Bitget Hack: $351.6 Million Stolen From Hot Wallets as Withdrawals Remain Frozen
Bitget says approximately $351.6 million in crypto was affected after attackers compromised part of its hot and warm wallet infrastructure. The exchange says cold wallets and customer balances remain protected, while withdrawals remain suspended during a security review.
Crypto exchange Bitget has confirmed a security breach involving approximately $351.6 million in digital assets, making it one of the largest reported crypto exchange breaches of 2026.
The exchange detected unauthorized transfers from some of its hot wallets at 18:31 UTC on September 24, according to its official security notice. Bitget subsequently activated its emergency response process, flagged the receiving addresses and notified law enforcement and blockchain-security firms.
Withdrawals remain paused, while deposits and trading continue to operate.
Bitget says the affected funds are covered by its User Protection Fund, which currently holds more than $464 million. It also says its cold-wallet reserves were not affected and that customer account balances remain accurate.
The incident has put renewed attention on a critical question for centralized crypto exchanges: how secure is the software controlling the wallets, even when the underlying private keys remain protected?
What happened in the Bitget hack?
The incident initially emerged through on-chain activity showing large amounts of cryptocurrency moving from addresses associated with Bitget to newly created wallets.
Early public estimates were significantly lower than Bitget’s eventual figure because analysts initially tracked only part of the transfers. Bitget later confirmed that approximately $351.6 million had been affected across its hot and warm wallet infrastructure.
The exchange says its security systems detected the unauthorized activity at 18:31 UTC and that its emergency response team acted within minutes.
Bitget then suspended withdrawals as a precaution while investigators worked to contain the incident.
The company’s initial security notice said it would not speculate about the attack vector while the investigation was ongoing.
A subsequent update from CEO Gracy Chen provided more detail.
Bitget says the private keys were not stolen
According to Chen’s latest account, attackers compromised a critical backend system within Bitget’s wallet infrastructure.
The attackers allegedly used that system to spoof transaction information and trigger Bitget’s existing authorization process.
In practical terms, the reported problem was not that an attacker simply stole a private key and used it elsewhere. Instead, the attacker allegedly compromised part of the software infrastructure that tells the wallet system which transactions should be authorized.
Bitget has said private-key compromise has been ruled out and that the loss has been contained, with no further unauthorized transfers possible.
That distinction matters.
A private-key theft can expose every asset controlled by the compromised key. A backend compromise attacks the controls surrounding the signing process.
The latter still represents a major security failure, but it points to a different part of the exchange’s infrastructure.
Hot wallets, warm wallets and cold wallets explained
Bitget uses a three-tier wallet architecture:
- Hot wallets: connected to online systems and used for operational transactions.
- Warm wallets: provide an intermediate layer between hot and cold storage.
- Cold wallets: kept offline and separated from internet-connected systems.
Bitget says the breach affected part of its hot and warm wallet layers, while its cold wallets remained secure.
The distinction is important because centralized exchanges typically need some online liquidity to process deposits, trading activity and withdrawals quickly.
That convenience creates an attack surface.
The Bitget incident therefore raises a broader security question for exchanges: how much of the transaction authorization process should remain connected to systems that can be reached through the internet?
How much crypto was taken?
Bitget’s official estimate is approximately $351.6 million.
On-chain investigators initially identified more than $170 million in transfers, with additional activity later bringing the estimated total much closer to the exchange’s figure.
The assets identified in public blockchain tracking included XRP, ETH, USDT, USDC, USDT0, tokenized gold, BNB, AVAX and TRX.
XRP became particularly important to the investigation because a large amount of XRP was transferred from Bitget-associated addresses, while early Ethereum-focused tracking captured only part of the overall activity.
The stolen assets also moved across several blockchain networks, complicating efforts to track and potentially freeze them.
Why the attacker converted assets into ETH
One of the most notable parts of the incident was the movement of assets into ETH.
On-chain investigators reported that some stablecoins and other assets were rapidly exchanged for Ether. Earlier tracking showed approximately 19.67 million USDT0 being used to acquire around 7,111 ETH on Arbitrum.
The logic is straightforward.
Stablecoins such as USDT and USDC can be frozen by their issuers under certain circumstances. Ether does not have a central issuer with an equivalent freeze function.
Converting potentially freezeable assets into a decentralized cryptocurrency can therefore make recovery more difficult.
That does not mean every conversion was necessarily made for that reason, but the movement is consistent with a common challenge in crypto theft investigations: once assets leave centralized issuers and move through multiple blockchain networks, recovery becomes considerably more complicated.
Are Bitget customer funds safe?
Bitget says they are.
The exchange has stated that:
- customer account balances remain accurate;
- customer assets are protected;
- the loss falls within its User Protection Fund;
- the fund currently contains more than $464 million;
- cold wallets remain secure;
- deposits and trading remain operational; and
- withdrawals are temporarily suspended.
