Skip to content
Coin News Media
September 26, 2026
Nifty 50+0.62%
Sensex+0.55%
S&P 500-0.18%
Subscribe
Coin News Media
Altcoins

Bitget Hack: $351 Million Drained as Withdrawals Freeze and Crypto Exchange Scrambles to Contain Fallout

The Bitget crypto exchange experienced a major security breach on 24 September 2026. Approximately $351.6 million in unauthorized transfers occurred from the exchange’s hot and... The post Bitget Hack: $351 Million Drained as Withdrawals Freeze and Crypto Exchange Scrambles to Contain Fallout appeared first on Bitcoin Foundation.

Bitget Hack: $351 Million Drained as Withdrawals Freeze and Crypto Exchange Scrambles to Contain Fallout

The Bitget cryptocurrency exchange suffered a major security breach on September 24, 2026. Approximately $351.6 million in unauthorized transfers were executed from the platform’s hot and warm wallet facilities.

Withdrawals were temporarily paused while deposits and trading operated normally. Bitget reported that customer balances remain accurate and that its protection fund is sufficient to absorb the estimated loss. Investigators are currently concentrating on a backend system compromise and the subsequent asset transfers, which may involve a North Korean perpetrator.

Related: Bitget $351.6M Hack Probe Points to Backend Breach as Private-Key Leak Is Ruled Out

What Happened in the Bitget Hack?

The security incident began when unexpected wallet transfers were detected. Initial on-chain reports only captured a fraction of the total value. Bitget later revised the total upward across multiple networks following a comprehensive review of the affected transactions.

Bitget Confirms $351.6 Million in Unauthorized Transfers

Bitget verified that roughly $351.6 million in digital assets were compromised via unauthorized transfers, impacting a portion of its operational wallet architecture. This event stands as one of the largest exchange security breaches of 2026. Early tallies were low because they failed to track all participating networks.

The company noted that the total losses fall well within the coverage limits of its User Protection Fund. Furthermore, customer account balances reportedly remained unaffected.

When Bitget Detected the Attack

Bitget’s security apparatus flagged the abnormal activity at 18:31 UTC on September 24, noting transactions that deviated from standard wallet operations.

Emergency protocols were enacted within minutes. Security personnel isolated systems, scrutinized the unauthorized movements, mapped destination addresses, and consulted outside cybersecurity experts alongside law enforcement agencies.

Read More: $320M Bitcoin Hack: What Really Happened to Liquid Network?

Which Bitget Wallets Were Affected?

The exploit impacted sections of the exchange’s hot and warm wallet layers, which supply liquidity and operational infrastructure.

Hot wallets remain online to support rapid withdrawals and everyday transactions, while warm wallets serve as a bridge between online liquidity and offline storage. Bitget confirmed that its cold wallets remained secure throughout the event, maintaining a strict three-tier separation of hot, warm, and cold storage.

Category Details
Incident Unauthorized transfers from Bitget wallet infrastructure
Date September 24, 2026
Estimated Amount Approximately $351.6 million
Affected Infrastructure Parts of hot and warm wallet systems
Cold Wallets Bitget says they were not affected
Main Assets XRP, Ethereum, stablecoins, BNB, AVAX, TRX and other assets
Withdrawals Temporarily suspended
Deposits Operational
Trading Operational
Private Keys Bitget says they were not compromised
User Balances Bitget says balances remain accurate
Protection Fund More than $464 million
Investigation Backend compromise and movement of affected assets under investigation
Attacker Attribution Not confirmed
Next Steps Root-cause analysis, system remediation and withdrawal restoration

How Did the $351 Million Bitget Hack Happen?

Initial findings indicated that private keys were not stolen. Instead, Bitget reported that a vital backend component supporting the wallet infrastructure was successfully compromised.

Attackers Targeted Bitget’s Backend Wallet Infrastructure

The perpetrators managed to access a core system inside Bitget’s wallet environment, enabling them to tamper with the transaction processing workflow.

This distinction is critical, as a wallet’s private keys can remain secure even if the surrounding infrastructure is breached. Exchanges rely on numerous auxiliary systems prior to transaction signing. The incident highlighted vulnerabilities in broader backend services that sophisticated actors can exploit to route funds.

