A crypto exchange can build better wallets, stricter withdrawal controls and more sophisticated monitoring. What it cannot realistically promise is that operational risk will ever reach zero.
Bitget is now confronting what happens after that assumption becomes real.
The exchange said unauthorized transfers affected approximately $351.6 million across portions of its hot and warm wallet infrastructure on September 24. Its cold wallets were not compromised, while withdrawals were temporarily suspended as the company began a security review.
The size of the breach would be enough to make the incident significant on its own. But Bitget entered it with something unusual already sitting outside its normal customer reserves: a protection fund worth more than $464 million.
Bitget says that fund is large enough to absorb the entire loss without passing it on to customers.
If that happens as announced, the episode will illustrate a distinction that is becoming increasingly important as crypto exchanges grow: preventing a loss and surviving one are two different security problems.
The First Line of Defense Tries to Stop the Loss
Most exchange security is designed around reducing the probability that assets can be stolen in the first place.
Cold storage limits online exposure. Wallet architectures separate different levels of access. Monitoring systems look for abnormal behavior, while internal controls determine when and how assets can move.
Bitget’s incident shows both the value and the limitations of that model.
The unauthorized transfers were contained to portions of its hot and warm wallet layers, according to the company. Assets held in cold wallets remained unaffected.
That separation limited the scope of the breach, but it did not prevent hundreds of millions of dollars from leaving the exchange’s infrastructure.
The investigation into exactly how that happened is still underway. Bitget has said it will publish a root-cause analysis and corrective measures, and that it will not speculate on the attack vector before the investigation is complete.
Whatever the technical explanation turns out to be, the financial problem already exists.
And that requires a different kind of defense.
Resilience Starts Where Prevention Fails
Bitget did not create its Protection Fund in response to this week’s attack.
The exchange established it in 2022 with an initial size of $300 million and has committed to keeping its valuation above that threshold. The fund currently holds 5,500 BTC, making its dollar value fluctuate with the price of Bitcoin.
In August, it was worth an average of $382 million. Its valuation ranged from roughly $345 million to $441.5 million during the month.
That structure suddenly matters much more when compared with a $351.6 million security incident.
The fund is no longer simply a number published in a monthly transparency report. If Bitget uses it as announced, capital accumulated before the breach will be used to absorb a loss after technological controls failed to prevent it.
That is financial resilience rather than cybersecurity.
The distinction matters because an institution can be compromised without necessarily becoming insolvent or forcing customers to absorb the resulting hole. The outcome depends partly on what financial resources were available before the incident occurred.
For a large exchange, security therefore has a balance-sheet dimension.
Proof of Reserves Answers a Different Question
Crypto has already spent several years developing another financial safeguard: Proof of Reserves.
Bitget reported a 135% total reserve ratio in its September disclosure across 19 supported assets. The system is intended to give users visibility into whether corresponding customer balances are backed by assets held by the platform.
A protection fund serves a different purpose.
Proof of Reserves asks whether customer assets are backed.
A protection fund addresses what happens when an unexpected event creates a loss.
Confusing the two can obscure the actual risks an exchange is trying to manage.
An exchange could theoretically have adequate reserves and still suffer a security breach. It could also maintain a protection fund without demonstrating that customer liabilities are fully backed.
They are separate layers responding to separate failure modes.
The Bitget incident is an unusually large real-world test of how those layers interact.
A Protection Fund Is Not Deposit Insurance
There is also a limit to how far comparisons with traditional finance should go.
Bitget’s Protection Fund is maintained by the company itself. It is not government-backed deposit insurance, and it should not be treated as equivalent to bank regulatory capital or systems such as the FDIC in the United States.
Its value also introduces another risk.
Because the fund holds 5,500 BTC, its dollar-denominated protection rises and falls with Bitcoin. The same holdings that averaged $382 million in August moved across a range of almost $100 million during that month.
That creates an unusual relationship between the risk being protected and the asset providing the protection.
A sharp crypto-market decline could reduce the dollar value of the fund at precisely the moment broader market stress increases operational or counterparty risks across the industry.
The existence of capital therefore matters, but so do its composition, liquidity and governance.
Those questions become more important as protection funds begin facing incidents large enough to consume meaningful portions of their resources.
Exchanges May Need to Be Judged by How They Fail
No protection fund makes a $351.6 million breach a security success.
Bitget still needs to establish how the unauthorized transfers occurred, why existing controls failed to stop them and what changes will prevent the same vulnerability from being exploited again.
But an exchange’s risk profile cannot be measured only by whether something eventually goes wrong.
At sufficient scale, another question becomes unavoidable: what happens next?
Banks are expected to hold capital partly because losses cannot always be prevented. Insurers maintain reserves because claims will occur. Clearing infrastructure is designed around the possibility that participants can default.
Crypto exchanges operate under different regulatory structures, and their protection mechanisms are far less standardized. But the underlying economic problem is increasingly similar.
Large financial platforms need not only defenses against failure, but resources that allow them to remain functional after failure occurs.
Bitget says it already had more than enough capital set aside to cover this breach. Whether the fund performs exactly as promised — and how it is replenished afterward — will now matter as much as the number that appeared on its balance before the attack.
For crypto exchanges, the next stage of security may therefore be measured by more than how difficult they are to breach.
It may also be measured by how much damage they can absorb when someone eventually succeeds.
