Bitget, the Seychelles-based cryptocurrency exchange, has confirmed that attackers moved an estimated $351.6 million in digital assets out of parts of its hot and warm wallet infrastructure on September 24, 2026. If the figure holds, it would be the largest reported exchange hack of 2026 so far.
The exchange has paused all withdrawals while deposits and trading continue, and Chief Executive Officer (CEO) Gracy Chen said customer balances are accurate and the company’s reserve fund will absorb the loss.
What Bitget Has Confirmed
Bitget’s security systems detected unauthorized transfers at 18:31 Coordinated Universal Time (UTC) on September 24, which was 2:31 p.m. US Eastern Time, according to the security notice Chen posted on X at 21:30 UTC. The same statement went live on Bitget’s support center at the same time.
Bitget stores customer assets across three wallet tiers. Hot wallets stay connected to the internet so the exchange can process withdrawals quickly. Warm wallets sit in the middle, holding reserves that refill hot wallets under tighter controls. Cold wallets are kept offline and hold the bulk of assets. Chen said the breach was limited to portions of the hot and warm layers and that cold storage remained secure.
According to the notice, Bitget activated its emergency response within minutes, flagged the receiving addresses, and notified law enforcement and on-chain security firms. The company promised hourly updates and a full report covering the root cause and corrective actions within 24 hours.
“Every dollar and every decision will be accounted for, transparently and in full,” Chen wrote.
How the Attackers Got In
In her first notice, Chen declined to speculate on the attack vector. At 00:43 UTC on September 25, she posted a second update saying the security team had traced the breach to a critical backend system inside the wallet infrastructure. Attackers used that system to spoof transaction data, which then passed through Bitget’s standard authorization process.
Chen ruled out a private key compromise. She said loss containment was complete and no further unauthorized transfers were possible, while the exact intrusion method remained under review.
In a later livestream, Chen added that the attackers did not forge customer withdrawal requests and did not obtain private keys for any cold, hot or warm wallet. In practical terms, the cryptography protecting the wallets held, but the internal system that tells those wallets what to sign was hijacked. This makes the incident closer to a signing pipeline breach than a classic key theft.
Chinese-language accounts of the livestream reported that Chen described the entry point as a compromised third-party tool used in Bitget’s operations. Bitget’s written statements have not confirmed that detail.
What Was Taken
The first public estimates understated the loss. On-chain monitors initially counted between $170 million and $192 million leaving Bitget-labeled wallets. Analytics firm Bubblemaps tracked 15 transfers worth about $192 million across seven assets, with Ether (ETH) making up 44.4% of that early slice.
The gap closed once the XRP Ledger was counted. SlowMist’s tracking tool MistTrack tagged seven XRP Ledger addresses holding about 102,926,478 XRP, a leg that most Ethereum-focused dashboards missed in the first hours. On-chain analytics account Lookonchain then published a nine-asset breakdown totaling about $356.86 million at the prices it used, close to Bitget’s internal figure.
| Asset | Amount | Value (Lookonchain) |
|---|---|---|
| XRP | 102,926,478 | $157.48 million |
| Ether (ETH) | 31,890 | $85.75 million |
| Tether (USDT) | 34,751,168 | $34.75 million |
| USD Coin (USDC) | 21,056,725 | $21.06 million |
| USDT0 | 19,668,852 | $19.67 million |
| Tether Gold (XAUt) | 3,000 | $12.82 million |
| BNB | 12,719 | $9.88 million |
| Avalanche (AVAX) | 821,012 | $8.38 million |
| Tron (TRX) | 20,593,377 | $7.07 million |
USDT0 is a cross-chain version of Tether’s USDT stablecoin, and XAUt is a token backed by physical gold. Chen said the affected networks included Ethereum, the XRP Ledger, Avalanche, BNB Smart Chain and Arbitrum.
During the livestream, Chen said Bitget’s official count remained $351.6 million across 19 attacker transfers, all from hot and warm wallets. She said the stolen stablecoins and related tokens were converted into roughly $170 million worth of ETH. Stablecoin issuers such as Tether and Circle can freeze tokens on their own networks, while ETH has no central issuer that can block it. Blockchain explorer Etherscan has labeled at least one receiving cluster “Bitget Exploiter 1.”
Who Bitget Believes Is Behind It
Chen told a live question-and-answer session that investigators found IP addresses matching virtual private network (VPN) patterns used by a group from the Democratic People’s Republic of Korea (DPRK), or North Korea, and that the activity resembled earlier North Korean operations. She said Bitget does not believe the breach was an inside job and stressed that the attribution is not yet certain.
