Bitget confirms $351.6 million hot-wallet breach
Bitget says unauthorized transfers affected about $351.6 million and paused withdrawals as it reviews the September 24 security breach.
By Sofia Marchetti · Columnist
· 3 min read
Bitget hack 2026: The crypto exchange says unauthorized transfers from some of its wallets affected about $351.6 million on Sept. 24. For customers, the immediate change is a temporary withdrawal pause while the company completes a security review, though Bitget says deposits and trading remain available.
According to Bitget’s incident notice, its security systems detected the transfers at 18:31 UTC. The exchange said it activated an emergency response team within minutes, identified and reported abnormal transfer addresses, and notified law enforcement and on-chain security firms.
The $351.6 million figure is Bitget’s estimate of funds affected, rather than an independently audited final loss total. The exchange said it will publish a report covering the root cause and corrective actions after its investigation.
What did Bitget say about the hack?
Bitget said the breach reached a portion of its hot- and warm-wallet layers. A hot wallet is an internet-connected reserve used to process everyday withdrawals. The company said its cold wallets, which are held offline, remained secure.
Bitget also said customer account balances remain accurate and that assets are protected. Those are company assurances. Chief executive Gracy Chen said the full loss falls within the exchange’s User Protection Fund, which Bitget says holds more than $464 million. The material available does not independently verify the fund’s balance, the eventual recovery of assets, or any completed reimbursement.
Withdrawals have been suspended as a precaution and will return after the security review, Bitget said. The exchange gave no timetable for their restoration. It said it would not speculate on the attack method before the investigation is complete.
Why do reports cite different amounts?
Early blockchain observations captured only part of the developing incident. Decrypt reported that analysts saw roughly $183 million move from wallets labeled as Bitget’s to a new address within about an hour. That figure and Bitget’s later $351.6 million estimate are different reported figures from a fast-moving event and should not be read as a final forensic accounting.
Decrypt also reported, based on on-chain researchers’ findings, that a newly created address swapped $19.67 million of USDT0 for 7,111 ETH on Arbitrum in six minutes. The researchers said the swaps used UniswapX and 1inch Fusion, decentralized services that enable blockchain-based token exchanges. Other wallets tagged as Bitget’s reportedly sent ETH, AVAX, BNB, USDC, USDT and XAUT to the same destination.
Those blockchain labels and transaction accounts are reporting from outside researchers, not confirmation by Bitget of the attacker’s identity or the precise path of every asset. Bitget has not publicly identified who was responsible or disclosed the attack vector in the information available.
For users, the key unresolved issues are when withdrawals will resume, what caused the breach, and whether Bitget’s stated protection fund will cover the affected amount as the company says it will.
This story draws on original reporting from Decrypt.