Headlines
Loading...
Bitget exchange hack: $387.5 million crypto theft explained

Bitget Exchange Hack: $387.5 Million Crypto Breach Explained — How It Happened, Who Is Suspected, and What Happens Next

Bitget says approximately $387.5 million in crypto assets were transferred to attacker-controlled addresses following the September 24, 2026 security incident.

$387.5MFinal loss estimate
Sep 24Date of hack
BackendAttack vector
DPRK-linkedSuspected actor
$464M+Protection fund
Sep 28Withdrawals resume
Jump to a section

The cryptocurrency industry is facing another major security incident after Bitget exchange was hacked on September 24, 2026, resulting in the unauthorized transfer of digital assets worth approximately $387.5 million to attacker-controlled addresses.

The incident initially appeared to involve about $351.6 million, but Bitget later revised the figure upward after on-chain investigators identified additional affected assets on Zcash and TRON. Bitget says the revised figure represents a more complete accounting of the same incident, not a second wave of theft.

The hack has attracted particular attention because the attackers apparently did not simply steal private keys from Bitget's cold storage. Instead, investigators say the attackers compromised a backend component of the exchange's wallet infrastructure and manipulated transaction information to get unauthorized transfers approved.

There is growing suspicion the attack may be connected to North Korean-linked cybercrime groups, although that attribution remains an investigative assessment rather than a formally established fact.

Bitget Hack at a Glance

DetailWhat is currently known
Date of incidentSeptember 24, 2026
Initial estimated lossApproximately $351.6 million
Revised amount transferredApproximately $387.5 million
Affected infrastructurePortions of Bitget's hot and warm wallet systems
Cold walletsReported unaffected
Private keysBitget says they were not compromised
Attack methodBackend wallet-system compromise and transaction-data manipulation
Affected assetsXRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX, TRX and others
Investigation partnersMandiant and SlowMist
Suspected perpetratorPossible DPRK/North Korean-linked hacking group
User Protection FundMore than $464 million at time of initial announcement
Withdrawal restartPhased, beginning September 28

Sources: Bitget, The Block and security-research reporting.

What Happened in the Bitget Exchange Hack?

The incident began on September 24, 2026, when Bitget's security systems detected unauthorized transfers from some of its hot wallets at approximately 18:31 UTC.

Hot wallets are cryptocurrency wallets connected to systems that facilitate active transactions and withdrawals — fundamentally different from cold wallets, which are kept offline for enhanced security.

Bitget immediately activated its emergency response procedures, identified suspicious addresses, and temporarily suspended withdrawals while its security team investigated. At first, the exchange estimated approximately $351.6 million worth of assets had been affected. Further blockchain analysis identified additional transfers involving Zcash and TRON, leading Bitget to revise its estimate to approximately $387.5 million. The exchange emphasized this increase did not represent additional unauthorized transfers — investigators simply obtained a more complete picture of the original incident.

How Was Bitget Hacked?

One of the most important aspects of this hack is that available evidence does not point to a straightforward theft of Bitget's private keys. According to Bitget CEO Gracy Chen and subsequent reporting, attackers compromised a backend system associated with Bitget's wallet infrastructure, apparently manipulating or spoofing transaction information and then using the legitimate authorization mechanism to initiate transfers.

Simplified attack path: Backend compromise → transaction information manipulated → authorization process triggered → assets transferred to attacker-controlled addresses.

This distinction matters. A conventional crypto-wallet theft might involve an attacker obtaining a private key or seed phrase and directly signing blockchain transactions. The Bitget incident appears different: the attackers reportedly did not obtain the private keys associated with Bitget's cold wallets, and the exchange says that separate cold-wallet infrastructure remained secure. The separate self-custodial Bitget Wallet product was also reported as unaffected.

Bitget subsequently stated it had identified the underlying vulnerability and remediated it. Mandiant and SlowMist are assisting with the continuing investigation and security validation.

Why the attack method matters

The incident demonstrates that cryptocurrency security is not exclusively about protecting private keys. Even when blockchain wallets themselves are properly secured, an exchange can have many layers of infrastructure between a user request and an eventual blockchain transaction, including:

  • Wallet-management systems
  • Backend APIs
  • Transaction databases
  • Signing services
  • Authorization systems
  • Risk-management systems
  • Monitoring infrastructure
  • Internal administrative tools

If an attacker compromises a sufficiently privileged backend component, they may be able to manipulate the information that legitimate security systems rely upon — which is why this incident is significant from a cybersecurity perspective.

