Skip to content

Bitget Hack: $351 Million Drained as Withdrawals Freeze and Crypto Exchange Scrambles to Contain Fallout

Altcoins16 min read

Bitget Hack: $351 Million Drained as Withdrawals Freeze and Crypto Exchange Scrambles to Contain Fallout

The Bitget crypto exchange experienced a major security breach on 24 September 2026. Approximately $351.6 million in unauthorized transfers occurred from the exchange’s hot and warm wallet facilities.

Withdrawals were suspended while deposits and trading functioned normally. Bitget states that customer balances remain accurate and its protection fund can cover the estimated loss. Investigatory attention is focused on the backend compromise and asset transference, which may involve a North Korean connection.

Related: Bitget $351.6M Hack Probe Points to Backend Breach as Private-Key Leak Is Ruled Out

What Happened in the Bitget Hack?

The Bitget security breach began as anomalous wallet transfers took place. Initial on-chain estimates captured only a portion of the total value. Bitget later confirmed a substantially increased total across a range of networks after reviewing the affected transfers.

Bitget Confirms $351.6 Million in Unauthorized Transfers

The Bitget exchange confirmed that approximately $351.6 million in digital assets were impacted by unauthorized transfers. The affected amount represented part of its operational wallet infrastructure. The Bitget $351.6 million hack ranks as one of the largest exchange security incidents reported during 2026. Initial estimates were lower due to not tracking across every involved network.

Bitget stated that the affected amount was within its User Protection Fund coverage. Customer account balances reportedly remained unaltered despite the loss.

When Bitget Detected the Attack

Bitget detected unauthorized activity at 18:31 UTC on 24 September. Its security systems identified transfers that did not match expected wallet operations.

Emergency procedures began within minutes of detecting suspicious transactions. Security teams initiated system isolation and review of the unauthorized transfer movements. The exchange then began identifying receiving addresses and consulting external security specialists. Law enforcement agencies were also alerted as the investigation progressed.

Read More: $320M Bitcoin Hack: What Really Happened to Liquid Network?

Which Bitget Wallets Were Affected?

The Bitget hack impacted parts of the exchange’s hot and warm wallet layers. These wallets provided liquidity and operational infrastructure to the platform.

Hot wallets maintained an online presence due to the requirement for providing fast withdrawals and everyday transfers. Warm wallets acted as an intermediary between online liquidity and offline storage. Bitget stated that its cold wallets remained secure throughout the incident. The exchange had a three-tier architecture separating hot, warm, and cold storage facilities.

Category Details
Incident Unauthorized transfers from Bitget wallet infrastructure
Date September 24, 2026
Estimated Amount Approximately $351.6 million
Affected Infrastructure Parts of hot and warm wallet systems
Cold Wallets Bitget says they were not affected
Main Assets XRP, Ethereum, stablecoins, BNB, AVAX, TRX and other assets
Withdrawals Temporarily suspended
Deposits Operational
Trading Operational
Private Keys Bitget says they were not compromised
User Balances Bitget says balances remain accurate
Protection Fund More than $464 million
Investigation Backend compromise and movement of affected assets under investigation
Attacker Attribution Not confirmed
Next Steps Root-cause analysis, system remediation and withdrawal restoration

How Did the $351 Million Bitget Hack Happen?

Initial information indicated that the attackers did not steal wallet private keys. Instead, Bitget stated that a critical backend component supporting its wallet infrastructure was compromised.

Attackers Targeted Bitget’s Backend Wallet Infrastructure

The attackers reportedly accessed a critical component within Bitget’s wallet environment. This access allowed them to interfere with transaction processing activities.

This distinction is important since a wallet can retain secure private keys while the surrounding infrastructure is compromised. Exchanges involve many systems before transactions reach the signing stage. The Bitget exploit demonstrated the risks presented by a broader ecosystem. Backend services could be targeted by sophisticated attackers and serve as a conduit for asset transfers.

Read More: FBI Crypto Crime Forum Targets Scams, Hacks and North Korean Threats

How Spoofed Transaction Data Triggered the Authorization Process

According to Bitget’s initial explanation, attackers altered transaction data within the compromised backend environment. The modified information was then submitted to the authorization process.

