Bitget confirms $351.6 million hot wallet breach, pauses withdrawals and leans on $464 million protection fund

Exchange NewsCrypto Coin Show News Team·September 25, 2026·5 min read

Bitget, the sixth-largest crypto exchange by trading volume, confirmed late Thursday that attackers moved approximately $351.6 million out of its hot and warm wallets in what is shaping up to be the largest centralized exchange breach of 2026. Withdrawals are paused, cold storage is untouched, and the exchange says its $464 million User Protection Fund covers the full loss.

  • Bitget detected the abnormal transfers at 18:31 UTC on September 24 and suspended withdrawals while deposits and trading stayed live.
  • On-chain researchers spotted the outflows before the announcement, with early estimates of $174 million to $183 million that roughly doubled once Bitget released its own figure.
  • The exchange has promised hourly updates and a full incident report, including root cause, within 24 hours, and has declined to speculate on the attack method.
  • $351.6M Bitget’s initial assessment of the loss from hot and warm wallets
  • $464M+ size of the User Protection Fund the exchange says covers the full amount
  • 7,111 ETH bought by the attacker in about six minutes on Arbitrum, at a roughly 5% premium
  • $684M+ total September crypto losses with Bitget included, the costliest month of 2026

The exchange said its security systems flagged the transfers at 18:31 UTC on September 24, which is 2:31 AM on September 25 in the Asian time zones where much of Bitget’s operation sits, and activated an emergency response within minutes. Suspicious addresses were flagged and reported, and law enforcement and on-chain security firms were brought in, as reported by CoinDesk.

Bitget Says the Breach Was Contained to Its Hot and Warm Wallet Layers

In a statement circulated by CEO Gracy Chen, Bitget laid out the situation in unusually direct terms. The initial assessment puts the loss at about $351.6 million. Cold wallets and what the exchange calls the vast majority of platform assets were not touched. Bitget runs a three-tier wallet architecture, and Chen said the breach was contained to a portion of the hot and warm layers.

The headline reassurance is financial. Bitget’s User Protection Fund currently holds more than $464 million, and the exchange says the entire loss falls within that coverage. In practical terms, user balances are shown as accurate and are expected to be made whole from the exchange’s own reserves rather than socialized across customers.

Notably, the exchange declined to speculate on the attack method until the investigation is complete, a restraint that stands out in an industry where early theories often outrun the facts.

Every dollar and every decision will be accounted for, transparently and in full.

Gracy Chen, CEO, Bitget

On-Chain Researchers Flagged the Outflows Before Bitget Did

The first public warning did not come from the exchange. Arkham Intelligence analyst Emmett Gallic and other independent researchers spotted the outflows before the official announcement, with early estimates landing between $174 million and $183 million, according to Decrypt. That figure roughly doubled once Bitget released its own assessment.

According to Gallic, the drained funds came from three Bitget hot wallets across multiple blockchains and were consolidated into a single address. Security firms Hacken and PeckShield also flagged the activity, with Hacken noting that Bitcoin was among the assets moved. Arkham has published a dashboard tracking the transfers.

The attacker’s early moves offer a clue to their priorities. Pseudonymous researcher DCF GOD flagged a transaction on Arbitrum in which roughly $19.7 million in USDT0 was swapped into about 7,111 ETH in the space of six minutes, paying a premium of around 5 percent above market. That kind of aggressive, price-insensitive conversion into ether is a pattern seen in prior large-scale thefts where speed matters more than execution quality. CryptoSlate puts ether at roughly 44 percent of the stolen value, spread across seven assets including ETH, BNB, AVAX, USDC, USDT and XAUT.

The Attack Vector and Attribution Remain Open Questions

Bitget has not disclosed how the wallets were compromised, whether through a private key leak, a signing infrastructure exploit, insider access or a social engineering campaign. Some social media accounts have pointed to North Korea’s Lazarus Group, which was behind the $1.4 billion Bybit hack in February 2025, but no security firm has published attribution and Bitget has not endorsed any theory.

There is also a discrepancy worth watching. Gallic’s initial analysis referenced one cold wallet among the affected addresses, while Bitget maintains its cold storage is fully secure. This may come down to how third-party labelers classify Bitget’s warm wallet tier, but it is exactly the kind of detail the 24-hour report should clarify.

Markets Shrugged, With BGB Down Under 3% and Bitcoin Flat

Bitget’s native token BGB dropped roughly 5 percent when reports first circulated before recovering to close down about 2.9 percent, trading near $1.96. Bitcoin and ether were essentially flat over the same 24-hour window, down 0.29 percent and 0.2 percent respectively.

That calm reflects two things. First, the market has absorbed larger shocks, most obviously Bybit, and has learned that a well-capitalized exchange with a funded insurance pool can withstand a nine-figure loss without a solvency crisis. Second, Bitget’s decision to keep trading and deposits live, rather than freezing the platform entirely, signaled operational confidence.

September Is Now the Costliest Month of 2026 for Crypto Security

Before Bitget, September had already logged roughly $331 million in losses across 17 incidents, including the $320 million Liquid Network sidechain drain on September 19. With Bitget added, September’s total now exceeds $684 million, overtaking April’s $646.9 million as the worst month of the year.

The timing is also awkward for Bitget specifically. The exchange is in the middle of its eighth-anniversary campaign and has been pushing its Universal Exchange strategy, an expansion into equities and foreign exchange trading. A breach of this size lands directly on the trust narrative that expansion depends on.

The CCS read. Hot wallets are a necessary operational risk for any exchange that wants fast withdrawals, and the defense is not eliminating that risk but capping it. Bitget’s three-tier architecture appears to have done that, limiting the damage to a fraction of total assets, and the $464 million protection fund is the second layer. That is why this story is about a painful loss rather than an exchange failure. The number that matters over the next few days is not the $351.6 million but how quickly withdrawals come back and whether the incident report names a root cause the rest of the industry can learn from.

Key markers over the next 24 hours are the timing of withdrawal resumption, the root cause disclosed in the incident report, whether stolen funds can be frozen at any centralized chokepoints, and whether any security firm publishes credible attribution. Bitget has set a high bar for itself on transparency, and the industry will be watching whether it clears it.

Get this in your inboxThe Crypto Coin Show newsletter covers the policy and market moves institutional crypto investors are pricing in.

Subscribe