Which Cryptocurrencies Were Affected?

The Bitget exchange hack involved multiple digital assets and blockchain networks. According to Bitget's latest incident update, confirmed affected assets include:

  • XRP
  • Ethereum (ETH)
  • Tether (USDT)
  • Zcash (ZEC)
  • USD Coin (USDC)
  • USDT0
  • Tether Gold (XAUt)
  • BNB
  • Avalanche (AVAX)
  • TRON (TRX)

The incident spans Ethereum and several EVM-compatible networks as well as the XRP Ledger, Zcash and TRON. Because blockchain transactions are publicly observable, researchers and security companies can trace movements after funds leave an exchange. Bitget has identified several attacker-controlled addresses and made fund-tracing information available to security researchers and other industry participants — important because stolen cryptocurrency can sometimes be frozen before it reaches a service where it could be converted or moved further.

Were Bitget User Funds Stolen?

Bitget says customer account balances were not affected and that the financial impact of the incident is covered by its User Protection Fund. At the time of the initial announcement, Bitget said its protection fund contained more than $464 million, exceeding the initial estimated $351.6 million loss.

It's important to distinguish between two things: unauthorized transfers from Bitget's exchange wallet infrastructure, and a reduction in individual customers' displayed account balances — these are not necessarily the same event. Bitget's position is that user balances remain intact while the exchange absorbs the loss through its protection mechanisms. The company also states the incident remains contained and no further unauthorized transfers are possible following remediation of the vulnerability.

Who Is Suspected of the Bitget Hack?

Bitget CEO Gracy Chen has publicly suggested the attack may be connected to a North Korean-linked hacking group, based on preliminary technical indicators — including IP addresses whose VPN characteristics appeared similar to infrastructure previously associated with a North Korean hacking group, and an attack pattern resembling previous DPRK-linked operations.

Blockchain intelligence firm Elliptic has also assessed the attack as highly likely linked to the DPRK, citing infrastructure overlap and connections between funds from the Bitget incident and addresses associated with earlier DPRK-attributed attacks.

North Korea has not been established as the perpetrator through a final public law-enforcement finding based on currently available information. The appropriate description at this stage is that North Korean/DPRK-linked cybercriminals are suspected, based on preliminary technical and blockchain intelligence. Mandiant, SlowMist, Bitget and law-enforcement authorities remain involved in the investigation.
Why North Korean hackers are being considered

North Korea-linked hacking groups have been repeatedly associated by governments and blockchain intelligence companies with large-scale cryptocurrency theft targeting exchanges, blockchain projects, DeFi protocols, wallet infrastructure, crypto companies, developers, employees/contractors and digital asset service providers. Elliptic said the Bitget attack pushed its tracked total of DPRK-attributed cryptocurrency theft during 2026 above $1 billion — a figure reflecting Elliptic's own attribution and tracking methodology, not a court determination.

Bitget's Response to the Hack

Bitget moved quickly after detecting the unauthorized transfers. The exchange:

  1. Activated its emergency security response
  2. Identified suspicious transaction addresses
  3. Suspended withdrawals
  4. Notified law enforcement
  5. Engaged external cybersecurity specialists
  6. Began on-chain fund tracing
  7. Identified and fixed the underlying vulnerability
  8. Began additional security validation
  9. Established a recovery bounty program
  10. Prepared a phased withdrawal restart

Mandiant and SlowMist are assisting with the investigation and security checks, and Bitget reports that some affected assets have already been frozen through coordination with industry partners.

Bitget Launches Recovery Bounty Program

According to Bitget, eligible participants can receive a bounty for actions that directly result in affected funds being frozen or recovered. The published program offers:

  • 5% of successfully frozen funds to an eligible contributor whose voluntary efforts directly caused the freeze.
  • 5% of successfully recovered funds to an eligible contributor whose voluntary efforts directly contributed to recovery.

Bitget says final determination of eligibility and bounty amounts remains with the exchange. The program highlights both an advantage and a challenge of blockchain-based investigations: because transactions are publicly recorded, researchers can monitor addresses and trace stolen assets — but tracing is not the same as recovering, since funds may move through multiple wallets, DEXs, bridges or mixers.

Bitget Withdrawals: When Will They Resume?

Bitget has published a phased withdrawal restoration schedule. Trading and deposits have continued throughout.

September 28, 2026 — BTC

Bitcoin withdrawals are scheduled to resume at 08:00 UTC.