Read More: FBI Crypto Crime Forum Targets Scams, Hacks and North Korean Threats

How Spoofed Transaction Data Triggered the Authorization Process

Bitget’s initial explanation suggested that attackers manipulated transaction parameters within the compromised backend environment before submitting them to the authorization pipeline.

This manipulation tricked the system into approving unauthorized transfers. Valid cryptographic signatures were ultimately used to clear fraudulent instructions, emphasizing the need for robust security controls that independently verify transaction intent prior to final sign-off.

Bitget Says Private Keys Were Not Compromised

Bitget reiterated that investigators ruled out any private-key compromise, separating this event from standard hot-wallet hacks where signing keys are stolen directly.

Instead, the attackers manipulated the infrastructure feeding data into the authorization system, enabling asset movement without extracting keys. Cold-storage keys likewise remained untouched within operational boundaries.

What Remains Unknown About the Attack Vector

Investigators still need to pinpoint how the intruders initially accessed the backend architecture, as Bitget has not yet published a full technical post-mortem.

Potential avenues include software vulnerabilities, leaked credentials, third-party system integrations, or internal weaknesses. A thorough root-cause analysis is required to clarify the entry point.

Where Did the Stolen Crypto Go?

The stolen funds have been rapidly circulated. Investigators note that the assets have moved through multiple third-party exchange wallets and jumped across blockchains to obscure their origins.

Portions of the stolen portfolio have been converted into Ether, while other tokens sit in distinct addresses awaiting potential routing through cross-chain bridges, exchanges, or decentralized swaps.

XRP, Ethereum and Stablecoins Account for Major Outflows

Once tracking expanded past Ethereum-compatible chains, XRP emerged as one of the largest holdings involved, accounting for roughly 102.9 million transferred tokens.

Ethereum also comprised a massive share at around 31,890 ETH, alongside stablecoins like USDT, USDC, and USDT0, as well as BNB, AVAX, TRX, and tokenized gold. The massive XRP volume explains why preliminary estimates drastically underreported the actual losses.

How the Attackers Moved Funds Across Multiple Networks

The bad actors dispersed assets across several blockchain networks, creating a tangled web of transactions for on-chain analysts to untangle.

While EVM-compatible networks handled a large volume of the theft, XRP transactions established an entirely separate tracking trail. Subsequent bridging and token swapping further complicated asset recovery efforts.

Why the Stolen Assets Were Swapped Into Ethereum

By converting heavy amounts of stablecoins and alternative tokens into Ethereum, the attackers reduced their vulnerability to centralized freezing commands.

Centralized stablecoin issuers can easily blacklist and freeze tokens linked to criminal activity, whereas native ETH lacks a central issuer capable of halting transactions. This made the Ethereum trail a central focus for blockchain forensics.

Tracking the Addresses Linked to the Bitget Exploit

Bitget announced that suspicious recipient addresses were identified shortly after the breach, with security firms closely monitoring subsequent outflows.

While public ledgers offer transparency, unmasking the individuals behind specific addresses demands deep forensic work, cross-chain bridge monitoring, and cooperation from centralized exchanges when funds land in identifiable accounts.

Why Bitget Froze Withdrawals

The sudden suspension of withdrawals served as the most immediate disruption for platform users while the exchange audited its wallet systems.

Bitget Suspends Withdrawals After Detecting Unauthorized Transfers

Bitget paused withdrawals purely as a precautionary measure to halt further exposure while investigations unfolded. This action bought security teams time to inspect systems before re-enabling external transfers.

The freeze did not mean user account balances had vanished; Bitget confirmed that internal accounting records remained completely accurate.

Deposits and Trading Remain Operational

Trading and deposits were kept online, enabling users to continue standard exchange activities.

Trading primarily updates internal ledgers rather than triggering immediate on-chain transfers, whereas withdrawals require assets to leave secured wallets. This structural difference allowed internal trading to continue while high-risk external outflows were halted.

When Will Bitget Withdrawals Resume?

