Learn
  • BitcoinWhat Bitcoin is and how it actually works.
  • EthereumSmart contracts, staking and what runs on Ethereum.
  • Crypto CoursesStructured learning programs.
  • GuidesPractical crypto tutorials and explainers.
  • TradingLearn to trade with the Crypto Masterclass.
  • DictionaryClear definitions for crypto terminology.
Buy
  • Buy Crypto
  • Buy Stablecoins
  • Buy Tokenized Stocks
  • Compare Platforms
Trade
  • Nitros Bull
  • Trade Crypto
  • ForexTake the free 7-day Trading Reset.
  • Exchanges
  • Memecoins
  • Brokers
  • Funded Accounts
  • Trading Bots
  • Copy Trading
  • Trading Tools
Wallets
  • Best Crypto Wallets
  • Crypto Wallets
  • Wallet Reviews
  • How to Choose a Wallet
  • Wallet Security Guide
Earn
  • Passive income
  • Crypto cards
Spend
  • Crypto Cards
  • Pay With Crypto
  • Gift Cards
  • Spend Guides
Cash Out
  • Cash Out Crypto
  • P2P
  • Spend Crypto With a Card
  • Stablecoins
  • Blockchains
  • Tokenized Stocks
  • MiCA
  • Taxes
  • Crypto Tools
  • News
DealsLog In

Crypto University

Global crypto education, research and decision tools.

Learn

BitcoinEthereumCrypto CoursesGuidesTradingDictionary

Explore

MiCA TrackerBlockchainsStablecoinsTokenized Stocks

Company

Our StoryCommunityAffiliate ProgramGet in Touch

Legal

PrivacyTerms of Use

Connect

Join the Community

Educational content only. Not investment, tax, or legal advice. Verify details with primary sources before making decisions. © 2026 Crypto University.

Go Back to Crypto University Blogs

Bitget Hack Explained: Hot Vs Warm Vs Cold Wallets

Crypto University • 29 September 2026

Bitget Hack Explained: Hot vs Warm vs Cold Wallets
Guides

Key Takeaways

  1. The keys were not stolen. Bitget says attackers used stolen internal credentials to fake transaction data and push fraudulent transfers through the exchange's own approval process. Private keys and cold wallets were not compromised.

  2. Wallet tiers limit damage, but do not remove risk. Hot and warm wallets hold a small share of exchange funds for daily withdrawals. That design capped the loss, but it did not stop it.

  3. A protection fund is a company promise, not insurance. Bitget says its User Protection Fund, worth more than $464 million, covers the loss. That is helpful, but it is not a government guarantee.

What Happened: A Plain-Language Timeline

On September 24, 2026, crypto exchange Bitget detected unauthorized transfers leaving its hot and warm wallets. Bitget first estimated the loss at about $351.6 million. After further on-chain tracing, it revised the figure to about $387.5 million, and said the higher number reflects transfers on Zcash and Tron that were identified later, not new theft after the attack was contained.

The assets moved across several networks, including Ethereum and other EVM chains, the XRP Ledger, Zcash and Tron. The largest single asset was XRP, reported at roughly 102.9 million XRP (about $157.5 million at the time).

Date and time (UTC)

What happened

Sept 24, 18:31

Bitget's security systems flag unauthorized transfers from some hot wallets

Sept 24

Blockchain analytics firms spot large outflows; over $170 million is reportedly swapped into ETH

Sept 24

Bitget pauses withdrawals. Deposits and trading stay open

Sept 25

CEO Gracy Chen says private keys were not stolen and the protection fund covers the loss

Sept 25

Chen says the attack pattern is "highly consistent" with known North Korean groups. This is not an official government attribution

By Sept 28

Loss estimate revised to about $387.5 million after further on-chain tracing

Sept 28, 08:00

Bitcoin withdrawals resume in a phased rollout

Sept 29 to Oct 2

ETH, then USDT, then remaining assets, fiat and P2P scheduled to return

Figures are based on Bitget statements and widely reported on-chain data. The investigation is ongoing and numbers may change.

The Key Detail: No Private Keys Were Stolen

Most people imagine a crypto hack as someone stealing a secret key. This attack worked differently.

According to Bitget, the attackers exploited a vulnerability in a third-party security product to obtain high-level internal credentials. With that access, they compromised a critical backend system in the wallet infrastructure, spoofed transaction data, and triggered the exchange's own authorization process. The system then signed the transfers as if they were legitimate.

Think of it like a bank vault. The thieves did not copy the key. They forged the paperwork, and the bank's own staff opened the vault for them.

The lesson: strong key storage is not enough. The systems that decide what gets signed matter just as much as the keys that do the signing.

How Exchange Custody Works: Hot, Warm and Cold Wallets

When you deposit crypto on a centralized exchange, your coins usually go into shared wallets the exchange controls. Your account balance is an entry in the exchange's internal database. Most large exchanges split their holdings into three tiers.

