Fri, September 25

Bitget Hack: What Happened in the $351.6 Million Crypto Security Breach?

Bitget Hack: What Happened in the $351.6 Million Crypto Security Breach? Market News

Bitget, a global crypto exchange, is facing heightened scrutiny following a major security incident on September 24, 2026, after approximately $351.6 million in digital assets were affected by unauthorized transfers. The exchange said the incident involved parts of its hot and warm wallet infrastructure, while cold wallets remained secure and its User Protection Fund held more than $464 million.

Bitget said its security systems detected unauthorized transfers from some hot wallets at 18:31 UTC on September 24 and that its emergency response procedures were activated within minutes. The exchange said the incident affected portions of its hot and warm wallet infrastructure, while its cold wallets remained secure. It also said customer account balances remained accurate and that its User Protection Fund, which it said held more than $464 million, was sufficient to cover the affected amount.

Bitget CEO Gracy Chen said preliminary findings indicate that a North Korean hacking group may be linked to the breach. Chen cited similarities with previous attacks and preliminary IP-related clues, while noting that the investigation into the incident remains ongoing.

Before going deeper into the hack, it is useful to first understand Bitget and its role in the cryptocurrency market.

Crypto Exchange Bitget Overview

Bitget is a global cryptocurrency exchange that provides a range of digital-asset trading and investment services. It supports spot trading, futures trading and other crypto products for users across international markets.

Founded in 2018, Bitget has expanded its platform to include trading tools, copy trading and Web3-related services. The exchange also operates security measures and a User Protection Fund designed to provide additional protection for users’ assets.

Bitget has become one of the major centralized crypto exchanges, serving retail and professional traders across multiple regions. Its platform supports a broad range of cryptocurrencies and trading pairs, while its security infrastructure includes hot, warm and cold wallet systems.

Bitget Hack: How the Incident Began

Initial signs of the incident emerged through unusual blockchain transactions involving wallets labeled as belonging to Bitget.

The Block reported that more than $177 million in crypto moved from several Bitget-associated wallets to a newly created address over roughly an hour. The assets included Ether, USDT, USDC, AVAX and BNB. At that stage, it was not yet clear whether the movements represented a security breach or an internal operation.

Decrypt later reported that approximately $183 million in assets had moved from Bitget-associated wallets into a single address. On-chain researchers, including analysts associated with Arkham and Bubblemaps, flagged the activity as suspicious.

The early blockchain estimates were lower than Bitget’s next assessment of $351.6 million because researchers were initially tracking transactions that were immediately visible on public networks. Bitget’s later figure reflected its broader internal assessment of the incident.

Bitget Hack: $351.6 Million in Crypto Assets Affected

Bitget estimates that approximately $351.6 million in digital assets were affected by the security incident.

According to Bitget, the breach was contained to a portion of its hot and warm wallet layers, while its cold wallets remained secure. The exchange also said the affected amount fell within the coverage of its User Protection Fund, which it said held more than $464 million.

The incident involved multiple cryptocurrencies. On-chain analysis identified ETH, USDT, USDC, AVAX, BNB and other assets among the transfers. Lookonchain estimated the stolen portfolio at around $356.8 million, slightly above Bitget’s $351.6 million estimate due to differences in valuation methods.

Decrypt’s analysis also documented the subsequent movement and conversion of several of these assets. Because cryptocurrency prices fluctuate, the dollar value attached to transferred assets can change depending on the valuation time. Bitget’s $351.6 million figure should therefore be understood as the exchange’s stated estimate for the affected assets.

Bitget’s Three-Tier Wallet Architecture 

Wallet architecture is central to understanding the Bitget incident.

Cryptocurrency exchanges generally use multiple wallet layers to balance operational accessibility and security. Hot wallets are connected to online systems and are used for transactions requiring frequent access. Warm wallets provide an intermediate layer, while cold wallets are designed to remain isolated from online space.

TierConnectivityPurposeSecurity Status in Sept 2026 Incident
Hot WalletOnline continuouslyFrequent daily transactions and withdrawalsBreached — unauthorized transfers detected
Warm WalletIntermittent/ControlledIntermediate buffer between hot and cold storagePartially affected by the breach
Cold WalletCompletely offlineMaximum security for long-term asset reservesFully secure and uncompromised

Bitget says it operates a three-tier wallet architecture. According to the exchange, the September 24 incident affected portions of its hot and warm wallet layers, while its cold wallets remained fully secure.

This distinction is important because an incident involving operational wallets does not automatically mean every asset controlled by an exchange has been exposed.

Bitget also said that deposits and trading remained operational while withdrawals were temporarily suspended during the security review.

