
AI-generated summary
Bitget is a cryptocurrency exchange offering spot and derivatives trading. Sygnum is a Swiss-based digital asset bank providing custody and trading services for institutional clients. The User Protection Fund is Bitget's reserve designed to cover losses from platform-wide security incidents.
Bitget says about $387.5 million in assets was transferred to attacker-controlled addresses during a Sept. 24 wallet breach. Its withdrawals remained suspended in notices issued through Sept. 25, even as deposits and trading continued.
On the day of the breach, Sygnum announced that Bitget's institutional clients could trade against collateral held at the Swiss bank instead of placing that collateral in Bitget's wallets.
The juxtaposition puts a question behind the promise of off-exchange custody: which assets sit beyond an exchange wallet breach, and what still depends on the exchange when trading or withdrawals are disrupted?
Sygnum's route is for eligible institutional clients who onboard with its bank. The companies have not disclosed how many Bitget clients use it or whether any Sygnum-held collateral was connected to this incident.
A breach alongside a new custody route
Bitget said its systems detected unauthorized transfers at 18:31 UTC on Sept. 24. Its initial notice placed the affected funds at about $351.6 million and said the breach reached portions of its hot and warm wallet layers, while cold wallets remained secure.
In a Sept. 25 update, Bitget raised the estimated assets transferred to attacker-controlled addresses to about $387.5 million after including Zcash and TRON transfers in a fuller accounting. It said the revision did not represent a fresh wave of unauthorized transfers.
The exchange said it identified and remediated the underlying vulnerability and contained the incident. Mandiant and SlowMist were assisting its investigation, according to Bitget.
Bitget's withdrawal notice said withdrawals were temporarily unavailable while deposits and trading stayed operational. The exchange promised to announce a withdrawal plan or status by Sept. 26 at 04:00 UTC.
For a customer with an ordinary Bitget balance, a displayed balance and the ability to trade do not by themselves provide an exit while withdrawals are paused.
Sygnum said Bitget's institutional clients can use its Protect service for spot and derivatives trading while pledged collateral remains in Sygnum custody in Switzerland. Bitget mirrors the balance as trading margin.
The bank lists Bitcoin, Ethereum, stablecoins and US Treasuries among the eligible collateral. Its published process requires a client to onboard with Sygnum, sign a contractual framework, open a Protect portfolio, and pledge assets before receiving exchange margin.
Under Sygnum's description, the collateral is held in segregated accounts off the bank's balance sheet and is bankruptcy remote under Swiss banking law. Keeping the pledged assets at the bank reduces direct custody exposure to Bitget's own wallets.
It also addresses the concern that if an exchange faces financial distress, the collateral is intended to remain outside its estate. These are features of the arrangement as Sygnum describes it.
The announcement is dated Sept. 24 but does not state when Bitget client access became operational, nor that the integration preceded the 18:31 UTC breach or arose in response to it, nor does it identify any Bitget client who had completed onboarding, give a Bitget-specific collateral balance, or say whether Sygnum-held assets were involved in the incident.
Figures in the release for Protect's total assets and the trading-volume share of all its integrated exchanges do not measure Bitget client uptake.
The limits of custody and a separate backstop
Protect's public page advertises flexible collateral top-ups and withdrawals. It does not publish the Bitget-specific contract that would determine when pledged assets can be released, how positions are settled, or what happens to margin if Bitget pauses its withdrawal service.
A trading balance mirrored at an exchange is also not the same thing as an ordinary customer's withdrawable exchange balance.
Trading still depends on the exchange's order, margin, and settlement processes even when the pledged assets are held elsewhere. Segregated custody can reduce exposure to theft from Bitget-held wallets and to Bitget insolvency, as Sygnum describes.
The public materials do not establish that a Protect client can instantly reclaim pledged collateral during an exchange disruption, or that an exchange's operational problems could never delay settlement. They equally do not show that any Sygnum client is blocked from its collateral in this incident.
The arrangement creates an optional boundary between institutional collateral and Bitget wallet custody.
For users holding assets on Bitget, the exchange pointed to its User Protection Fund. In its initial Sept. 24 notice, Bitget said the fund was worth more than $464 million and that the then-estimated $351.6 million incident fell within its coverage.
Its public fund page lists 5,500 BTC and says users may claim for qualifying losses from platform-wide events beyond their own actions or trading behavior. Bitget reserves the right to assess and investigate claims.
The dollar value of a Bitcoin-denominated fund moves with Bitcoin's price. Bitget's report for August put the fund's monthly average at $382 million and its month-end value near $432 million on the same 5,500 BTC holding.
Bitget also said it froze some affected assets through work with industry partners, but its Sept. 25 update did not quantify the frozen or recovered amount. The next measurable tests are a confirmed withdrawal timetable, a firmer loss and recovery accounting, and the terms of any fund disbursement.
For the custody comparison, the missing facts are Bitget-specific Protect uptake and the contract governing collateral release and settlement when the exchange is under strain.
AI outlook — possibilities, not facts
Bitget will resume withdrawals within the next 7 days following security remediation
Likely · Within days
More institutional clients will consider Sygnum's Protect service or similar off-exchange custody solutions
Possible · Within weeks

The US Department of Justice is pursuing civil forfeiture of $84.2 million that flowed through accounts used by Montana-based payments firm Capstone Ltd. to process Tether transactions. The complaint alleges Capstone operated as an unlicensed money transmitter in multiple states, misrepresented itself to banks as an IT services company, and had ties to EQIBank, a Dominica-licensed digital bank. Tether confirmed EQIBank handled its USDT transfers but denied knowledge of Capstone's alleged misconduct, noting its exposure is under 0.034% of group assets.

Strategy announced a proposal to pay daily dividends on four preferred share series used in its Bitcoin financing strategy, aiming to accelerate cash flow to investors without altering dividend rates or securities' economics, with effectiveness dependent on investor valuation of timing and pending approvals.

Strategy is seeking shareholder approval to switch four preferred stocks, including STRC, to daily dividend payments without changing dividend rates or total payout. The proposal follows Strive's earlier move to daily dividends and aims to address leverage-driven price volatility in STRC, which fell below $100 earlier this year due to unexpected market leverage.

MicroStrategy aims to transition four preferred share classes to daily dividend payments to lower volatility and increase liquidity. Shareholders are scheduled to vote on the proposal on October 28, with potential implementation beginning in November.

Morgan Stanley will serve as a strategic partner at the upcoming NEXTPredict summit in New York, marking the first public institutional bank engagement with the prediction market sector as firms evaluate the industry's potential for hedging and forecasting.

SEC Commissioner Hester Peirce is urging financial firms to move away from mass data collection, proposing attribute-based digital credentials to reduce privacy risks after high-profile breaches at companies like Coinbase and Revolut.