Buy
Market
🔥
Prediction Market

Bitget hit by $351.6 million hack, possibly 2026's largest crypto theft

Bitget confirmed a $351.6 million hack on September 24, 2026, freezing withdrawals while its User Protection Fund covers the loss.

24/09/2026 22:5223 min read

Bitget's native token, BGB, dropped about 5% when the hack reports started spreading late in the US trading session. The wider cryptocurrency market has gained almost 10% in the past week, indicating that traders view the incident as an isolated issue for Bitget rather than a risk to the entire industry.

The attacker's quick ether purchases on Arbitrum temporarily drove the WETH/USDC pool price to around $2,870. This was a brief, local anomaly rather than genuine demand. The greater threat to market sentiment is the duration of the withdrawal freeze: as it extends, skepticism could spill over to other centralized exchanges.

---

Bitget states that customer funds are protected following the $351.6 million loss to hackers. However, with withdrawals halted and the method of the breach still undisclosed, the critical measure is how soon users can regain access to their assets.

Summary:

  • At 18:31 UTC on 24 September, Bitget identified unauthorized withdrawals from several of its hot wallets. CEO Gracy Chen stated that the affected amount was approximately $351.6 million.
  • According to Chen, the offline cold wallets remain safe, and the intrusion was restricted to certain parts of the hot and warm tiers within the exchange's three-layer wallet structure.
  • All user withdrawals are halted while a security review is conducted, though deposits and trading operations are still active.
  • Chen said that the User Protection Fund, containing over $464 million, is sufficient to cover the entire loss. However, the fund's composition has not been independently audited.
  • The method used in the attack remains undisclosed. Bitget has committed to providing hourly status updates and a comprehensive incident report within 24 hours, and has informed law enforcement authorities.
  • Initial on-chain estimates placed the loss at between $174 million and $183 million, roughly half of the amount Bitget later confirmed. If the exchange's figure stands, September's total reported crypto hack losses would exceed $684 million, making it the most costly month of 2026.

On Thursday, cryptocurrency exchange Bitget confirmed that approximately $351.6 million in digital assets were stolen from its online wallets, potentially marking the biggest crypto theft of 2026 to date. The platform has paused withdrawals during its investigation, but CEO Gracy Chen stated that the entire loss will be reimbursed and that customer account balances are still accurate.

In a security update on X, Chen reported that Bitget's systems detected unauthorized transactions at 18:31 UTC on September 24, prompting the immediate activation of emergency protocols. She noted that the breach only affected certain parts of the 'hot' and 'warm' layers of the exchange's three-tier wallet system, while the offline 'cold' wallets remained untouched. Deposits and trading continue to operate, but all withdrawal services are suspended until a security review is completed. The exchange has not revealed how the attackers gained access. Bitget has pledged hourly updates and a full incident report—including the root cause and remediation actions—within 24 hours. It also stated that it has marked the recipient addresses and notified law enforcement and blockchain security companies.

The difference between wallet types is important for those unfamiliar with crypto. An exchange stores customer funds in digital wallets governed by private keys—similar to passwords that authorize transactions. A hot wallet remains connected to the internet to enable fast withdrawals, while a cold wallet stores its keys offline, making it far more secure but less convenient for frequent transactions. Exchanges usually maintain only a small operational balance in hot wallets, making them the primary target for attackers. Since blockchain transactions are mostly irreversible, there is no financial institution to reverse the transfer once funds leave a compromised wallet.

Independent analysts detected the fund outflows before Bitget made any public statement. According to Emmett Gallic, an analyst at Arkham Intelligence, assets from multiple Bitget-labeled wallets across various blockchains were gathered into a single address, with early estimates ranging from $174 million to $183 million—about half what Bitget later disclosed. One transaction was particularly notable: a new wallet converted roughly $19.7 million of USDT0 (a cross-chain variant of the Tether stablecoin) into 7,111 ether within approximately six minutes, paying as much as 5% above the prevailing market price, as reported by Decrypt. This willingness to pay a premium indicates that speed was prioritized over cost. Stablecoins like Tether can be frozen by their issuer, while ether has no central authority that can block it. Thus, such rapid conversion is a pattern analysts have observed in the early phases of previous exchange hacks.

Hacks of this magnitude are not uncommon. Prior to the September 19 Fetch.ai exploit, DeFiLlama had recorded approximately $331 million lost across 17 incidents in September, the bulk of which came from a roughly $320 million event at Liquid Network, where the attackers claimed to be "white hat" hackers. According to CryptoSlate, Bitget's losses would push September's total reported hack sum above $684 million, surpassing April as the most expensive month of 2026—though the tally may change if some funds are recovered. Social media speculation that North Korea is behind the attack remains unconfirmed, and Bitget has refrained from offering any theory.

Chen stated that the exchange's User Protection Fund, valued at over $464 million, is enough to cover the full loss. While that amount exceeds the confirmed theft, TFTC pointed out that the fund's asset composition has not been independently audited. Moreover, the withdrawal freeze affects all users, including those whose funds were not involved. The takeaway for new users is that funds held on an exchange are only as secure as the platform's security measures and its capacity to absorb losses.

The next key event is the incident report expected within 24 hours, which should detail how the breach occurred and whether withdrawals will be restored fully and without issues. A swift resumption of services with a clear explanation of the root cause would bolster Bitget's claims, whereas an extended freeze or an increased loss estimate would undermine them. The movement of the stolen ether is also significant: if the funds pass through privacy tools like Tornado Cash, the chances of recovery drop significantly. For users with assets on the platform, it may be prudent to await the report before making any judgments.

Share to

Disclaimer: this article comes from third-party media and is provided for reference only. It does not constitute investment advice. Crypto and other financial products carry significant price volatility risk, so please make your own decisions carefully.

Related articles