Status note: This article reflects information publicly available as of September 25, 2026. The investigation is ongoing, and Bitget has said a full incident report will follow. Figures below are company statements or widely reported on-chain estimates and may change.
Key Takeaways
About $351.6 million was taken from Bitget's hot and warm wallets on September 24, 2026. Bitget says its cold wallets were not affected and that the loss falls within its User Protection Fund of more than $464 million.
Bitget says private keys were not stolen. According to the CEO, attackers compromised a backend wallet system, fed it fake transaction data, and caused Bitget's own approval process to sign the transfers.
The incident is a lesson in custody risk. Funds held on any exchange depend on that exchange's internal security, which is why understanding hot wallets, cold wallets, and protection funds matters for every user.
What Happened at Bitget on September 24, 2026
At 18:31 UTC on September 24, 2026, Bitget's security systems detected unauthorized transfers from some of its hot wallets. Bitget CEO Gracy Chen published a security notice on X shortly after, confirming the incident and outlining the company's response.
According to Bitget, the estimated loss is approximately $351.6 million. The breach affected part of the exchange's hot wallet and warm wallet layers. Bitget states that its cold wallets, which hold most platform assets, remained secure.
Bitget said the full loss is covered by its User Protection Fund, which it reports holds more than $464 million. Account balances, the company said, remain accurate. Deposits and trading continued, while withdrawals were paused pending a security review.
Several outlets described it as the largest breach of a centralized exchange in 2026 so far.

Timeline of the Incident
Time (UTC) | Event |
|---|---|
Sept 24, 18:31 | Bitget systems detect unauthorized transfers from hot wallets |
Sept 24, evening | On-chain trackers report more than $170 million moving to an unknown address |
Sept 24, evening | CEO Gracy Chen publishes a security notice confirming about $351.6 million affected |
Sept 24 | Withdrawals paused; deposits and trading remain open |
Sept 25 | Chen says a backend wallet system was compromised and rules out private key theft |
Sept 25 | Bitget says a third-party forensic team has been commissioned |
Pending | Full incident report and withdrawal restoration |
The gap between early on-chain estimates and Bitget's figure has a reported explanation. Chen said early public analysis focused mainly on Ethereum activity, while the unauthorized transfers also covered other blockchains.
What Was Taken: Reported Asset Breakdown
Bitget has not yet published its own full inventory. On-chain tracker Lookonchain published a widely cited breakdown across nine assets.
Asset | Reported Amount | Estimated Value at Time of Report |
|---|---|---|
XRP | 102.93 million XRP | About $157.5 million |
ETH | 31,890 ETH | About $85.8 million |
Stablecoins (USDT, USDC, USDT0) | Combined | About $75.5 million |
XAUt (tokenized gold) | 3,000 XAUt | Not separately reported |
BNB | 12,719 BNB | Not separately reported |
AVAX | 821,012 AVAX | Not separately reported |
TRX | 20.59 million TRX | Not separately reported |
By this estimate, the total was about $357 million at the time, slightly above Bitget's figure. Differences like this are common because token prices move constantly.
Security firm SlowMist linked the theft to 11 EVM addresses, 7 XRP Ledger addresses, and 1 Tron address. It also reported that the attacker was converting assets on EVM chains into ETH. Swapping stolen tokens is a common tactic because some tokens, especially stablecoins, can be frozen by their issuers, while ETH cannot.
How the Attack Reportedly Worked
On September 25, Chen shared a preliminary explanation. She said the attacker compromised a critical backend system within the wallet infrastructure, used it to spoof transaction data, and triggered Bitget's authorization process to move funds out.
In simple terms, the attackers did not break the lock. They tricked the system that decides when the lock should open.
Why "No Private Key Compromise" Matters
A private key is the secret that controls a crypto wallet. If an attacker steals private keys, every address those keys control stays at risk until funds are moved to new wallets.
Bitget says this did not happen. Instead, the failure was in the controls that sit in front of the signing process. This type of attack is sometimes described as an off-chain hack that leads to on-chain losses. The cryptography worked as designed, but the system feeding it instructions was compromised.
The exact method of intrusion is still under investigation. Until the full report is published, details should be treated as preliminary.
Hot, Warm, and Cold Wallets: How Exchange Custody Works
Bitget describes its setup as a three-tier wallet architecture. Many large exchanges use a similar model, balancing speed against security.
Wallet Tier | Connection to Internet | Typical Use | Main Trade-off |
|---|---|---|---|
Hot wallet | Always online | Processing everyday withdrawals quickly | Fast, but most exposed to attacks |
Warm wallet | Partially online, with extra controls | Refilling hot wallets, medium-sized transfers | A middle ground between speed and safety |
Cold wallet | Offline | Storing most customer assets long term | Very secure, but slow to access |
Exchanges keep only a portion of funds in hot wallets so that a breach there does not affect everything. In this case, that design appears to have limited the damage. However, the incident also shows that hot and warm wallets can still hold very large sums on a major exchange.
What Is a User Protection Fund?
A user protection fund is a reserve an exchange sets aside to cover customer losses from events like hacks. Binance's SAFU fund is a well-known example of the same idea.