Wallet tier

Connection

Main job

Speed

Risk level

Hot wallet

Always online

Pays out everyday withdrawals automatically

Seconds to minutes

Highest

Warm wallet

Partly connected, more approvals needed

Refills the hot wallet and moves extra deposits toward storage

Minutes to hours

Medium

Cold wallet

Offline, keys kept off the internet

Stores most reserves long term

Hours to days

Lowest

The goal is to keep only a small working balance online. If the hot layer is breached, most funds should still sit safely in cold storage. That is exactly what Bitget says happened: the hot and warm layers were hit, and the cold wallets were not.

For individual users, the same logic applies. A mobile or browser wallet is a hot wallet. A hardware wallet that signs transactions offline is a form of cold storage.

Sponsored

Bybit Cybertruck campaign: trade stocks and crypto for a chance to win.

What a Protection Fund Is (and What It Isn't)

Bitget's User Protection Fund is a reserve the company set aside to cover user losses from events like hacks. BleepingComputer reported it holds about 5,500 BTC, valued at more than $464 million when the incident was disclosed.

A protection fund IS

A protection fund IS NOT

A reserve owned and managed by the exchange

Government deposit insurance, such as FDIC coverage for US bank accounts

A public signal that the company plans to absorb losses

A legal guarantee that every user is covered in every scenario

Often held in crypto, such as BTC

A fixed dollar amount, since its value moves with market prices

Helpful in a contained incident

A replacement for audits, strong controls and proof of reserves

Because Bitget's fund is held in bitcoin, its dollar value rises and falls with BTC. It is also worth noting that the revised $387.5 million loss was published after the $464 million fund figure was first stated. Users should read these funds as a helpful backstop, not a certainty.

Why Exchanges Pause Withdrawals

A withdrawal pause can feel alarming, but it is a standard emergency step. Exchanges pause for several practical reasons:

  • Stop further losses. If the approval system is compromised, every new withdrawal could be another fake one.

  • Find the attack path. Engineers need time to identify and close the vulnerability.

  • Reconcile balances. The exchange must confirm what was taken and that user account records are correct.

  • Work with partners. Stablecoin issuers, blockchain foundations and other exchanges can sometimes freeze stolen funds, and Bitget reported some assets were frozen.

A pause is a warning sign worth taking seriously, but it is not proof of insolvency. What matters is how long it lasts and how clearly the exchange communicates. Bitget restored withdrawals in phases, starting with Bitcoin, and said the schedule applied equally to all users.

Bitget vs Bybit: Two Attacks on the Approval Process

The Bitget case looks similar to the February 2025 Bybit hack, the largest crypto theft on record. In both cases, attackers did not break the cryptography. They manipulated what the signing system believed it was approving.

Factor

Bybit (Feb 21, 2025)

Bitget (Sept 24, 2026)

Amount

About $1.46 billion, often rounded to $1.5 billion

About $387.5 million (revised from $351.6 million)

Wallet affected

ETH multisig cold wallet, during a routine transfer to a warm wallet

Parts of hot and warm wallet layers

Method

Malicious code in the Safe{Wallet} interface showed signers a normal transaction while changing what they signed

Stolen credentials let attackers spoof transaction data and trigger internal approvals

Private keys stolen?

No

No, according to Bitget

Entry point

A compromised developer machine at a third-party wallet provider

A vulnerability in a third-party security product

Attribution

FBI attributed it to North Korea's TraderTraitor group

CEO cited patterns consistent with North Korean groups; not officially confirmed

Two lessons stand out. First, cold storage is only as safe as the process around it. Bybit's funds were in cold storage, but the attack struck during a transfer. Second, third-party tools are a major weak point. Both incidents started outside the exchange's own code.

Sponsored

Crypto University and OKX: spend crypto with the OKX Card. Zero fees.

Exchange Risk Checklist for Users

You cannot audit an exchange's backend. You can reduce how much an incident affects you.

  1. Keep only what you trade on exchanges. Move long-term holdings to a wallet where you control the keys.

  2. Check for proof of reserves. Look for regular, independently reviewed reports. Bitget reported a reserve ratio of 127%, but self-reported figures deserve scrutiny.

  3. Read the protection fund terms. Know its size, what asset it holds, and what it covers.

  4. Spread risk. Avoid keeping everything on a single platform.

  5. Enable strong account security. Use an authenticator app or security key, withdrawal address allowlists and anti-phishing codes.

  6. Watch official channels only. During incidents, scammers post fake "refund" links. Use the exchange's verified website and accounts.

  7. Do not panic-trade. Fast decisions during a pause often come from rumors, not facts.

  8. Keep records. Save balance screenshots and transaction IDs in case you need to file a claim.

Want to control your own keys? Follow our Web3 Wallets & Self-Custody Security 2026: Ledger, OneKey, Exodus & Guarda

FAQ

Did Bitget users lose money in the hack?

Bitget says user account balances are unaffected and its User Protection Fund covers the loss. The investigation is ongoing, so users should follow official updates.

What is the difference between a hot wallet and a cold wallet?

A hot wallet is connected to the internet for fast transfers. A cold wallet keeps private keys offline, which makes remote theft much harder but transfers slower.

What is a warm wallet?

A warm wallet sits between hot and cold storage. It is partly connected, needs more approvals, and is used to refill hot wallets and move excess funds to cold storage.