Bitget’s latest Proof of Reserves report, published before the incident, showed a 135% total reserve ratio across 19 assets. The exchange described it as its 46th Proof of Reserves update.
But Proof of Reserves and a protection fund answer different questions.
Proof of Reserves provides a snapshot of whether an exchange holds assets corresponding to reported customer liabilities.
A protection fund is a separate pool intended to absorb losses from extraordinary incidents.
Neither, by itself, demonstrates that an exchange’s internal software and authorization systems cannot be compromised.
That distinction is now central to the Bitget story.
Bitget’s $464 million protection fund faces its biggest test
Bitget established its User Protection Fund in 2022 and has committed to maintaining it above $300 million.
Its latest August report said the fund held approximately 5,500 BTC and had an average valuation of $382 million during August, reaching a monthly high of $441.5 million.
Bitget now says the fund is worth more than $464 million and is sufficient to cover the estimated $351.6 million loss.
The important question is therefore no longer simply whether the fund exists.
It is whether the exchange can demonstrate how the loss will be covered, how quickly withdrawals can resume and how the fund will be replenished afterward.
Bitget has said a full incident report will include a root-cause analysis and corrective measures.
Who is behind the Bitget hack?
Attribution remains less certain than the technical details.
Bitget CEO Gracy Chen has reportedly pointed to preliminary indicators that may connect the attack to a North Korean-linked operation, including similarities in IP and VPN usage.
However, that is not the same as a confirmed attribution by law enforcement or an independently established finding.
Reports have referenced similarities with previous attacks associated with North Korean-linked groups, but investigators are still examining the incident.
For now, the responsible approach is to describe North Korean involvement as a suspected or investigated lead, rather than an established fact.
Why the Bitget hack matters for crypto exchanges
The size of the breach is significant, but the attack method could ultimately prove more important.
For years, crypto security discussions have focused heavily on private-key theft, phishing, compromised seed phrases and malicious wallet software.
The Bitget incident highlights another vulnerability:
the systems that sit between a user request and the private key.
An exchange can protect its keys and maintain substantial reserves while still facing a major threat if an attacker can manipulate the software that generates or authorizes transactions.
That expands the security conversation from wallet custody to the entire transaction-signing pipeline.
For centralized exchanges, that means backend systems, privileged access, authentication, transaction validation, internal controls and third-party software all become part of the security perimeter.
What Bitget users can do now
For users with funds on Bitget, the exchange says:
Balances: Accurate.
Deposits: Operational.
Trading: Operational.
Withdrawals: Temporarily suspended.
Cold wallets: Reported secure.
Customer funds: Bitget says they remain protected.
Users should also be particularly cautious about phishing attempts.
Major exchange hacks often produce fake support accounts, fraudulent recovery offers and messages asking users to provide passwords, seed phrases or additional payments to “unlock” withdrawals.
No legitimate support representative should require a user’s private key or recovery phrase.
What happens next?
The next major developments will likely centre on three areas.
First, withdrawals.
Users will want to know when Bitget can safely restore withdrawal functionality.
Second, recovery.
Investigators and blockchain-security firms will continue tracking the stolen assets across networks.
Third, the technical report.
The most valuable information may be Bitget’s explanation of exactly how the backend system was compromised and what controls failed.
The company has said it will publish a fuller incident report covering the root cause and corrective actions.
The bigger lesson for African crypto users
For users across Africa, where centralized exchanges remain important gateways into the global crypto market, the Bitget incident is a reminder that exchange risk is different from blockchain risk.
Bitcoin, Ethereum and other blockchain networks can continue functioning normally while a centralized company holding users’ assets experiences a major security incident.
That distinction matters.
An exchange can offer Proof of Reserves, maintain cold storage and operate a large protection fund, while users can still face temporary loss of access when withdrawals are suspended.
For long-term holders, the incident also reinforces the difference between custody and convenience.
Keeping funds on an exchange provides easy access to trading and liquidity. Self-custody removes the exchange as an intermediary, but transfers responsibility for security and recovery to the user.
Neither model eliminates risk.
They simply place the risk in different hands.
The bottom line
Bitget says approximately $351.6 million was taken from parts of its hot and warm wallet infrastructure on September 24, 2026.
The exchange says its cold wallets were not affected, customer balances remain accurate and its $464 million-plus User Protection Fund covers the reported loss. Withdrawals remain suspended while the security review continues.
The preliminary technical explanation is particularly significant: Bitget says attackers compromised a backend wallet system, spoofed transaction data and used the exchange’s authorization process to move funds, while private keys were not compromised.
The next test is execution.
Can Bitget restore withdrawals safely, demonstrate that the protection fund can cover the loss, recover any stolen assets and publish enough technical detail to show how the vulnerability will be prevented from happening again?
Those answers will matter well beyond Bitget.
They could shape how the crypto industry thinks about exchange security in 2026.
Sources