Bitget Hack: What Was the Attack Vector?

The precise attack mechanism remains one of the most important questions surrounding the incident.

In its initial security notice, Bitget said it would not speculate on the attack vector until the investigation was complete. The exchange said a full incident report would include a root-cause analysis and corrective actions.

More recent reporting has provided additional information. CoinDesk reported that Bitget CEO Gracy Chen said attackers compromised a critical backend system within the exchange’s wallet infrastructure, used that access to spoof transaction data and triggered the exchange’s own authorization process. Chen also said a private-key compromise had been ruled out.

This distinction is technically important. A private-key theft would indicate direct compromise of cryptographic signing credentials, while a backend compromise could involve manipulating information processed by the exchange’s transaction-authorization infrastructure.

The backend explanation should still be treated as a preliminary finding until Bitget publishes its complete technical investigation.

Bitget Hack: How the Funds Moved On-Chain

Blockchain activity provided some of the earliest evidence that unusual activity was taking place.

Decrypt reported that a newly created address used approximately $19.67 million in USDT0 to purchase 7,111 ETH on Arbitrum within six minutes. The transactions involved UniswapX and 1inch Fusion, with the purchases reportedly made at premiums to the prevailing market price.

The Block also reported that multiple assets were transferred from Bitget-associated wallets to a fresh address and that the receiving wallet subsequently began swapping assets on-chain.

Public blockchains make such movements traceable because transactions are permanently recorded. Blockchain analytics firms can therefore monitor addresses and follow subsequent transfers.

However, tracing cryptocurrency does not automatically mean recovering it. Investigators still need to determine who controls destination addresses and whether the funds interact with centralized exchanges or other services capable of intervening.

Bitget Hack: Why Withdrawals Were Suspended

Bitget temporarily suspended withdrawals following the incident.

The exchange’s withdrawal notice states that the incident occurred at 18:31 UTC on September 24 and that withdrawal services were temporarily unavailable. Deposits and trading remained operational, while Bitget said withdrawals would be restored once its security review was complete.

Restricting withdrawals during a suspected wallet-security incident can help prevent additional unauthorized outbound transactions while technical teams investigate affected systems.

Bitget said the measure was precautionary and that it would provide hourly updates while the security review continued.

Bitget Says Customer Funds Are Protected

Bitget has stated that customer funds remain protected following the incident.

Its official security notice says customer account balances remain accurate and that the full amount of the reported loss falls within the coverage of its User Protection Fund. Bitget said the fund currently holds more than $464 million.

This distinction between exchange-controlled wallet assets and customer account balances is important. The unauthorized transfers originated from Bitget’s wallet infrastructure, while the exchange says its internal accounting of customer balances remains accurate.

The protection fund is therefore a central part of Bitget’s stated response to the incident.

Bitget Hack: Law Enforcement and Security Firms Join the Investigation

Bitget said it has involved external parties in its response to the incident.

According to its official security notice, unauthorised transfer addresses were identified, flagged and reported. Bitget also said law-enforcement authorities and on-chain security firms had been formally notified and were engaged in the investigation.

Blockchain security firms can monitor addresses connected to the incident, track subsequent movements and identify attempts to move affected assets through other services. Law-enforcement involvement can add investigative capabilities when authorities attempt to connect blockchain addresses with individuals, organizations or infrastructure.

Bitget CEO Gracy Chen said the exchange is collaborating with independent cybersecurity experts from Mandiant and SlowMist to conduct a comprehensive investigation into the incident and determine how the unauthorized transfers occurred. 

Bitget Hack: What Happened to the Assets After the Transfers?

The movement of assets continued after the initial transfers.

Decrypt reported that the receiving wallet converted substantial amounts of stablecoins into Ether through decentralized trading infrastructure. The reported purchase of 7,111 ETH using approximately $19.67 million in USDT0 was one of the most notable transactions identified.

Other assets were also transferred across multiple networks. This has turned the incident into a multi-chain tracking operation. Blockchain monitoring provides investigators with a continuing trail of transactions, although following the assets does not guarantee recovery.

Bitget Hack: What the Incident Means for Crypto Exchange Security

The Bitget incident highlights the importance of security throughout an exchange’s entire wallet infrastructure.

Bitget’s account says that the affected systems were within portions of its hot and warm wallet layers, while cold wallets remained secure. Preliminary reporting has also pointed toward manipulation of a backend system rather than direct private-key theft.

Modern exchanges depend on interconnected systems covering wallet management, transaction generation, authorization, monitoring and blockchain execution. If the preliminary backend findings are confirmed, the incident would demonstrate why security controls around transaction-generation and authorization systems can be as important as protecting private keys.