This mechanism seemingly caused Bitget’s infrastructure to approve transfers that should not have been initiated. Valid cryptographic signatures could be utilized to authorize malicious transaction instructions. Such an attack targeted the decision-making pipeline around wallet signing processes. Security controls are needed to verify transaction intent before final authorization.

Bitget Says Private Keys Were Not Compromised

Bitget stated that investigators ruled out private key compromise. This finding distinguished the incident from a conventional Bitget hot wallet hack involving stolen signing keys.

The attackers seemingly manipulated infrastructure that supplied information to the authorization system. This allowed assets to be moved without directly extracting private keys. Cold-storage keys also remained unaffected, according to Bitget. The company stated that the compromise was contained within the operational wallet layers.

What Remains Unknown About the Attack Vector

Investigators need to determine how the attackers entered the backend environment. Bitget has not provided a full technical explanation of the intrusion.

Several possibilities could exist with regard to a backend compromise. Software vulnerabilities, compromised credentials, third-party systems, and internal weaknesses all present potential avenues. No specific entry method should be considered confirmed at this time. A root-cause analysis should clarify the initial access point before determining any control failures.

Where Did the Stolen Crypto Go?

The ill-gotten crypto has changed hands, as investigators report that it has already passed through several exchange wallets not controlled by Bitget, in the process switching between different blockchains to obscure their trail.

Some of the proceeds of the heist have been converted to ether, while others remained in deposits across these addresses, where it is being watched if they will be moved via bridges, exchanges, or decentralized swaps.

XRP, Ethereum and Stablecoins Account for Major Outflows

XRP represented one of the largest components identified after expanding tracking beyond Ethereum-compatible networks. Roughly 102.9 million XRP appeared in the identified transfers.

Ethereum also represented a significant share of the stolen assets. Around 31,890 ETH appeared in one of the most tracked asset breakdowns. Stablecoins included USDT, USDC, and USDT0. Other affected assets were BNB, AVAX, TRX, and tokenized gold.

The Bitget hack XRP component explained why initial estimates underrepresented the total damage. Monitoring was primarily focused on Ethereum-compatible networks initially.

How the Attackers Moved Funds Across Multiple Networks

Attackers distributed the assets across several blockchain networks. This created multiple transaction trails for investigators to follow.

Ethereum-compatible networks accounted for a substantial portion of the activity. XRP movements created another major branch outside of the EVM-focused tracking systems. Bridging and swapping activity further modified the composition of the stolen portfolio. Each conversion complicated following the original assets directly.

Why the Stolen Assets Were Swapped Into Ethereum

Attackers converted substantial stablecoins and other stolen tokens into Ethereum. This reduced exposure to issuer-controlled freezing mechanisms.

Centralized stablecoin issuers could freeze specific tokens associated with criminal activity. Native ETH lacked a comparable centralized issuer with control capabilities. The Bitget hack Ethereum trail became a focal point for investigators. Large conversions also generated visible on-chain movements for analysts.

Tracking the Addresses Linked to the Bitget Exploit

Bitget stated that abnormal transfer addresses were identified after the attack. Security companies monitored subsequent movements from the flagged destinations.

Blockchain transparency made many movements publicly observable, but identifying the people controlling specific addresses required forensic evidence. Investigators could also follow bridges, decentralized exchanges, and other services involved in laundering attempts. Cooperation from centralized services could be crucial when the stolen funds reached identifiable accounts.

Why Bitget Froze Withdrawals

The Bitget withdrawal freeze became one of the most immediate consequences for customers. The exchange suspended withdrawals as it reviewed its wallet infrastructure.

Bitget Suspends Withdrawals After Detecting Unauthorized Transfers

Bitget withdrawals were suspended as a precaution following the detection of unauthorized activity. This reduced further exposure during the ongoing investigation. Keeping withdrawals closed granted security teams time to inspect transaction systems before re-opening external transfers. It also restricted potential exploitation of remaining vulnerabilities.

The Bitget withdrawals suspended status did not indicate that customer account balances disappeared. Bitget stated that balances remained accurate inside the platform.

Deposits and Trading Remain Operational

Bitget kept deposits and trading operational after the breach. This allowed users to continue utilizing major internal exchange functions.

