At 18:31 UTC on September 24, 2026, Bitget’s security systems flagged unauthorized transfers moving out of some of the exchange’s hot wallets. By the time CEO Gracy Chen confirmed the breach on X, the estimated damage stood at approximately $351.6 million — the largest confirmed crypto exchange hack of 2026, surpassing the $320 million Liquid Network incident earlier in September, as CoinDesk reported.
The number that matters most for understanding this hack, though, is not $351.6 million. It is zero — the number of private keys that were stolen.
What actually happened
Bitget published a security notice confirming the incident: at 18:31 UTC its systems detected unauthorized transfers, the security team activated emergency protocols, and abnormal transfer addresses were flagged and reported to law enforcement and on-chain security firms. Nineteen transfers moved out of portions of the hot and warm wallet infrastructure, according to CNBC. Cold wallets — the fully offline layer of Bitget’s three-tier architecture — were not touched.
The mechanics, as explained by Chen on X and in a live Q&A, are what make this incident worth studying:
“The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out. Private key compromise has been ruled out.”
Read that carefully, because it inverts the mental model most people carry about exchange security. The attackers did not brute-force anything. They did not phish a seed phrase. They did not steal a private key. They got inside the system that prepares transactions, fed it forged transfer details, and let Bitget’s own legitimate signing process approve the moves. Chen separately noted that the attackers did not forge user withdrawal requests either — this was direct fund movement through compromised infrastructure, as Cointelegraph reported.
A hot wallet is an exchange’s online cash drawer: always connected, always ready to process trades, deposits and withdrawals. A warm wallet sits between that and cold storage, topping up the hot layer and pulling excess funds back offline. Those are exactly the layers you attack if you cannot get the keys — you target the machinery around the keys.
The Bybit pattern, again
If this sounds familiar, it should. In February 2025, Bybit lost roughly $1.5 billion when attackers spoofed the interface of its cold-wallet signing workflow — the engineers saw a legitimate-looking transaction on screen and approved one that was not, in what became the largest crypto theft on record. The FBI attributed that attack to North Korean actors, and North Korean-linked groups were tied to an estimated $2.02 billion in crypto theft across 2025, according to Cointelegraph.
The shared lesson of Bybit and Bitget is uncomfortable: the security of a key and the integrity of a transaction are two different problems. A signature is only as trustworthy as the data that went into it. When that data can be manipulated upstream — in a signing interface, in a wallet backend — the strongest key in the world authorizes the wrong transfer anyway.
This is the same family of risk we cover on the individual level in eth_sign phishing, where victims sign messages they cannot read. The scale differs; the structure does not.
Following the money
On-chain researchers spotted the breach before any official statement. Analysts at Hacken and PeckShield flagged unusual movements from Bitget-labeled wallets, with early estimates around $174–183 million before the full multi-chain picture emerged, as Bitcoin.com noted. Arkham Intelligence analyst Emmett Gallic identified three Bitget hot wallets and one cold wallet label involved, with funds consolidated into a single address.
The most telling detail comes from Decrypt: a freshly created address starting with 0xe410 took $19.67 million in USDT0 — a cross-chain variant of the stablecoin USDT — and swapped it for 7,111 ETH in about six minutes on Arbitrum, routing through UniswapX and 1inch Fusion and paying up to roughly 5 percent above market price.
That premium is a signature in itself. Someone willing to overpay by 5 percent values speed over price, because stablecoins can be frozen at issuer level while ETH cannot. The swap was not trading. It was conversion into an asset no third party can claw back. Affected assets across the full incident included ETH, XRP, USDT, USDC, AVAX, BNB and XAUT across Ethereum, XRP Ledger, Avalanche, BNB Smart Chain and Arbitrum, per CNBC.
Who did it
Chen said preliminary findings point toward North Korean attackers: investigators identified IP addresses matching VPN services previously used by a DPRK-associated hacking group, and the attack’s pattern resembles earlier operations attributed to the country. She was explicit that the attribution is not yet confirmed, and that Bitget does not believe the breach was an inside job. Some stolen funds have already been recovered, she added, without specifying an amount — the exchange is working with blockchain foundations and security partners on tracing.
Attribution at this stage is direction, not conclusion. VPN fingerprints have been wrong before. But the profile fits: a patient intrusion into backend infrastructure, multi-chain fund consolidation, rapid conversion into seizure-resistant assets. These are the hallmarks of state-linked crews, not opportunistic drainer gangs.
What Bitget users should actually do
The exchange’s position is that user balances are accurate and the loss falls entirely within its User Protection Fund, which holds over $464 million. Trading and deposits remain open; withdrawals are suspended pending the security review, with a full incident report promised within 24 hours of the breach.
If you hold funds on Bitget, the riskiest moment is not the hack itself. It is the next 72 hours.
Expect the recovery-phishing wave. Every major breach triggers a second campaign: fake “Bitget compensation” sites, impersonator accounts, DMs offering priority withdrawals or refund processing for a fee. The CFTC classifies these follow-ups as advance-fee fraud, and we walk through the pattern in what to do after a wallet drainer attack. No real compensation program will ever reach out to you first.
Verify everything through the app you already have installed. When withdrawals reopen, open the official app directly — not a link from a message, email or search ad. Phishing clones of exchange sites surge exactly during outage windows, when users are anxious and searching for updates.
Read the incident report when it lands. Bitget has promised root-cause analysis within 24 hours. Whether it explains how the backend was compromised, or stays vague, tells you something about what a second incident would look like.
And the standing lesson, unchanged since Mt. Gox: an exchange is someone else’s computer. Funds you cannot afford to have frozen during an incident belong in self-custody, where no backend you have never seen can sign them away. If you are new to that trade-off, our first-24-hours guide for stolen crypto covers the decision points in both directions.
The bigger picture
Industry-wide losses to hackers reached $2.72 billion in 2025, per Decrypt’s tally. September 2026 alone has now produced the Liquid Network incident and Bitget. The attacks keep not breaking the cryptography — they break the systems and the humans around it. Backend spoofing, interface spoofing, blind signing, fake airdrop claims: every variant shares one root, transactions getting approved on the strength of data the approver cannot verify.
That is the real takeaway from the Bitget hack. Your keys were never the weakest link. The signing process was.
This article is for education and risk awareness only, not investment advice. Figures reflect official statements and on-chain analyses as of September 25, 2026, while the investigation is ongoing.
Frequently Asked Questions
Is Bitget going under after the $351.6 million hack?
Bitget says the loss is fully covered by its User Protection Fund, which holds over $464 million, and that trading and deposits remain open. That is the company's own account, delivered while the investigation is still running. The precedent it points to is Bybit, which lost roughly $1.5 billion in February 2025 and continued operating. The practical test is what happens when withdrawals reopen and users decide whether to stay.
How did attackers drain Bitget without stealing private keys?
According to CEO Gracy Chen, the attackers compromised a critical backend system in the wallet infrastructure, spoofed the transaction data flowing through it, and triggered Bitget's normal authorization-signing process. The signatures were genuine; the data being signed was fake. Chen also said the attackers did not forge user withdrawal requests. The exact way they got into the backend is still under investigation.
What should Bitget users do right now?
Three things. Treat the withdrawal freeze as a security review, not a collapse signal — trading and deposits are still open. Ignore anyone contacting you with compensation offers, refund links, or 'priority withdrawal' access; recovery phishing after a major hack is a reliable second wave. And when withdrawals reopen, withdraw through the official app only, not through links sent to you.