The final investigation will be needed to establish which controls were bypassed and what changes Bitget will implement.

Bitget Hack: What the Incident Means for Users

For users, the incident highlights the operational risks associated with keeping digital assets on centralized exchanges.

Exchange users rely on the platform to manage wallet infrastructure, transaction authorization and withdrawal systems. This provides convenience and access to trading liquidity, but it also means users depend on the exchange’s security architecture.

Bitget said account balances remained accurate while withdrawals were temporarily suspended. Users assessing exchange custody can consider factors such as wallet architecture, reserve disclosures, protection mechanisms, security procedures and incident-response policies. These factors do not eliminate risk, but they can provide additional information about how a platform manages digital-asset custody.

Bitget Hack: CEO Gracy Chen Suspects North Korean Behind the Hack

Bitget CEO Gracy Chen said preliminary findings indicate that a North Korean hacking group may be linked to the exchange’s $351.6 million security breach. During a live Q&A following the incident, Chen said investigators identified IP addresses that matched VPN services associated with a DPRK group and found similarities with previous North Korean attacks. She also said Bitget did not believe the incident was an inside job.

Chen later said the attackers breached a backend system connected to Bitget’s wallet service and used it to manipulate transfer information and trigger the authorization-signing process. She said the attackers did not forge user withdrawal requests and did not obtain the private keys of Bitget’s cold, hot or warm wallets. Investigators were still working to determine exactly which systems were compromised and how the attackers gained access.

An independent on-chain researcher, Specter, also alleged a possible connection to North Korean-linked hacking activity. 

Specter traced some of the stolen XRP to an Ethereum address that had received USDT from a wallet previously linked to an address labeled “AFX EXPLOITER.” The AFX incident in July was previously suspected of involving TraderTraitor, a group associated with North Korea. This remains an on-chain attribution claim rather than a confirmed finding by law enforcement.

Chen also said during the Q&A that some of the stolen funds had already been recovered, although she did not disclose the amount. Bitget said it was working with blockchain foundations and other partners as it continued efforts to trace and recover the affected assets.

Other Recent Records of North Korean Crypto Theft

In addition, North Korean-linked hackers were estimated to have stolen around $2.02 billion in cryptocurrency during 2025, according to Chainalysis. The figure represented a significant increase from the previous year and included several major attacks targeting crypto platforms and infrastructure.

One of the largest incidents was the February 2025 Bybit breach, in which approximately $1.5 billion stolen in virtual assets. The FBI formally attributed the theft to North Korea, identifying the activity as part of the TraderTraitor campaign.

Bitget Hack: What Happens Next?

Bitget’s next major step is completing its security review and publishing its full incident report.

The exchange said, 

“A full incident report, including the root cause analysis (RCA) and corrective actions, will be published within 24 hours after withdrawals are restored.” 

The technical report should provide greater clarity about the backend compromise, the systems involved, the controls affected and the measures being implemented to prevent another incident.

Moreover, the investigation into the transferred assets will continue separately, with blockchain security teams and law enforcement monitoring associated addresses. 

Regarding the withdrawal recovery timeline, Bitget said its goal is to complete a full recovery as soon as possible. The exchange added that it will announce a specific timeframe once it is confirmed, stressing that it does not want to commit to a timeline it cannot deliver.

Bitget Hack: The Bigger Security Lesson

The Bitget incident shows that crypto exchange security extends beyond private-key protection. Modern platforms rely on interconnected systems for trading, withdrawals and wallet transactions, meaning a weakness in one component can affect others.

Bitget CEO Gracy Chen said attackers compromised a backend wallet system and manipulated transaction information, while private keys were not compromised. The incident highlights the importance of layered authorization, transaction monitoring, wallet segregation and rapid anomaly detection.

Conclusion

The Bitget hack has highlighted the complexity of securing modern cryptocurrency exchanges, where protection depends on more than safeguarding private keys. With approximately $351.6 million in digital assets affected, the incident has raised important questions around backend systems, transaction authorization and wallet infrastructure.

Bitget’s ongoing investigation, supported by independent security experts, will be crucial in establishing the full attack path and determining how the unauthorized transfers were enabled. As the exchange works to trace and recover affected assets and restore normal withdrawal services, the incident underscores the importance of layered security, continuous monitoring and rapid response across the crypto industry.

A final technical report will be important to establish the complete attack sequence, identify the initial vulnerability and outline corrective measures. Until then, confirmed Bitget statements should be distinguished from independently observed blockchain activity and preliminary investigative findings.