Bitget has not committed to a fixed timeline for restoring withdrawals, stating only that services will come back online once safety reviews are finalized.

Security teams must verify that the compromised pathway is entirely patched before allowing external movements. Customers should expect restoration to depend on technical milestones rather than a rigid calendar date.

What Bitget Says About Further Unauthorized Transfers

Bitget asserted that the breach has been contained and that further unauthorized transfers via the exploited vector are impossible, though security hardening continues.

Containment does not automatically mean all secondary vulnerabilities are resolved. Continuous monitoring remains essential given that attackers frequently establish persistence prior to detection.

Are Bitget User Funds Safe After the Hack?

Bitget maintains that client assets are secure despite the $351.6 million loss, leaning heavily on its substantial User Protection Fund to absorb the shock.

Bitget Says Customer Balances Remain Accurate

According to management, user account balances were untouched by the incident, with no individual account reductions announced.

This means the exploit impacted exchange-held treasury and operational wallet assets rather than individual holdings, even though withdrawal restrictions remained in place during the audit.

How the $464 Million User Protection Fund Covers the Loss

The Bitget User Protection Fund held upward of $464 million at the time of the disclosure, easily surpassing the estimated $351.6 million damage.

The fund was specifically created to handle extraordinary security crises. While this financial buffer is reassuring, users continue to monitor how quickly normal withdrawal operations return.

Why Cold Wallets Were Not Affected

Cold storage remained disconnected from routine online operational pipelines, shielding it from attacks targeting internet-facing infrastructure.

Bitget affirmed that its cold storage units remained secure while only hot and warm layers were breached, demonstrating the value of asset segmentation across custody tiers.

What Bitget Customers Should Know While Withdrawals Are Suspended

Customers can still view balances and trade, but they must exercise extreme caution regarding unofficial channels promising emergency withdrawal services.

Major incidents frequently trigger aggressive phishing scams. Users are strongly advised against sharing login credentials, seed phrases, or authentication codes with anyone claiming to offer special access.

Who Is Behind the Bitget Hack?

Formal attribution remains unconfirmed, though Bitget executives have publicly pointed toward a possible North Korean connection.

Why Investigators Are Looking at a Possible North Korean Link

Bitget CEO Gracy Chen stated that a North Korean threat actor is a strong possibility based on technical indicators and behavioral patterns.

State-sponsored groups from North Korea have a long history of targeting digital asset platforms with highly prepared operations. While behavioral similarities raise suspicion, they do not constitute definitive proof.

What Evidence Connects the Attack to Lazarus Group?

Discussions surrounding the Lazarus Group center on network telemetry, specific VPN usage profiles, and transaction flows matching past high-profile thefts.

Researchers continue to cross-reference on-chain behavior with known theft clusters. While these leads aid the investigation, definitive confirmation requires deeper corroborating evidence.

What Remains Unconfirmed About the Attackers

No comprehensive forensic report has officially identified the culprits, leaving the North Korean theory as a working hypothesis.

Pinpointing state-backed hackers is notoriously difficult due to deliberate obfuscation tactics. Final technical findings from Bitget and ongoing law enforcement probes will ultimately dictate the official attribution.

Bitget Hack Timeline: From First Outflows to Withdrawal Freeze

The security event unfolded rapidly on September 24, with anomalous transactions appearing long before the exchange published a complete assessment of the breach.

18:31 UTC: Bitget Detects Unauthorized Transfers

Security monitors flagged unauthorized transfers originating from a subset of operational wallets at 18:31 UTC.

Staff immediately began tracing the outflows, establishing this timestamp as the official starting point of the company’s emergency response.

Initial On-Chain Transfers Raise Security Concerns

External blockchain observers quickly spotted unusually large transfers leaving Bitget-labeled addresses, though early calculators drastically underestimated the final losses.

Because large exchanges frequently move funds for routine operational reasons, initial speculation varied until Bitget formally confirmed the unauthorized nature of the transfers.

Bitget Activates Its Emergency Response

Emergency protocols kicked in within minutes of the discovery. Teams isolated impacted systems, tracked destination addresses, paused withdrawals, and brought in external security consultants.