On-chain researcher Specter separately argued that the fund flows overlap with an earlier theft cluster tied to the Lazarus Group, the North Korean state-linked hacking unit blamed for a string of major crypto thefts, including the February 2025 Bybit hack. Bitget has not confirmed that link. For now, the North Korea attribution stands as a preliminary assessment from the CEO rather than a completed forensic finding.
Can the Protection Fund Cover the Loss?
Bitget launched its User Protection Fund in 2022 with a $300 million commitment. The fund is a corporate reserve meant to compensate users after extreme events such as hacks. Chen said it held more than $464 million at the time of the notice.
A $351.6 million payout would consume about 76% of that pool and leave roughly $112 million, assuming the full balance is liquid and available. Chen also said Bitget holds more than $1 billion in its own capital, and pointed to Bybit’s decision to absorb a loss of about $1.5 billion in February 2025 and continue operating.
Bitget’s August 2026 protection fund report showed an average valuation of about $382 million, a high of $441.5 million, a low of $345.3 million, and 5,500 Bitcoin (BTC) inside the pool. Because much of the fund is held in BTC, its dollar value moves with the Bitcoin price.
The fund is separate from Bitget’s Proof of Reserves (PoR), a periodic snapshot showing whether an exchange’s holdings exceed customer balances. Bitget’s September 2026 PoR update, Issue No. 46, reported a 135% aggregate reserve ratio and expanded coverage from four assets to 19. PoR measures solvency at a single point in time. The hack tests the protection fund, not the reserve ratio.
Two limits apply. The protection fund has not been publicly audited in the way a bank deposit insurance scheme would be. And coverage of the loss does not reopen withdrawals. Users can see correct balances but still can’t move funds until Bitget completes its backend review.
What Others Are Saying
Aneirin Flynn, CEO of cybersecurity firm FailSafe, said the breach destroys the illusion that major exchanges have solved hot-wallet security, in comments carried by Bloomberg. He added that even with the loss covered, a breach of this size damages institutional confidence in crypto infrastructure.
Xie Jiayin, Bitget’s head of Greater China, said the exchange has hired a third-party security team to run an independent forensic investigation. Several teams are verifying fixes, confirming the attack path and supporting law enforcement, and withdrawals will resume once all potential risks are removed, he said. Bitget Wallet, the company’s separate self-custody wallet app, said it was not affected by the exchange incident.
A Costly Month for Crypto Security
The Bitget breach adds to a heavy September. Earlier this month, about $320 million in Bitcoin was drained from a wallet used by the Liquid Network, according to the same Bloomberg report. Industry tallies show that adding Bitget’s loss pushes September’s reported crypto thefts above $684 million, surpassing April’s $646.9 million, which was driven by the Drift and KelpDAO exploits.
Bitget was already managing fallout from another incident this week, having paused FET deposits after the SingularityNET bridge exploit widened. The exchange ranked as the sixth-largest by trading volume on CoinGecko near the time of the notice, handling more than $1.1 billion in daily trades. It is also winding down its services in Japan by December 31.
The incident remains far smaller than the Bybit theft of February 2025, still the largest exchange hack on record.
Where Things Stand for Users
At the time of writing, Bitget reports the following status:
- Account balances: accurate, according to Bitget
- Deposits: open
- Spot and derivatives trading: open
- Withdrawals: paused
- Cold wallets: not affected, according to Bitget
- Law enforcement and on-chain firms: notified
- Full incident report: due before about 21:30 UTC on September 25
Chen said withdrawals will stay closed until the compromised backend path is fully secured, since reopening early could expose the exchange to a second loss. She indicated restoration could take hours or days but not weeks.
Users should treat only the @GracyBitget and @bitget accounts on X as official channels and ignore any unofficial “emergency withdrawal” links, which are a common phishing tactic after major hacks.
What Comes Next
Three developments will shape how this incident is judged: the confirmed reopening time for withdrawals, an asset-by-asset account of any recovered or frozen funds, and whether independent security firms corroborate the North Korea attribution. The written root cause report will be the first document to answer those questions on the record.
This is a developing story. The Crypto Times will update this report as Bitget publishes its incident findings and as withdrawals, recoveries, and attribution are confirmed.
Also Read: Duelbits Hit by Suspected $4.3M Crypto Hack as Funds Shift to ETH