September 29, 2026 — ETH

Ethereum withdrawals return at 08:00 UTC across: Ethereum, BNB Smart Chain, Arbitrum, Base, Optimism.

September 30, 2026 — USDT

USDT withdrawals return at 08:00 UTC across: Ethereum, BNB Smart Chain, Solana, TRON.

October 2, 2026 — Remaining services

Other tokens, fiat services and peer-to-peer services are scheduled for the final phase.

Bitget says the phased approach allows additional security validation before each service is restored.

What the Bitget Hack Means for Crypto Security

1. Private-key security is not enough

Exchanges need to protect not only private keys but also every system that can influence transaction authorization — backend systems, APIs, signing infrastructure and administrative controls can all become attack surfaces.

2. Hot wallets remain high-value targets

Hot wallets are convenient because they enable fast transactions, but because they're connected to operational infrastructure, they're also attractive targets — one reason major exchanges separate hot, warm and cold storage.

3. Transaction authorization needs multiple layers

A compromised backend should ideally not be able to independently authorize large transfers. The incident highlights the importance of:

  • Multi-party authorization
  • Transaction simulation
  • Independent policy engines
  • Address allowlisting
  • Withdrawal limits
  • Anomaly detection
  • Hardware-backed signing
  • Real-time monitoring
  • Emergency circuit breakers

4. On-chain transparency can help investigations

Public blockchains let investigators follow transactions after assets leave an exchange, and security companies can flag suspicious addresses to other industry participants. That doesn't guarantee recovery, but it can make laundering stolen cryptocurrency more difficult.

What Should Bitget Users Do Now?

Monitor official announcements

Avoid relying solely on posts circulating on social media.

Be careful of phishing scams

Major exchange hacks often create opportunities for scammers, who may create fake sites or messages claiming to offer compensation, refunds, emergency withdrawals, recovery services, account verification or security updates. Never provide your seed phrase or private keys in response to an unsolicited message.

Verify withdrawal networks

When withdrawals reopen, carefully verify the selected blockchain network and destination address before confirming transactions.

Enable account security controls

Review available security settings, including two-factor authentication, anti-phishing codes, withdrawal address controls, device management and login alerts.

Stay Ahead of the Next Exchange Hack

Get plain-English breakdowns of major crypto security incidents, scam alerts and safety checklists — before they hit the headlines.

Get Free Crypto Security Alerts →

Final Takeaway: What We Know About the Bitget Hack

The Bitget exchange hack on September 24, 2026 resulted in approximately $387.5 million in cryptocurrency being transferred to attacker-controlled addresses, according to Bitget's latest accounting. The initial estimate of $351.6 million increased after investigators included additional Zcash and TRON transfers.

Available evidence indicates the attackers compromised a backend component of Bitget's wallet infrastructure and manipulated transaction information, rather than simply stealing the exchange's cold-wallet private keys. Bitget says its cold wallets remained secure and its separate Bitget Wallet product was unaffected.

The investigation has also produced preliminary indications pointing toward North Korean/DPRK-linked hackers, although that remains a suspected attribution rather than a conclusively established perpetrator. Bitget says the vulnerability has been fixed, its protection fund covers the financial impact, and it's working with Mandiant, SlowMist, law enforcement and other blockchain companies to trace and recover assets.

The next major milestone is the phased reopening of withdrawals beginning September 28, 2026, starting with BTC and continuing through ETH, USDT and other assets and services. For the wider crypto industry, the incident is a reminder that exchange security depends on much more than protecting private keys — backend infrastructure, authorization systems, transaction integrity and operational controls can all become critical attack surfaces.

As the investigation continues, additional details about the exact attack path, attribution and recovery of stolen funds may emerge. For now, the Bitget incident remains a major crypto news story and an important case study in the evolving cybersecurity risks facing centralized cryptocurrency exchanges.

This article is for informational purposes only and is not financial advice. Details surrounding the Bitget security incident remain subject to investigation and may change as new evidence becomes available.

Earn Online Guru covers crypto, Web3, and online-income opportunities with a focus on clear, practical analysis over hype. The team tracks market trends, emerging tokens, and passive-income strategies, breaking down complex blockchain concepts into guidance readers can actually act on. Every piece is researched against current market data and updated as the space evolves, with a standing reminder that crypto markets are volatile and nothing here should be taken as financial advice.


Est. content coverage: crypto markets · DeFi · Web3 earning · blockchain gaming ·AI

0 Comments: