Bitget Exchange Hack: How $387.5M Was Stolen & Who Is Suspected?
Bitget Exchange Hack: $387.5 Million Crypto Breach Explained — How It Happened, Who Is Suspected, and What Happens Next
Bitget says approximately $387.5 million in crypto assets were transferred to attacker-controlled addresses following the September 24, 2026 security incident.
Jump to a section
The cryptocurrency industry is facing another major security incident after Bitget exchange was hacked on September 24, 2026, resulting in the unauthorized transfer of digital assets worth approximately $387.5 million to attacker-controlled addresses.
The incident initially appeared to involve about $351.6 million, but Bitget later revised the figure upward after on-chain investigators identified additional affected assets on Zcash and TRON. Bitget says the revised figure represents a more complete accounting of the same incident, not a second wave of theft.
The hack has attracted particular attention because the attackers apparently did not simply steal private keys from Bitget's cold storage. Instead, investigators say the attackers compromised a backend component of the exchange's wallet infrastructure and manipulated transaction information to get unauthorized transfers approved.
Bitget Hack at a Glance
| Detail | What is currently known |
|---|---|
| Date of incident | September 24, 2026 |
| Initial estimated loss | Approximately $351.6 million |
| Revised amount transferred | Approximately $387.5 million |
| Affected infrastructure | Portions of Bitget's hot and warm wallet systems |
| Cold wallets | Reported unaffected |
| Private keys | Bitget says they were not compromised |
| Attack method | Backend wallet-system compromise and transaction-data manipulation |
| Affected assets | XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX, TRX and others |
| Investigation partners | Mandiant and SlowMist |
| Suspected perpetrator | Possible DPRK/North Korean-linked hacking group |
| User Protection Fund | More than $464 million at time of initial announcement |
| Withdrawal restart | Phased, beginning September 28 |
Sources: Bitget, The Block and security-research reporting.
What Happened in the Bitget Exchange Hack?
The incident began on September 24, 2026, when Bitget's security systems detected unauthorized transfers from some of its hot wallets at approximately 18:31 UTC.
Hot wallets are cryptocurrency wallets connected to systems that facilitate active transactions and withdrawals — fundamentally different from cold wallets, which are kept offline for enhanced security.
Bitget immediately activated its emergency response procedures, identified suspicious addresses, and temporarily suspended withdrawals while its security team investigated. At first, the exchange estimated approximately $351.6 million worth of assets had been affected. Further blockchain analysis identified additional transfers involving Zcash and TRON, leading Bitget to revise its estimate to approximately $387.5 million. The exchange emphasized this increase did not represent additional unauthorized transfers — investigators simply obtained a more complete picture of the original incident.
How Was Bitget Hacked?
One of the most important aspects of this hack is that available evidence does not point to a straightforward theft of Bitget's private keys. According to Bitget CEO Gracy Chen and subsequent reporting, attackers compromised a backend system associated with Bitget's wallet infrastructure, apparently manipulating or spoofing transaction information and then using the legitimate authorization mechanism to initiate transfers.
This distinction matters. A conventional crypto-wallet theft might involve an attacker obtaining a private key or seed phrase and directly signing blockchain transactions. The Bitget incident appears different: the attackers reportedly did not obtain the private keys associated with Bitget's cold wallets, and the exchange says that separate cold-wallet infrastructure remained secure. The separate self-custodial Bitget Wallet product was also reported as unaffected.
Bitget subsequently stated it had identified the underlying vulnerability and remediated it. Mandiant and SlowMist are assisting with the continuing investigation and security validation.
Why the attack method matters
The incident demonstrates that cryptocurrency security is not exclusively about protecting private keys. Even when blockchain wallets themselves are properly secured, an exchange can have many layers of infrastructure between a user request and an eventual blockchain transaction, including:
- Wallet-management systems
- Backend APIs
- Transaction databases
- Signing services
- Authorization systems
- Risk-management systems
- Monitoring infrastructure
- Internal administrative tools
If an attacker compromises a sufficiently privileged backend component, they may be able to manipulate the information that legitimate security systems rely upon — which is why this incident is significant from a cybersecurity perspective.
Which Cryptocurrencies Were Affected?
The Bitget exchange hack involved multiple digital assets and blockchain networks. According to Bitget's latest incident update, confirmed affected assets include:
- XRP
- Ethereum (ETH)
- Tether (USDT)
- Zcash (ZEC)
- USD Coin (USDC)
- USDT0
- Tether Gold (XAUt)
- BNB
- Avalanche (AVAX)
- TRON (TRX)
The incident spans Ethereum and several EVM-compatible networks as well as the XRP Ledger, Zcash and TRON. Because blockchain transactions are publicly observable, researchers and security companies can trace movements after funds leave an exchange. Bitget has identified several attacker-controlled addresses and made fund-tracing information available to security researchers and other industry participants — important because stolen cryptocurrency can sometimes be frozen before it reaches a service where it could be converted or moved further.
Were Bitget User Funds Stolen?
Bitget says customer account balances were not affected and that the financial impact of the incident is covered by its User Protection Fund. At the time of the initial announcement, Bitget said its protection fund contained more than $464 million, exceeding the initial estimated $351.6 million loss.
It's important to distinguish between two things: unauthorized transfers from Bitget's exchange wallet infrastructure, and a reduction in individual customers' displayed account balances — these are not necessarily the same event. Bitget's position is that user balances remain intact while the exchange absorbs the loss through its protection mechanisms. The company also states the incident remains contained and no further unauthorized transfers are possible following remediation of the vulnerability.
Who Is Suspected of the Bitget Hack?
Bitget CEO Gracy Chen has publicly suggested the attack may be connected to a North Korean-linked hacking group, based on preliminary technical indicators — including IP addresses whose VPN characteristics appeared similar to infrastructure previously associated with a North Korean hacking group, and an attack pattern resembling previous DPRK-linked operations.
Blockchain intelligence firm Elliptic has also assessed the attack as highly likely linked to the DPRK, citing infrastructure overlap and connections between funds from the Bitget incident and addresses associated with earlier DPRK-attributed attacks.
Why North Korean hackers are being considered
North Korea-linked hacking groups have been repeatedly associated by governments and blockchain intelligence companies with large-scale cryptocurrency theft targeting exchanges, blockchain projects, DeFi protocols, wallet infrastructure, crypto companies, developers, employees/contractors and digital asset service providers. Elliptic said the Bitget attack pushed its tracked total of DPRK-attributed cryptocurrency theft during 2026 above $1 billion — a figure reflecting Elliptic's own attribution and tracking methodology, not a court determination.
Bitget's Response to the Hack
Bitget moved quickly after detecting the unauthorized transfers. The exchange:
- Activated its emergency security response
- Identified suspicious transaction addresses
- Suspended withdrawals
- Notified law enforcement
- Engaged external cybersecurity specialists
- Began on-chain fund tracing
- Identified and fixed the underlying vulnerability
- Began additional security validation
- Established a recovery bounty program
- Prepared a phased withdrawal restart
Mandiant and SlowMist are assisting with the investigation and security checks, and Bitget reports that some affected assets have already been frozen through coordination with industry partners.
Bitget Launches Recovery Bounty Program
According to Bitget, eligible participants can receive a bounty for actions that directly result in affected funds being frozen or recovered. The published program offers:
- 5% of successfully frozen funds to an eligible contributor whose voluntary efforts directly caused the freeze.
- 5% of successfully recovered funds to an eligible contributor whose voluntary efforts directly contributed to recovery.
Bitget says final determination of eligibility and bounty amounts remains with the exchange. The program highlights both an advantage and a challenge of blockchain-based investigations: because transactions are publicly recorded, researchers can monitor addresses and trace stolen assets — but tracing is not the same as recovering, since funds may move through multiple wallets, DEXs, bridges or mixers.
Bitget Withdrawals: When Will They Resume?
Bitget has published a phased withdrawal restoration schedule. Trading and deposits have continued throughout.
September 28, 2026 — BTC
Bitcoin withdrawals are scheduled to resume at 08:00 UTC.
September 29, 2026 — ETH
Ethereum withdrawals return at 08:00 UTC across: Ethereum, BNB Smart Chain, Arbitrum, Base, Optimism.
September 30, 2026 — USDT
USDT withdrawals return at 08:00 UTC across: Ethereum, BNB Smart Chain, Solana, TRON.
October 2, 2026 — Remaining services
Other tokens, fiat services and peer-to-peer services are scheduled for the final phase.
Bitget says the phased approach allows additional security validation before each service is restored.
What the Bitget Hack Means for Crypto Security
1. Private-key security is not enough
Exchanges need to protect not only private keys but also every system that can influence transaction authorization — backend systems, APIs, signing infrastructure and administrative controls can all become attack surfaces.
2. Hot wallets remain high-value targets
Hot wallets are convenient because they enable fast transactions, but because they're connected to operational infrastructure, they're also attractive targets — one reason major exchanges separate hot, warm and cold storage.
3. Transaction authorization needs multiple layers
A compromised backend should ideally not be able to independently authorize large transfers. The incident highlights the importance of:
- Multi-party authorization
- Transaction simulation
- Independent policy engines
- Address allowlisting
- Withdrawal limits
- Anomaly detection
- Hardware-backed signing
- Real-time monitoring
- Emergency circuit breakers
4. On-chain transparency can help investigations
Public blockchains let investigators follow transactions after assets leave an exchange, and security companies can flag suspicious addresses to other industry participants. That doesn't guarantee recovery, but it can make laundering stolen cryptocurrency more difficult.
What Should Bitget Users Do Now?
Monitor official announcements
Avoid relying solely on posts circulating on social media.
Be careful of phishing scams
Major exchange hacks often create opportunities for scammers, who may create fake sites or messages claiming to offer compensation, refunds, emergency withdrawals, recovery services, account verification or security updates. Never provide your seed phrase or private keys in response to an unsolicited message.
Verify withdrawal networks
When withdrawals reopen, carefully verify the selected blockchain network and destination address before confirming transactions.
Enable account security controls
Review available security settings, including two-factor authentication, anti-phishing codes, withdrawal address controls, device management and login alerts.
Stay Ahead of the Next Exchange Hack
Get plain-English breakdowns of major crypto security incidents, scam alerts and safety checklists — before they hit the headlines.
Get Free Crypto Security Alerts →Final Takeaway: What We Know About the Bitget Hack
The Bitget exchange hack on September 24, 2026 resulted in approximately $387.5 million in cryptocurrency being transferred to attacker-controlled addresses, according to Bitget's latest accounting. The initial estimate of $351.6 million increased after investigators included additional Zcash and TRON transfers.
Available evidence indicates the attackers compromised a backend component of Bitget's wallet infrastructure and manipulated transaction information, rather than simply stealing the exchange's cold-wallet private keys. Bitget says its cold wallets remained secure and its separate Bitget Wallet product was unaffected.
The investigation has also produced preliminary indications pointing toward North Korean/DPRK-linked hackers, although that remains a suspected attribution rather than a conclusively established perpetrator. Bitget says the vulnerability has been fixed, its protection fund covers the financial impact, and it's working with Mandiant, SlowMist, law enforcement and other blockchain companies to trace and recover assets.
The next major milestone is the phased reopening of withdrawals beginning September 28, 2026, starting with BTC and continuing through ETH, USDT and other assets and services. For the wider crypto industry, the incident is a reminder that exchange security depends on much more than protecting private keys — backend infrastructure, authorization systems, transaction integrity and operational controls can all become critical attack surfaces.
As the investigation continues, additional details about the exact attack path, attribution and recovery of stolen funds may emerge. For now, the Bitget incident remains a major crypto news story and an important case study in the evolving cybersecurity risks facing centralized cryptocurrency exchanges.
This article is for informational purposes only and is not financial advice. Details surrounding the Bitget security incident remain subject to investigation and may change as new evidence becomes available.
0 Comments: