The cryptocurrency exchange Bitget has encountered a significant security breach, resulting in the loss of approximately $351.6 million from its hot and warm wallet systems. The breach was detected at 18:31 UTC on September 24, 2026, triggering immediate emergency protocols from Bitget’s security team.
Bitget officials assured that the exchange’s cold wallets were not affected, ensuring that user account balances remain accurate. The breach was confined to specific areas of Bitget’s multi-tiered wallet system. Although a comprehensive list of stolen assets is yet to be released, on-chain analysis indicates the involvement of cryptocurrencies such as ETH, BNB, AVAX, USDT, and USDC.
Immediate Response and Investigation
Initial assessments estimated suspicious transfers between $174 million and $183 million. However, further investigation confirmed exposure totaling $351.6 million. In response, Bitget temporarily halted withdrawals to assess the security of its wallet infrastructure and determine any further vulnerabilities.
Despite the suspension, deposits and trading activities continue unaffected. Bitget has taken steps to flag suspicious recipient addresses and has engaged with law enforcement and blockchain-security experts to track the stolen funds.
User Protection and Security Measures
Bitget CEO Gracy Chen has confirmed that the losses are covered by the exchange’s User Protection Fund, valued at over $464 million. This measure ensures a financial cushion of around $112.4 million above the breach losses. However, users remain vigilant about how the fund will be utilized and the timeline for withdrawal resumption.
The incident underscores the necessity for verifiable, liquid, and accessible protection reserves during major exchange security breaches.
Investigation and Attribution
During a live Q&A session, Chen highlighted that preliminary evidence suggests the involvement of IP addresses linked to VPNs used by a suspected North Korean threat group. This activity mirrors past operations attributed to the notorious Lazarus Group. Nonetheless, Bitget refrains from formal attribution until further investigation is complete.
Investigators are exploring whether a third-party vulnerability or supply-chain attack facilitated unauthorized transfer instructions. Findings indicate that attackers swiftly transferred assets post-system access, bypassing fraudulent withdrawal requests. Bitget is committed to providing hourly updates and a comprehensive report within 24 hours, detailing the incident’s root cause and remedial actions.
Customers are advised to follow official Bitget communications, remain vigilant against phishing attempts exploiting the withdrawal pause, and avoid sharing credentials or approving unsolicited wallet requests.
