Key Takeaways
The keys were not stolen. Bitget says attackers used stolen internal credentials to fake transaction data and push fraudulent transfers through the exchange's own approval process. Private keys and cold wallets were not compromised.
Wallet tiers limit damage, but do not remove risk. Hot and warm wallets hold a small share of exchange funds for daily withdrawals. That design capped the loss, but it did not stop it.
A protection fund is a company promise, not insurance. Bitget says its User Protection Fund, worth more than $464 million, covers the loss. That is helpful, but it is not a government guarantee.
What Happened: A Plain-Language Timeline
On September 24, 2026, crypto exchange Bitget detected unauthorized transfers leaving its hot and warm wallets. Bitget first estimated the loss at about $351.6 million. After further on-chain tracing, it revised the figure to about $387.5 million, and said the higher number reflects transfers on Zcash and Tron that were identified later, not new theft after the attack was contained.
The assets moved across several networks, including Ethereum and other EVM chains, the XRP Ledger, Zcash and Tron. The largest single asset was XRP, reported at roughly 102.9 million XRP (about $157.5 million at the time).
Date and time (UTC) | What happened |
|---|---|
Sept 24, 18:31 | Bitget's security systems flag unauthorized transfers from some hot wallets |
Sept 24 | Blockchain analytics firms spot large outflows; over $170 million is reportedly swapped into ETH |
Sept 24 | Bitget pauses withdrawals. Deposits and trading stay open |
Sept 25 | CEO Gracy Chen says private keys were not stolen and the protection fund covers the loss |
Sept 25 | Chen says the attack pattern is "highly consistent" with known North Korean groups. This is not an official government attribution |
By Sept 28 | Loss estimate revised to about $387.5 million after further on-chain tracing |
Sept 28, 08:00 | Bitcoin withdrawals resume in a phased rollout |
Sept 29 to Oct 2 | ETH, then USDT, then remaining assets, fiat and P2P scheduled to return |
Figures are based on Bitget statements and widely reported on-chain data. The investigation is ongoing and numbers may change.
The Key Detail: No Private Keys Were Stolen
Most people imagine a crypto hack as someone stealing a secret key. This attack worked differently.
According to Bitget, the attackers exploited a vulnerability in a third-party security product to obtain high-level internal credentials. With that access, they compromised a critical backend system in the wallet infrastructure, spoofed transaction data, and triggered the exchange's own authorization process. The system then signed the transfers as if they were legitimate.
Think of it like a bank vault. The thieves did not copy the key. They forged the paperwork, and the bank's own staff opened the vault for them.
The lesson: strong key storage is not enough. The systems that decide what gets signed matter just as much as the keys that do the signing.
How Exchange Custody Works: Hot, Warm and Cold Wallets
When you deposit crypto on a centralized exchange, your coins usually go into shared wallets the exchange controls. Your account balance is an entry in the exchange's internal database. Most large exchanges split their holdings into three tiers.
Wallet tier | Connection | Main job | Speed | Risk level |
|---|---|---|---|---|
Hot wallet | Always online | Pays out everyday withdrawals automatically | Seconds to minutes | Highest |
Warm wallet | Partly connected, more approvals needed | Refills the hot wallet and moves extra deposits toward storage | Minutes to hours | Medium |
Cold wallet | Offline, keys kept off the internet | Stores most reserves long term | Hours to days | Lowest |
The goal is to keep only a small working balance online. If the hot layer is breached, most funds should still sit safely in cold storage. That is exactly what Bitget says happened: the hot and warm layers were hit, and the cold wallets were not.
For individual users, the same logic applies. A mobile or browser wallet is a hot wallet. A hardware wallet that signs transactions offline is a form of cold storage.
What a Protection Fund Is (and What It Isn't)
Bitget's User Protection Fund is a reserve the company set aside to cover user losses from events like hacks. BleepingComputer reported it holds about 5,500 BTC, valued at more than $464 million when the incident was disclosed.
A protection fund IS | A protection fund IS NOT |
|---|---|
A reserve owned and managed by the exchange | Government deposit insurance, such as FDIC coverage for US bank accounts |
A public signal that the company plans to absorb losses | A legal guarantee that every user is covered in every scenario |
Often held in crypto, such as BTC | A fixed dollar amount, since its value moves with market prices |
Helpful in a contained incident | A replacement for audits, strong controls and proof of reserves |
Because Bitget's fund is held in bitcoin, its dollar value rises and falls with BTC. It is also worth noting that the revised $387.5 million loss was published after the $464 million fund figure was first stated. Users should read these funds as a helpful backstop, not a certainty.
Why Exchanges Pause Withdrawals
A withdrawal pause can feel alarming, but it is a standard emergency step. Exchanges pause for several practical reasons:
Stop further losses. If the approval system is compromised, every new withdrawal could be another fake one.
Find the attack path. Engineers need time to identify and close the vulnerability.
Reconcile balances. The exchange must confirm what was taken and that user account records are correct.
Work with partners. Stablecoin issuers, blockchain foundations and other exchanges can sometimes freeze stolen funds, and Bitget reported some assets were frozen.
A pause is a warning sign worth taking seriously, but it is not proof of insolvency. What matters is how long it lasts and how clearly the exchange communicates. Bitget restored withdrawals in phases, starting with Bitcoin, and said the schedule applied equally to all users.
Bitget vs Bybit: Two Attacks on the Approval Process
The Bitget case looks similar to the February 2025 Bybit hack, the largest crypto theft on record. In both cases, attackers did not break the cryptography. They manipulated what the signing system believed it was approving.