Trading generally involved changes within the exchange’s internal ledger, rather than immediate blockchain transfers. Withdrawals required assets to exit controlled wallets. This distinction explained why one service remained available while another was paused. External transfers presented greater security implications during wallet remediation.

When Will Bitget Withdrawals Resume?

Bitget has not set a guaranteed re-opening time for withdrawals. The company stated that services would resume after its security review was completed.

Security teams needed confidence that the compromised pathway had been removed before re-enabling external transfers. Re-opening too soon could generate unnecessary exposure to another unauthorized transfer.

Customers should therefore expect restoration to rely on technical verification rather than a set deadline. Further updates would clarify the withdrawal timeline.

What Bitget Says About Further Unauthorized Transfers

Bitget stated that the incident had been contained and further unauthorized transfers through the identified pathway were no longer possible. Security work continued, however.

Containment did not guarantee that every underlying weakness had been remediated. Investigators also needed to establish the precise root cause. Further monitoring remained crucial after withdrawals returned. Attackers could establish persistence mechanisms before defenders isolated compromised infrastructure.

Are Bitget User Funds Safe After the Hack?

Bitget stated that customer assets remained protected despite the $351.6 million loss. Its position relied partly on the size of its User Protection Fund.

Bitget Says Customer Balances Remain Accurate

According to Bitget, customer account balances remained accurate following the incident. The exchange had not announced losses allocated directly to individual users.

This meant that the Bitget hack impacted exchange-controlled wallet assets rather than reducing displayed customer balances. Operational restrictions still restricted withdrawals during the review.

Users should distinguish between accurate internal balances and immediate access to external withdrawals. Both issues were relevant in assessing the practical impact.

How the $464 Million User Protection Fund Covers the Loss

The Bitget user protection fund held more than $464 million when the exchange disclosed the incident. That exceeds the estimated $351.6 million loss.

Bitget stated that the entire loss would fall within the fund’s coverage. The protection mechanism had been designed to provide financial support during exceptional securities incidents. A fund in excess of the headline loss presented an important financial buffer. However, customers would also watch how quickly normal withdrawal functionality resumed.

Why Cold Wallets Were Not Affected

Cold wallets remained separated from systems required for routine online transactions. This reduced exposure to attacks targeting internet-connected infrastructure.

Bitget stated that its cold storage had remained fully secure during the breach. The compromised area involved parts of the hot and warm wallet layers.

This separation highlighted why exchanges distributed assets across different custody tiers. Operational wallets prioritized accessibility while cold storage emphasized isolation.

What Bitget Customers Should Know While Withdrawals Are Suspended

Customers could still view their account balances and utilize available trading functions. Deposits also remained operational according to the exchange.

Withdrawals, however, remained temporarily unavailable while the security review progressed. Users should be cautious of unofficial messages promising alternative withdrawal methods.

Major hacks often presented opportunities for phishing campaigns. Customers should avoid disclosing credentials, recovery phrases, and authentication codes to anyone claiming to offer emergency access.

Who Is Behind the Bitget Hack?

Attribution remained one of the biggest unanswered questions. Bitget’s leadership had pointed to a potential North Korean connection, but final attribution remained unconfirmed.

Why Investigators Are Looking at a Possible North Korean Link

Bitget CEO Gracy Chen had stated that a North Korean group was a likely possibility. Investigators examined technical indicators and behavioral similarities.

North Korean hacking operations had previously targeted cryptocurrency platforms and digital asset infrastructure. Their techniques often involved extensive preparation and operational security. The possible connection had attracted significant attention. Similarity to previous attacks did not independently prove responsibility, however.

What Evidence Connects the Attack to Lazarus Group?

Reports surrounding the Bitget Lazarus Group theory cited network indicators and similarities with previously observed North Korean activity. Fund-flow patterns were also under examination.

Some investigators had reportedly analyzed infrastructure characteristics and VPN usage associated with the attackers. On-chain researchers were separately comparing transaction behavior with previous theft clusters. These indicators could support further investigation, but they did not confirm definitive attribution. A stronger conclusion required corroborating forensic evidence.

