
Bitget’s scam-response guidance says its staff will not request passwords, two-factor codes or private keys. If you disclosed account credentials, change the password through the genuine service, review Device Management, remove unfamiliar sessions and secure the linked email account. Contact support through the app or Help Center, keeping screenshots and transaction IDs. Recovery is not guaranteed. [3]
If someone instead supplied a destination and told you to move crypto there, stop and establish who controls it. Our guide to verifying a crypto wallet before sending money explains why an address that exists on a blockchain is not proof of a trustworthy recipient.
The distinction to keep is simple: investigate personal account activity through the genuine service, and follow the exchange’s own incident updates for withdrawal availability. A stranger offering a shortcut cannot establish either.
References
- Bitget. Security notice: hot-wallet incident. September 24, 2026; accessed September 25, 2026.
- Bitget. How to verify official channels and report suspicious links. July 29, 2025; accessed September 25, 2026.
- Bitget. Steps to take after falling victim to a scam. January 17, 2025; accessed September 25, 2026.