Factor | Bybit (Feb 21, 2025) | Bitget (Sept 24, 2026) |
|---|---|---|
Amount | About $1.46 billion, often rounded to $1.5 billion | About $387.5 million (revised from $351.6 million) |
Wallet affected | ETH multisig cold wallet, during a routine transfer to a warm wallet | Parts of hot and warm wallet layers |
Method | Malicious code in the Safe{Wallet} interface showed signers a normal transaction while changing what they signed | Stolen credentials let attackers spoof transaction data and trigger internal approvals |
Private keys stolen? | No | No, according to Bitget |
Entry point | A compromised developer machine at a third-party wallet provider | A vulnerability in a third-party security product |
Attribution | FBI attributed it to North Korea's TraderTraitor group | CEO cited patterns consistent with North Korean groups; not officially confirmed |
Two lessons stand out. First, cold storage is only as safe as the process around it. Bybit's funds were in cold storage, but the attack struck during a transfer. Second, third-party tools are a major weak point. Both incidents started outside the exchange's own code.
Exchange Risk Checklist for Users
You cannot audit an exchange's backend. You can reduce how much an incident affects you.
Keep only what you trade on exchanges. Move long-term holdings to a wallet where you control the keys.
Check for proof of reserves. Look for regular, independently reviewed reports. Bitget reported a reserve ratio of 127%, but self-reported figures deserve scrutiny.
Read the protection fund terms. Know its size, what asset it holds, and what it covers.
Spread risk. Avoid keeping everything on a single platform.
Enable strong account security. Use an authenticator app or security key, withdrawal address allowlists and anti-phishing codes.
Watch official channels only. During incidents, scammers post fake "refund" links. Use the exchange's verified website and accounts.
Do not panic-trade. Fast decisions during a pause often come from rumors, not facts.
Keep records. Save balance screenshots and transaction IDs in case you need to file a claim.
Want to control your own keys? Follow our Web3 Wallets & Self-Custody Security 2026: Ledger, OneKey, Exodus & Guarda
FAQ
Did Bitget users lose money in the hack?
Bitget says user account balances are unaffected and its User Protection Fund covers the loss. The investigation is ongoing, so users should follow official updates.
What is the difference between a hot wallet and a cold wallet?
A hot wallet is connected to the internet for fast transfers. A cold wallet keeps private keys offline, which makes remote theft much harder but transfers slower.
What is a warm wallet?
A warm wallet sits between hot and cold storage. It is partly connected, needs more approvals, and is used to refill hot wallets and move excess funds to cold storage.
Is an exchange protection fund the same as insurance?
No. It is a reserve owned by the exchange. Its value can change, and it is not a government deposit guarantee.
Was the Bitget hack worse than the Bybit hack?
No. Bybit lost about $1.46 billion in 2025, roughly four times more. Both attacks manipulated the approval process instead of stealing private keys.
Related Terms
Hot Wallet: A crypto wallet connected to the internet, built for fast and frequent transactions.
Cold Wallet: A wallet that keeps private keys offline to reduce the risk of remote theft.
Private Key: A secret number that proves ownership of crypto and authorizes transactions from an address.
Multisig Wallet: A wallet that needs approval from several keys before a transaction can be sent.
Proof of Reserves: A report that shows an exchange holds enough assets to cover customer balances.
Sources
CoinDesk, "Bitget's $352 million hack happened via spoofed transfers, not private keys, CEO Gracy Chen says" (Sept 25, 2026): https://www.coindesk.com/markets/2026/09/25/bitget-s-usd351-million-hack-happened-via-spoofed-transfers-not-private-keys-ceo-gray-chen-says
BleepingComputer, "Hackers steal $351.6 million in Bitget crypto exchange hack" (Sept 2026): https://www.bleepingcomputer.com/news/security/hackers-steal-3516-million-in-bitget-crypto-exchange-hack/
SecurityWeek, "North Korea Suspected in $351 Million Bitget Crypto Heist" (Sept 2026): https://www.securityweek.com/north-korea-suspected-in-351-million-bitget-crypto-heist/
Bitcoin.com News, "Bitget Restarts Bitcoin Withdrawals as $388M Hack Investigation Widens" (Sept 28, 2026): https://news.bitcoin.com/exchanges/bitget-restarts-bitcoin-withdrawals-388m-hack-investigation-widens/
Cointelegraph, "Bitget Restores Bitcoin Withdrawals After $388M Hack" (Sept 28, 2026): https://cointelegraph.com/news/bitget-btc-withdrawal-hacker-eth-swap-thorchain
Blockhead, "Bitget Loses $351.6 Million in Hot Wallet Breach, Rules Out Private Key Compromise" (Sept 25, 2026): https://www.blockhead.co/2026/09/25/bitget-loses-351-6-million-in-hot-wallet-breach-rules-out-private-key-compromise/
The Hacker News, "Bybit Hack Traced to Safe{Wallet} Supply Chain Attack Exploited by North Korean Hackers" (Feb 27, 2025): https://thehackernews.com/2025/02/bybit-hack-traced-to-safewallet-supply.html
Communications of the ACM, "Behind the Bybit Crypto Theft": https://cacm.acm.org/news/behind-the-bybit-crypto-theft
More Reading
Bitget Hot Wallet Hack Explained: What It Teaches About Exchange Security
The Biggest Crypto Exchange Hacks in History: From Mt. Gox to Bybit
How to Get Started on Robinhood Chain: A Complete Beginner's Guide
How to Find an Old Crypto Wallet Using Records You Still Have
How RugCheck Works: A Beginner's Guide to Checking Solana Tokens
Solana vs Robinhood Chain: Which Network Has the Better Future?
Crypto University: How to Cash Out Crypto
Disclaimer: This article is for educational purposes only. It is not financial, investment, legal, or tax advice. Dates and figures are based on public sources as of September 29, 2026 and may change.