What Remains Unconfirmed About the Attackers

No completed forensic report had officially established the identity of the attackers. The Lazarus Group connection remained a working theory.

Investigators needed to connect infrastructure, wallet behavior, access methods, and other evidence. Attribution became exceptionally challenging when attackers deliberately imitated known groups. Bitget’s final technical findings could provide additional clues. Law enforcement investigations could require considerably longer than the exchange’s internal review.

Bitget Hack Timeline: From First Outflows to Withdrawal Freeze

The incident developed rapidly on 24 September. Unusual transactions appeared before Bitget publicly explained the scale of the security breach.

18:31 UTC: Bitget Detects Unauthorized Transfers

Bitget stated that its security systems had detected unauthorized transfers at 18:31 UTC. The activity involved a limited portion of operational wallet infrastructure.

Security personnel immediately began reviewing the movements. This timestamp became the official starting point for Bitget’s incident response.

Initial On-Chain Transfers Raise Security Concerns

Blockchain observers had noted unusually large movements from addresses associated with Bitget. Early estimates had suggested losses well below the eventual total.

Those first calculations had predominantly captured visible activity on certain networks. Additional XRP movements had later helped explain the discrepancy.

Speculation had initially been unavoidable due to large exchange transfers having legitimate operational explanations. Bitget’s confirmation later established that unauthorized activity had occurred.

Bitget Activates Its Emergency Response

The exchange activated emergency procedures within minutes of detecting suspicious transfers. Teams began isolating systems and tracing destination addresses.

Withdrawals were then paused to reduce further risk. External security specialists and law enforcement became involved in the response. Bitget also began examining its wallet authorization infrastructure. The investigation subsequently identified a compromised backend component.

Exchange Confirms the $351.6 Million Loss

Bitget eventually placed the estimated affected amount at approximately $351.6 million. That figure greatly exceeded several early on-chain estimates.

The wider total represented assets across different networks. XRP formed a particularly significant portion that had been missed by the EVM-focused calculations. Bitget simultaneously stated that its protection fund exceeded the loss. Cold wallets reportedly remained unaffected.

Investigation and System Remediation Begin

After containment, attention shifted towards root-cause analysis and infrastructure remediation. Engineers needed to determine how attackers had entered the backend system.

Wallet authorization controls also required examination before withdrawals could safely resume. Any compromised components would need to be replaced or hardened. Forensic teams continued following the stolen assets. Their work could identify additional addresses, services, and counterparties connected to the attackers.

What the Bitget Hack Means for Crypto Exchange Security

The Bitget exploit highlighted how exchange security extended beyond protecting private keys. Complex custody infrastructure involved numerous components that could become attack surfaces.

Why Backend Systems Can Become a Critical Attack Surface

Modern exchanges automated large volumes of deposits, withdrawals, wallet replenishment, and internal transfers. Backend systems coordinated many of these processes.

Attackers who compromised transaction-generation infrastructure could manipulate what legitimate signing systems received. Strong key security did not automatically detect false instructions. Security architecture needed independent verification at multiple stages. Transaction intent, destination addresses, limits, and behavioral anomalies required controls.

Hot, Warm, and Cold Wallet Security Explained

Hot wallets remained connected to online infrastructure and provided immediate liquidity. Their accessibility made them useful but also exposed them to increased operational risk.

Warm wallets occupied an intermediate security layer. They could replenish hot wallets while being more restricted than fully online systems. Cold wallets remained isolated from routine internet-connected operations. Exchanges commonly utilized them to store assets that did not require immediate movement.

Why Private-Key Protection Alone May Not Be Enough

Private keys represented the final authority behind blockchain transactions, but they operated within broader systems. Those systems determined what transactions reached signing infrastructure.

If attackers manipulated trusted transaction data, legitimate keys could potentially sign malicious instructions. The cryptographic keys themselves could remain secret throughout the attack. The Bitget hack explained through this model demonstrated a broader security challenge. Exchanges needed to secure both keys and the systems controlling their use.

What the Incident Reveals About Exchange Custody Risks

Customers utilizing centralized exchanges depended on internal systems that they could not independently inspect. Security therefore relied on architecture, monitoring, controls, and incident response.