Exchange Confirms the $351.6 Million Loss

Bitget eventually pegged the total affected sum at $351.6 million—vastly exceeding initial EVM-focused metrics once massive XRP movements were accounted for.

Investigation and System Remediation Begin

Following containment, engineers pivoted to root-cause analysis, system hardening, and tracing stolen assets to ensure wallet authorization layers are secure before reopening.

What the Bitget Hack Means for Crypto Exchange Security

The breach underscored that exchange security encompasses far more than simply safeguarding private keys; complex custody ecosystems present numerous potential attack surfaces.

Why Backend Systems Can Become a Critical Attack Surface

Exchanges automate massive volumes of deposits, withdrawals, and internal rebalancing via complex backend pipelines.

If these systems are compromised, attackers can manipulate transaction instructions before they reach signing modules. Strong key security alone cannot stop false data; platforms need multilayered checks verifying transaction intent and behavioral anomalies.

Hot, Warm, and Cold Wallet Security Explained

Hot wallets stay online to provide instant liquidity, exposing them to higher operational risks. Warm wallets act as an intermediate buffer, while cold wallets remain entirely isolated offline to protect long-term reserves.

Why Private-Key Protection Alone May Not Be Enough

While private keys represent the final cryptographic authorization on-chain, they rely entirely on upstream systems. If attackers spoof transaction inputs, valid keys may sign fraudulent transfers unwittingly.

What the Incident Reveals About Exchange Custody Risks

Centralized exchange users rely on internal architectures they cannot independently audit. While a large protection fund buffers financial losses, it cannot prevent service outages, proving that robust, layered custody controls are vital.

What Happens Next for Bitget?

Bitget faces several immediate priorities: finalizing its root-cause investigation, upgrading wallet infrastructure, tracking stolen assets, and safely restoring withdrawals.

Bitget’s Investigation and Root-Cause Analysis

Engineers are combing through system logs to map out the attacker’s exact entry point and understand why authorization checks failed to block spoofed inputs.

When the Full Incident Report Is Expected

Bitget initially promised a comprehensive incident report within 24 hours of its first alert, detailing underlying causes and corrective actions.

Restoring Withdrawals and Hardening Wallet Infrastructure

Withdrawal resumption depends on rigorous safety checks, enhanced validation controls, stricter authorization logic, and thorough testing by independent specialists.

Monitoring the Movement of the Stolen Funds

Forensic teams continue to shadow stolen funds across public ledgers, monitoring large ETH holdings and XRP addresses for any slip-ups as assets move toward decentralized or centralized off-ramps.

FAQ

Was Bitget Actually Hacked?

Yes. Bitget confirmed unauthorized transfers affecting roughly $351.6 million from parts of its hot and warm wallet infrastructure on September 24, 2026. Cold wallets were reported secure.

How Much Crypto Was Stolen From Bitget?

Bitget estimated the affected amount at approximately $351.6 million, encompassing XRP, Ethereum, stablecoins, and several other digital assets.

Are Bitget Withdrawals Working?

No. Withdrawals remain temporarily suspended during the security review, though deposits and internal trading continue to function normally.

Are Bitget User Funds Safe?

Bitget assures users that individual account balances are accurate and protected, backed by a User Protection Fund that exceeds the total losses.

Did Bitget Lose Its Private Keys?

No. The exchange stated that private keys were not compromised; rather, attackers gained unauthorized access to backend wallet infrastructure to manipulate transaction data.

Who Hacked Bitget?

Official attribution remains unconfirmed, though Bitget executives have indicated that the attack bears hallmarks linked to North Korean threat actors.

How Much Is Bitget’s User Protection Fund Worth?

At the time of the disclosure, Bitget’s User Protection Fund held over $464 million, comfortably exceeding the estimated $351.6 million breach.

Anastasia Viktorova

Web3 PR Specialist | KOL | Blockchain Advocate | Digital Strategy Expert based in Moscow, Russia. Focused on Web3 communications, blockchain, digital strategy, and community growth.

More from this author

Related stories

Comments 0 responses

Join the discussion

Comments are moderated and appear after review.