You open your exchange app. There’s a red banner. Withdrawals paused.
That’s the moment thousands of Bitget users faced this week. No warning. No countdown. Just a notification that your money is technically “safe,” but you can’t touch it.
Here’s what actually happened.
A newly created wallet started buying ETH in minutes, funded straight from Bitget’s hot wallet. Trackers noticed fast. Within an hour, over $350 million had moved across multiple chains into one address. The attacker didn’t need your password or seed phrase. They exploited the exchange’s own systems.
This is the part beginners miss. You think keeping funds “on the exchange” is safer than managing your own wallet. Sometimes it’s the opposite. Hot wallets exist so exchanges can process withdrawals fast, which also makes them a live target 24/7.
“Cold storage isn’t a marketing term. It’s the only wall between your money and an attacker’s laptop. If an exchange can’t clearly show you which wallets hold your funds, that’s your answer.”
Bitget says cold wallets stayed untouched and a $464M fund covers the damage. That’s reassuring, but it doesn’t erase the lesson. Every centralized platform is one system flaw away from a headline like this one.
Smart traders don’t panic-sell or blindly trust reassurance tweets. They check facts, then quietly reduce exposure to any single point of failure.