Is an exchange protection fund the same as insurance?

No. It is a reserve owned by the exchange. Its value can change, and it is not a government deposit guarantee.

Was the Bitget hack worse than the Bybit hack?

No. Bybit lost about $1.46 billion in 2025, roughly four times more. Both attacks manipulated the approval process instead of stealing private keys.

Related Terms

  • Hot Wallet: A crypto wallet connected to the internet, built for fast and frequent transactions.

  • Cold Wallet: A wallet that keeps private keys offline to reduce the risk of remote theft.

  • Private Key: A secret number that proves ownership of crypto and authorizes transactions from an address.

  • Multisig Wallet: A wallet that needs approval from several keys before a transaction can be sent.

  • Proof of Reserves: A report that shows an exchange holds enough assets to cover customer balances.

Sources

  1. CoinDesk, "Bitget's $352 million hack happened via spoofed transfers, not private keys, CEO Gracy Chen says" (Sept 25, 2026): https://www.coindesk.com/markets/2026/09/25/bitget-s-usd351-million-hack-happened-via-spoofed-transfers-not-private-keys-ceo-gray-chen-says

  2. BleepingComputer, "Hackers steal $351.6 million in Bitget crypto exchange hack" (Sept 2026): https://www.bleepingcomputer.com/news/security/hackers-steal-3516-million-in-bitget-crypto-exchange-hack/

  3. SecurityWeek, "North Korea Suspected in $351 Million Bitget Crypto Heist" (Sept 2026): https://www.securityweek.com/north-korea-suspected-in-351-million-bitget-crypto-heist/

  4. Bitcoin.com News, "Bitget Restarts Bitcoin Withdrawals as $388M Hack Investigation Widens" (Sept 28, 2026): https://news.bitcoin.com/exchanges/bitget-restarts-bitcoin-withdrawals-388m-hack-investigation-widens/

  5. Cointelegraph, "Bitget Restores Bitcoin Withdrawals After $388M Hack" (Sept 28, 2026): https://cointelegraph.com/news/bitget-btc-withdrawal-hacker-eth-swap-thorchain

  6. Blockhead, "Bitget Loses $351.6 Million in Hot Wallet Breach, Rules Out Private Key Compromise" (Sept 25, 2026): https://www.blockhead.co/2026/09/25/bitget-loses-351-6-million-in-hot-wallet-breach-rules-out-private-key-compromise/

  7. The Hacker News, "Bybit Hack Traced to Safe{Wallet} Supply Chain Attack Exploited by North Korean Hackers" (Feb 27, 2025): https://thehackernews.com/2025/02/bybit-hack-traced-to-safewallet-supply.html

  8. Communications of the ACM, "Behind the Bybit Crypto Theft": https://cacm.acm.org/news/behind-the-bybit-crypto-theft

More Reading

Bitget Hot Wallet Hack Explained: What It Teaches About Exchange Security

The Biggest Crypto Exchange Hacks in History: From Mt. Gox to Bybit

How to Get Started on Robinhood Chain: A Complete Beginner's Guide

How to Find an Old Crypto Wallet Using Records You Still Have

How RugCheck Works: A Beginner's Guide to Checking Solana Tokens

Solana vs Robinhood Chain: Which Network Has the Better Future?

Crypto University: How to Cash Out Crypto

Disclaimer: This article is for educational purposes only. It is not financial, investment, legal, or tax advice. Dates and figures are based on public sources as of September 29, 2026 and may change.

Share Posts

Copy Link

cryptouniversity.networkblog/bitget...

$30,000 Deposit Blast-Off campaign artwork
Limited-Time

$30,000 Deposit Blast-Off

Stand to earn the biggest reward in any crypto exchange! Bybit is offering up to 30,000 USDT in deposit rewards! Spread the word now!

Bybit logo

Bybit

Claim OfferTerms apply.
Ends Dec 31, 202693 days remaining
Professional Crypto Trading Terminals 2026: Coinigy, Logx & ASCN Guide
Cryptouniversity Research•30 September 2026

Professional Crypto Trading Terminals 2026: Coinigy, Logx & ASCN Guide

Master professional crypto execution in 2026. Learn to unify multi-exchange trading with Coinigy, execute decentralized perps on Logx, and optimize yield on ASCN.

TradingGuides
Crypto Calendar October 2026: Token Unlocks, Regulatory, Fed Dates, and Bitcoin ETF Flows
Crypto University•29 September 2026

Crypto Calendar October 2026: Token Unlocks, Regulatory, Fed Dates, and Bitcoin ETF Flows

Crypto Calendar October 2026: Token Unlocks, Regulatory Deadlines, and Bitcoin ETF Flows

Crypto News
Web3 Wallets & Self-Custody Security 2026: Ledger, OneKey, Exodus & Guarda
Cryptouniversity Research•28 September 2026

Web3 Wallets & Self-Custody Security 2026: Ledger, OneKey, Exodus & Guarda

Master crypto self-custody in 2026. Learn to secure your digital assets using Ledger, OneKey, Exodus, and Guarda, while avoiding phishing and supply chain attacks.

Wallet ExchangesCryptocurrency