Exchange News

Bitget’s September hack drained $388 million from hot wallets, exchange confirms

Exchange NewsCrypto Coin Show News Team·October 6, 2026·4 min read

Bitget confirmed in a security update published through its own Academy channel that the September 24 hack drained a final verified $388 million from its hot and warm wallet infrastructure, up from the roughly $387.5 million first estimated. The disclosure matters to institutional counterparties because it tests whether the exchange’s protection fund and outside capital can absorb a nine-figure loss without disrupting custody, withdrawals or trust in its reserve reporting.

  • Bitget’s final verified tally rose to $388 million, covering 12 wallet addresses across its hot and warm tiers.
  • The exchange replenished its protection fund above $300 million and completed phased withdrawal resumption on October 2.
  • CEO Gracy Chen told BeInCrypto the company holds more than $1 billion in capital outside that fund, but could not explain how attackers learned Bitget’s internal systems.
  • $388M final verified theft, versus Bitget’s initial $387.5 million estimate
  • 131% reserve ratio across 19 assets in Bitget’s 47th proof of reserves
  • $1.07M frozen by trackers, just 0.28% of the stolen total

Bitget’s security update, confirmed as of October 6, puts the final figure at $388 million, slightly above the roughly $387.5 million first reported in the days after the attack.

The exchange said the intrusion began at 18:31 UTC on September 24, when an attacker exploited a vulnerability in a third-party security product to obtain high-level internal credentials, then used them to send fraudulent withdrawal commands that bypassed existing risk controls.

Chainalysis has attributed the theft to North Korean actors, according to its analysis, consistent with earlier state-linked exchange breaches. Crypto Coin Show first covered the breach when Bitget paused withdrawals and pointed to its replenished protection fund above $300 million days after the attack.

Bitget’s own account, detailed in its Academy update, rules out a private-key compromise and says cold wallets across all chains were untouched. The incident was limited to a portion of its hot and warm wallet infrastructure, the exchange said, in a case first detailed by BeInCrypto’s interview with CEO Gracy Chen.

Bitget Rules Out Private-Key Breach, Confirms 12 Wallets Hit

Bitget’s timeline shows its reconciliation system detected a discrepancy shortly after the first unauthorized transfers, triggering an automatic risk-control block on withdrawals across the platform.

Because private-key compromise had not yet been ruled out at that point, the wallet team moved remaining funds to cold storage and shut down signing services entirely, isolating withdrawal-related access while the security team traced the attack path.

Twelve wallet addresses tied to hot or warm infrastructure were affected, spanning assets including XRP, ETH, USDT, ZEC, ATOM, USDC, USD0, XAUt, BNB, AVAX, TRX, ALGO and TIA. Bitget Wallet, a separate non-custodial product that keeps user assets onchain under their own control, was not touched.

Mandiant and SlowMist Confirm Vendor Compromise, Withdrawals Fully Restored October 2

Independent investigation reports from Mandiant, part of Google Cloud, and SlowMist became available on September 30, and both broadly aligned with Bitget’s internal findings. The firms identified the compromise of a third-party security product as the mechanism that ultimately enabled unauthorized access to the exchange’s wallet environment, according to the bitget.com security update.

Resumption followed in stages. ETH withdrawals returned first across Ethereum, BSC, Arbitrum, Base and Optimism, followed by USDT across Ethereum, BSC, Solana and Tron once the protection fund had been rebuilt to more than $300 million.

Bitget’s 47th proof of reserves update, released during the same window, reported a 131% overall reserve ratio across 19 covered assets, before the exchange completed the plan on October 2 by restoring remaining tokens, fiat and C2C services.

Internal login credentials were revoked and reissued, and critical operations now require multiple approvals. The affected third-party vendor was notified and the exploited functionality disabled, Bitget said, while asset tracing with industry partners continues.

Chen Says Bitget Can Absorb Another Loss, But Can’t Explain How Attackers Got In

In the interview, Chen said Bitget had used bitcoin from its protection fund to meet withdrawals before rebuilding it past $300 million, a level she called sufficient even though the September theft exceeded that threshold.

She added the company holds more than $1 billion in capital outside the fund and could absorb another loss of several hundred million dollars, though the interview did not establish how much of that capital is immediately liquid.

Asked how attackers acquired enough knowledge of Bitget’s systems to build a dedicated withdrawal tool, Chen said a preliminary internal investigation found no insider involvement but she had no explanation for the attackers’ access. She said the probe could take longer than Bybit’s prior wallet breach because Bitget’s systems were more complicated.

No system, no security infrastructure is perfect or impenetrable.

Gracy Chen, CEO of Bitget

Trackers show only about $1.07 million frozen so far, roughly 0.28% of the stolen total, with the amount actually returned undisclosed. Certora’s post-interview analysis estimated that roughly $238 million left Bitget’s wallets even after the initial withdrawal block, a gap that will test whether the new multi-approval controls can stop forged transfers once an alarm sounds.

Chen also rejected the idea that protocols such as THORChain bear chief responsibility for laundering stolen exchange funds, saying permissionless infrastructure has varying technical capacity to intervene, as other chains have shown with emergency security measures of their own. She said Bitget has held preliminary talks about an exchange-and-protocol alliance against such attacks, but acknowledged aligning competitors’ interests and disclosure limits remains unresolved, a tension not unlike the aftermath of the Humanity Protocol hack earlier this year.

The CCS read. We read this less as a security story than a counterparty-risk story. Institutional desks routing liquidity through Bitget care more about the untouched capital buffer than the vulnerability patch, because self-reported reserve ratios and fund replenishments reassure depositors without proving the new approval layers would catch a repeat forged-transfer bypass. Until an independent audit covers access controls, not just custody balances, confidence rests on Chen’s word alone.

Bitget says asset tracing and recovery remain ongo

Get this in your inboxThe Crypto Coin Show newsletter covers the policy and market moves institutional crypto investors are pricing in.

Subscribe