A large protection fund could reduce the financial consequences after an attack. It did not, however, eliminate temporary service disruptions and operational uncertainty. The Bitget security breach reinforced the importance of layered custody controls. Exchanges needed to assume that attackers would target every component surrounding wallet authorization.

What Happens Next for Bitget?

Bitget now had several priorities, including completing its investigation, reopening withdrawals, strengthening wallet infrastructure, and tracking stolen assets.

Bitget’s Investigation and Root-Cause Analysis

Investigators needed to reconstruct how the attackers had entered the backend environment. Logs would assist in determining the sequence of unauthorized actions.

The analysis also needed to identify why existing controls had accepted spoofed transaction information. Understanding that failure would shape corrective measures. Bitget would likely review access permissions, authorization logic, monitoring systems, and wallet segregation. External specialists could independently test revised infrastructure.

When the Full Incident Report Is Expected

Bitget initially stated that a complete incident report would follow within 24 hours of its first security notice. The report would address root causes and corrective actions.

Technical findings could evolve as investigators gathered further evidence. Early explanations would be distinguishable from those supported by completed forensic analysis. The final report would be particularly important for understanding the backend compromise. It could also clarify the status of the suspected North Korean connection.

Restoring Withdrawals and Hardening Wallet Infrastructure

Withdrawal restoration depended on Bitget confirming that its transaction pipeline could operate safely. Security checks needed to go beyond the initially compromised component.

Engineers could introduce additional transaction validation, stricter authorization controls, and enhanced anomaly detection. Wallet exposure limits could also receive further review.

The Bitget withdrawal freeze should end only after these checks provided sufficient confidence. Customers would closely watch the reopening process for stability.

Monitoring the Movement of the Stolen Funds

Investigators continued tracking Bitget stolen funds across multiple networks. Public blockchains provided a persistent record of many attacker transactions.

Large Ethereum holdings remained particularly visible after substantial token conversions. XRP movements could also be followed through their respective ledger addresses.

Recovery became more complicated when attackers bridged assets or utilized decentralized infrastructure. Centralized services could create intervention opportunities when the stolen funds eventually reached them.

FAQ

Was Bitget Actually Hacked?

Yes. Bitget had confirmed unauthorized transfers affecting approximately $351.6 million from parts of its hot and warm wallet infrastructure.

The Bitget hack took place on 24 September 2026. Cold wallets reportedly remained secure.

How Much Crypto Was Stolen From Bitget?

Bitget estimated that approximately $351.6 million in assets had been affected. The stolen portfolio involved XRP, Ethereum, stablecoins, and several other cryptocurrencies.

Early estimates had been considerably lower due to not tracking across every involved network. Later tracking identified a large XRP component.

Are Bitget Withdrawals Working?

Bitget suspended withdrawals for the time being as it investigated security concerns. Deposits and trading continued uninterrupted despite the withdrawal freeze.

The exchange announced that it would reinstate withdrawals after the security teams had completed their checks. A specific deadline was not given at the time of the original announcement.

Are Bitget User Funds Safe?

Bitget is assuring customers that their balances are accurate and their assets are secure. The company stated that the protection fund could cover the amount of the alleged damages.

Customers still have their withdrawals restricted for the time being as the exchange continues its security measures. Bitget is reporting that cold storage assets remained untouched.

Did Bitget Lose Its Private Keys?

The exchange is saying that there was no compromise of the private keys. Investigations point to unauthorized access to the critical backend wallet infrastructure.

The attackers allegedly changed transaction data and initiated the unauthorized withdrawals. The method of the breach is still under investigation.

Who Hacked Bitget?

The hackers still have not been identified. Bitget executives believe the attack was conducted by North Koreans.

The Lazarus Group’s involvement in the heist is still unproven, requiring a more substantial investigation.

How Much Is Bitget’s User Protection Fund Worth?

The user protection fund of Bitget is said to be covering more than $464 million when the exchange disclosed the breach. That amount exceeds the estimated $351.6 million loss.

The exchange assures that the fund covers the losses suffered in the alleged attack. The customers’ balances will not be negatively affected, Bitget stated.

The NewsDIO Briefing

One email each morning with the stories that matter.

Join the discussion

Your email address is not published. Required fields are marked.