According to Bitget and on-chain analysts, its fund holds 5,500 BTC across three publicly viewable addresses. Bitget said the loss will be covered "after assessment" and that the fund will then be replenished.
Point to Understand | Why It Matters |
|---|---|
The fund is held in Bitcoin | Its dollar value rises and falls with the BTC price |
The payout would use roughly three quarters of the fund | Less reserve remains until it is replenished |
Coverage terms are still to be detailed | How and when losses are settled has not been fully explained |
A protection fund is a company commitment, not government insurance. It is not the same as bank deposit protection.
Who Was Behind It? What We Know About Attribution
No formal attribution has been published. During a livestream, Chen said some IP addresses used in the attack closely resembled VPN patterns linked to a North Korea-associated group. She stressed that the attackers' identity was not confirmed.
One on-chain investigator separately linked the routing of stolen XRP to funds from a smaller hack earlier in 2026. These are early signals, not conclusions. Official attribution, if it comes, usually follows from law enforcement or detailed forensic reports.
How This Compares to Other Major Exchange Hacks
The figures below are widely reported estimates based on values at the time of each incident.
Exchange | Year | Reported Loss | Notes |
|---|---|---|---|
Mt. Gox | 2014 | About 850,000 BTC reported missing | Led to the exchange's bankruptcy |
Coincheck | 2018 | About $530 million in NEM | Funds held in a hot wallet |
CoinEx | 2023 | About $53 million to $70 million | Users compensated in full |
Bybit | 2025 | About $1.5 billion in ETH | The FBI attributed it to North Korea |
Bitget | 2026 | About $351.6 million | Covered by protection fund, per Bitget |
A pattern stands out. Several recent large incidents targeted operational systems and signing workflows rather than blockchain code itself.
What Users Can Learn From This Incident
This is general educational information, not financial advice.
Understand custody. When you keep crypto on an exchange, the exchange holds the keys. Your safety depends on its security and its financial strength.
Check reserve transparency. Many exchanges publish proof of reserves reports. Learn what these reports do and do not prove.
Know the difference between a protection fund and insurance. Read how a platform's fund works before relying on it.
Consider self-custody knowledge. Learning how hardware wallets and seed phrases work helps you make informed choices.
Use official channels only. After a hack, scammers often post fake "refund" links. Trust only verified company announcements.
What to Watch Next
The full incident report, including root cause and corrective actions
A confirmed date for restoring withdrawals
Details on how the protection fund will cover the loss
Any official attribution from law enforcement
Whether stolen stablecoins are frozen by their issuers
FAQ
Were Bitget user balances affected by the hack?
Bitget says customer account balances remain accurate and that the full loss is covered by its User Protection Fund. Withdrawals were paused during the security review.
Did hackers steal Bitget's private keys?
According to CEO Gracy Chen, private key compromise has been ruled out. She said attackers compromised a backend wallet system and spoofed transaction data to trigger unauthorized transfers.
What is the difference between a hot wallet and a cold wallet?
A hot wallet is connected to the internet and used for fast transactions. A cold wallet is kept offline and is used to store larger amounts more securely.
Is Bitget's User Protection Fund the same as insurance?
No. It is a reserve held by the company, reported to be in Bitcoin. It is not government-backed deposit insurance, and its value changes with the BTC price.
When will Bitget withdrawals resume?
As of September 25, 2026, Bitget had not given a fixed date. The company said withdrawals will resume once its security review is complete.
Related Terms
Hot Wallet: A crypto wallet connected to the internet, used for quick and frequent transactions.
Cold Wallet: A crypto wallet kept offline to reduce exposure to online attacks.
Private Key: A secret code that gives full control over the crypto held at a wallet address.
Proof of Reserves: An audit-style report showing that an exchange holds assets to match customer balances.
Custodial Wallet: A wallet where a third party, such as an exchange, holds the private keys on the user's behalf.
Sources
Bitget Support Center, "Security Notice: Bitget Hot Wallet Incident, September 24, 2026": https://www.bitget.com/support/articles/12560603896024
Bitget official post on X, September 24, 2026: https://x.com/bitget/status/2103236552482848927
Blockhead, "Bitget Loses $351.6 Million in Hot Wallet Breach, Rules Out Private Key Compromise": https://www.blockhead.co/2026/09/25/bitget-loses-351-6-million-in-hot-wallet-breach-rules-out-private-key-compromise/
Bitcoin Magazine, "Nearly $352M Moved From Crypto Exchange Bitget Wallets In Suspected Hack": https://bitcoinmagazine.com/news/bitget-suffers-352-million-hack
Crypto Breaking News, "Bitget Reports $352M Security Breach, Halts Withdrawals": https://www.cryptobreaking.com/bitget-reports-352m-security-breach/
TechFlow, Bitget third-party investigation and protection fund updates: https://www.techflowpost.com/en-US/newsletter/137734
Forbes, "Bitget Hack Of $351.6 Million Triggers A Withdrawal Freeze": https://www.forbes.com/sites/boazsobrado/2026/09/24/bitget-hack-of-3516-million-triggers-a-withdrawal-freeze/
Wikipedia, "CoinEx" (2023 hot wallet incident): https://en.wikipedia.org/wiki/CoinEx




