Bitget Wallets Flagged in Suspected $170M Security Breach

More than $170 million in crypto reportedly moved from Bitget-linked wallets to one unlabelled address before being swapped into ETH, raising fresh questions about a possible security breach at the exchange.
The claim remains unconfirmed. Neither the reported attack method nor the final loss total had been established at publication. The Block said it had contacted Bitget to ask whether the transfers were tied to a security incident and whether withdrawals had been paused, but no public explanation had been identified at publication.
The alerts concern wallets associated with Bitget’s exchange infrastructure; they do not establish a compromise of the separately branded Bitget Wallet self-custody app.
What the on-chain trail reportedly shows
The Block reported also that on-chain data appeared to show more than $170 million moving from Bitget hot and cold wallets to one address over roughly an hour. The transfers reportedly included ETH, USDT, USDC, AVAX and BNB.
The initial reports identify both hot and cold wallets, rather than a single routine transfer.
The recipient did not appear to be labelled as belonging to Bitget or as part of its known wallet structure.
The reported conversions into ETH are why the movements drew closer scrutiny.
Wu Blockchain said, citing MLM monitoring, that three hot wallets and one cold wallet were suspected of being involved. It linked the activity to 0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee and stressed that the attack vector and total losses remain unconfirmed.
Withdrawal Complaints Create a Separate Question
The Block also noted social-media posts and online reports from users who said they were experiencing withdrawal problems. Those claims do not establish that Bitget has suspended withdrawals, and they do not prove that any service issue is connected to the flagged wallet movements.
They nevertheless create a second question for the exchange. If the transfers were authorised wallet management, Bitget can identify the receiving address and explain whether users are facing an unrelated operational delay. If the two developments are connected, a public response becomes more urgent.
Why $170 million moved does not yet mean $170 million was stolen
Exchanges regularly shift large balances between hot wallets, cold storage and liquidity-related addresses. A large transfer can look alarming on a blockchain explorer while still being authorised wallet management.
The reported pattern here is more difficult to dismiss than a single transfer because assets from several wallets reportedly reached one fresh address that was not identified as Bitget-controlled and then entered swaps. Even so, that is evidence worth investigating, not proof of theft.
The missing fact is simple: does Bitget control the receiving address?
If the exchange identifies it as an internal operational wallet, the breach theory weakens sharply. If the ETH continues through bridges, mixers or wallets unrelated to Bitget, the case for an unauthorised outflow becomes much stronger.
Three answers matter more than the first loss estimate
Is the destination address controlled by Bitget?
This is the fastest way to separate internal wallet management from a possible compromise. The destination address is publicly visible; only Bitget can say whether it controls it.
Were the transfers authorised?
Bitget needs to clarify whether the wallets acted through normal signing procedures or whether access to any part of its infrastructure was compromised. Until then, claims about the method behind the transfers remain speculation.
Are users or platform services affected?
The on-chain reports do not establish that customer balances, deposits, withdrawals or trading services have been affected. A public update on those points would matter more to users than another revised estimate of the outflows.
What would settle the question
A formal Bitget statement is the next important development, but independent tracing will matter too. Security firms can follow whether the ETH remains in the recipient wallet, is moved through bridges, reaches exchange deposit addresses or enters recognised laundering routes.
That evidence will determine whether the story remains a suspicious sequence of wallet movements or becomes a confirmed exchange security incident. Until then, the $170 million figure should be treated as reported on-chain volume, not a final accounting of losses.
This article is provided for informational purposes only and does not constitute financial or investment advice. Wallet labels and on-chain estimates can change as new information emerges.










