The crypto exchange Bitget is at the center of one of 2026's largest reported security breaches. In the early hours of September 25, the platform confirmed that unauthorized transfers had drained funds from a portion of its hot and warm wallets, with an estimated impact of $351.6 million.
The Bitget hack 2026 incident triggered an immediate suspension of withdrawals, a flurry of on-chain tracking by independent analysts, and public reassurances from CEO Gracy Chen that customer funds remain protected. Here is a full breakdown of what is known so far.
At a Glance
Bitget detected unauthorized transfers at 18:31 UTC on September 24, 2026
Estimated affected funds: approximately $351.6 million
Only certain hot and warm wallets were impacted; cold wallets remain secure, per Bitget
Withdrawals temporarily suspended; deposits and trading continue as normal
Bitget's User Protection Fund, over $464 million, is expected to cover the loss
Some investigators point to a possible North Korea link, though this remains unconfirmed
Bitget Wallet, a separate self-custodial product, says it was not affected
Bitget operates a three-tier wallet architecture consisting of hot, warm, and cold storage. According to the company, the breach was limited to certain hot and warm wallet layers, while cold wallets and the overwhelming majority of platform assets were untouched.
Bitget maintains that customer account balances remain accurate and that its User Protection Fund, which currently holds more than $464 million, is sufficient to absorb the estimated loss.
Withdrawals were paused as a precaution while security checks continue, though deposits and trading have remained fully operational throughout. Bitget also drew a clear line between its exchange operations and Bitget Wallet, a separate self-custodial product.

Source: GracyBitget X Post
Detail | Information |
Incident detected | September 24, 2026, 18:31 UTC |
Estimated affected funds | ~$351.6 million |
Affected wallets | Certain hot and warm wallets |
Cold wallets | Unaffected, according to Bitget |
User Protection Fund | More than $464 million |
Withdrawals | Temporarily suspended |
Deposits and trading | Operating normally |
Full report | Expected within 24 hours |
Gracy Chen said her security team made early progress tracing the intrusion's source. According to her account, attackers compromised a critical backend system tied to Bitget's wallet infrastructure, used it to forge transfer data, and then triggered the exchange's own authorized signing process to move funds out.
Chen said a private key leak has been ruled out, which she described as eliminating a more severe risk scenario. The precise method used to breach the backend remains under active investigation, and multiple technical teams are now working on repairs and security hardening.
On-chain analysts began tracking the stolen funds almost immediately. Lookonchain reported the following breakdown: roughly 102.93 million XRP (about $157.48 million), 31,890 ETH (about $85.75 million), 34.75 million USDT, 21.05 million USDC, 19.67 million USD₮0, 3,000 XAUt (about $12.82 million), 12,719 BNB (about $9.88 million), 821,012 AVAX (about $8.38 million), and 20.59 million TRX (about $7.07 million).
Separately, monitoring service MLM flagged an address linked to the outflows and noted that early estimates of over $170 million later climbed past $183 million as funds were swapped into ETH. These tracker figures are independent estimates and should be viewed alongside, not as a replacement for, Bitget's own $351.6 million assessment.

Source: Wu Blockchain
Time | Development |
Sep. 24, 18:31 UTC | Bitget detects unauthorized transfers |
Minutes later | Emergency response activated |
Shortly after | Abnormal addresses flagged and reported |
Sep. 25 | Withdrawals suspended |
Initial assessment | ~$351.6 million estimated affected |
Investigation update | Wallet backend identified as compromised |
Latest update | Further outflows are contained |
Ongoing | Security hardening and recovery prep underway |
Beyond the protection fund, Chen said Bitget holds more than $1 billion in its own resources. Addressing concerns about a potential rush of withdrawals once services resume, she stated that Bitget is "absolutely not another FTX hack" and argued the exchange can manage concentrated withdrawal demand.
She also compared Bitget's retail scale to Bybit's, noting that Bybit crypto hack previously absorbed a loss of around $1.5 billion, implying Bitget should be able to manage a loss north of $300 million. These remain statements from Bitget's leadership rather than independently verified conclusions.

Source: Gracy Chen X
Chen said some IP addresses tied to the attack matched VPN patterns associated with a North Korea-linked group. Separately, blockchain investigator Specter reported that stolen XRP, once bridged across chains, could be traced to funds from a $24 million AFX attack in July, which had previously been attributed to the group TraderTraitor.
Based on that link, Specter suggested Lazarus Group could be responsible. These remain third-party attributions rather than a confirmed identification, and Bitget's own investigation is still underway.
Bybit co-founder and CEO Ben Zhou said his team is ready to assist Bitget and is updating its LazarusBounty platform to help trace the stolen assets. Zhou noted that Bitget had previously helped Bybit following its own security incident. Law enforcement and on-chain security firms have also been formally notified.

Source: Karry Web3 Post
Bitget Wallet, led by Karry, emphasized that it operates independently as a self-custodial product where users control their own assets on-chain. Following a precautionary review, the team reported no impact on its systems or user funds. It urged users to remain alert to phishing sites, fake support accounts, and impersonators, and never to share private keys or seed phrases.
Key questions remain open: when withdrawals will resume, what the exact intrusion method was, whether the $351.6 million figure will hold, and whether the North Korea link will be confirmed. The crypto exchange has committed to hourly updates and a full incident report, including root cause analysis and remediation steps, within 24 hours.
The Bitget crypto hack 2026 episode is still developing, and much of what's known comes directly from company statements and independent on-chain trackers rather than a completed forensic investigation.
It has moved quickly to reassure users that funds are covered and that cold wallets were untouched, but the full picture, including the precise attack vector and confirmed attribution, will only emerge once the promised incident report is released.
Disclaimer: This article is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency markets are volatile and carry risk. Readers should conduct their own research and consult a qualified professional before making any financial decisions.