Skip to content

Bitget Hack Drains $352M From Hot Wallets, Withdrawals Halted

Bitget Hack Drains $352M From Hot Wallets, Withdrawals Halted

Short answer: On September 24, 2026, crypto exchange Bitget detected unauthorized transfers from its hot and warm wallets at 18:31 UTC and suspended all withdrawals. It first put the loss at about $351.6 million, then raised the figure to $387.5 million after on-chain tracing. Bitget says cold wallets and private keys were not compromised, deposits and trading kept running, and its User Protection Fund of about $464 million will cover the losses.

What happened

On the evening of Thursday, September 24, 2026, blockchain security firms flagged large outflows from wallets labeled as Bitget's, shortly before the exchange confirmed the incident. Bitget, based in the Seychelles and ranked by CoinGecko as the sixth-largest exchange with over $1.1 billion in daily volume, then laid out the basic facts:

  • Detection: its systems flagged multiple unauthorized transfers from a limited number of wallets at 18:31 UTC.
  • Size: the first estimate was $351.6 million. The next day Bitget raised it to $387.5 million after adding Zcash and Tron assets, stressing that the higher figure reflected classification, not further theft.
  • Assets and chains: ETH, XRP, BNB, AVAX, USDT, USDC and other tokens left across Ethereum, the XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Smart Chain and Base. The XRP loss was the largest on a single chain, and security firm Hacken said some bitcoin was moved as well.
  • Response: withdrawals were paused, the receiving addresses were flagged, Mandiant and SlowMist joined the investigation, law enforcement was notified and a recovery bounty was opened. Some chains froze the attacker's addresses.

The funds went to a fresh address that later started swapping part of the haul on-chain, according to The Block.

How the Bitget hack worked

A hot wallet is an exchange wallet kept online so withdrawals can be processed quickly; a cold wallet is kept offline. Bitget describes a three-tier setup, and only part of the hot and warm layers was hit. CEO Gracy Chen said the attacker compromised a critical backend system in the wallet infrastructure and spoofed transaction data so that the normal authorization process approved the transfers. In other words, the signing keys were not stolen; the system was tricked into using them. How the attacker got into that backend was still under investigation, and Chen later said the pattern was highly consistent with known North Korean hacking groups, without a formal attribution.

Part of BitgetStatus after the breach
Hot and warm walletsPartly drained
Cold wallets and private keysNot compromised, per Bitget
WithdrawalsSuspended pending security review
Deposits and tradingOperating; balances reported as accurate
Bitget Wallet (self-custodial app)Not affected; separate infrastructure

Who covers the losses?

Chen said the loss falls within the coverage of Bitget's User Protection Fund, which holds 5,500 BTC, worth about $464 million at the time. Bitget said the fund would cover all losses from the incident and promised to publish a plan for resuming withdrawals by 04:00 UTC on September 26. The breach followed the Liquid Network exploit earlier in September.

What it means for you

If you have funds on Bitget, the exchange says balances are intact, but you cannot move them out until withdrawals reopen. More general points:

  • Custody is the real risk. Coins on an exchange are an IOU from that exchange. A breach can freeze withdrawals even when the platform promises full coverage.
  • Keep only what you trade. Long-term holdings are safer in a wallet you control; an instant exchanger sends coins straight to your own address rather than holding them.
  • Watch for fake "refund" offers. Big hacks are followed by phishing that promises compensation or early withdrawals. Use only official Bitget channels.
  • Do not keep everything in one place. Splitting funds between your own wallet and more than one service limits how much a single outage or breach can freeze.

Key takeaways

  • Bitget detected unauthorized hot wallet transfers at 18:31 UTC on September 24, 2026.
  • The loss was estimated at $351.6 million, later revised to $387.5 million after tracing.
  • The attacker spoofed transaction data in a backend system; Bitget says private keys and cold wallets were safe.
  • Withdrawals were halted; a User Protection Fund of about $464 million is to cover losses.

To reduce how much of your crypto depends on someone else's security, read our crypto wallet security guide.

Frequently asked questions

How much was stolen in the Bitget hack?

Bitget first estimated $351.6 million taken from its hot and warm wallets on September 24, 2026, then revised the figure to $387.5 million after on-chain tracing added Zcash and Tron assets. It says the revision was not additional theft.

Is my money safe on Bitget after the hack?

Bitget says customer balances are accurate, cold wallets were untouched and its User Protection Fund, about $464 million, will cover all losses. Withdrawals were suspended while the breach was investigated.

Was Bitget Wallet affected by the hack?

No. Bitget says its self-custodial Bitget Wallet runs on separate infrastructure and was not affected; only custodial exchange wallets were hit.

← Blog

Read next