Bitget Wallets Drained of $180M in Suspected Exchange Hack
TREE NEWS reports: A fresh address pulled ETH, stablecoins, tokenized gold and AVAX out of Bitget-labeled hot and cold wallets over Thursday afternoon, in what on-chain analysts describe as a suspected hack worth more than $180 million. The exchange has not commented on the transfers.
What the On-Chain Trail Shows
The withdrawals were not routed through Bitget’s usual operational flows. Instead, a newly created address received a spread of assets — ether, dollar-pegged stablecoins, a tokenized gold product and Avalanche’s native token — in rapid succession. That pattern, moving multiple asset classes out of both hot and cold storage into a single fresh wallet, is characteristic of a coordinated exploit rather than routine treasury management or a scheduled migration.
The inclusion of tokenized gold is notable. It signals that the attacker took whatever was liquid and bridgeable, not just majors, which suggests either automated sweeping scripts or a prepared set of destination venues for converting assets quickly.
Why This Matters Beyond One Exchange
Bitget is a top-20 venue by derivatives volume and a major player in copy trading and emerging-market retail flows. A nine-figure loss at an exchange of that scale lands in a market that is already thin on margin for confidence shocks. Two implications stand out:
- Custody risk is back at the center of the narrative. Every large exchange breach reopens the debate over proof-of-reserves, segregated cold storage and whether “cold” wallets are truly air-gapped in practice.
- Contagion channels are narrower but real. Unlike the 2022 cycle, much of Bitget’s balance sheet is not interwoven with large DeFi lending markets, which limits direct protocol exposure. The bigger risk is a withdrawal cascade if users front-run a solvency question.
Stablecoin and tokenized-gold outflows also give the attacker a fast path to fiat-adjacent liquidity, making recovery unlikely without centralized exchange cooperation and issuer-level freezing. Tether and other issuers have historically blacklisted addresses tied to major exploits, and that playbook will likely be tested here.
The Regulatory Overhang
The timing is awkward. Exchange security failures feed directly into licensing reviews, MiCA compliance assessments and enforcement priorities in multiple jurisdictions. A confirmed breach of this size strengthens the argument for mandatory reserve attestation and stricter key-management standards — and gives critics of offshore venues fresh ammunition.
What to Watch Next
Three signals will determine how this resolves: whether Bitget confirms the loss and publishes reserve data, whether issuers freeze the moved stablecoins, and whether the attacker begins laundering through mixers or bridges. If the funds sit still, it may indicate negotiation. If they move, expect a fast, public forensic chase — and another round of hard questions about how safely exchanges actually hold customer assets.




