Bitget Hack: $387.5M Stolen, Withdrawals Still Frozen – What We Know
Developing story. We update this article as Bitget publishes its incident report and reopens withdrawals.
- Sep 25, 20:30 UTC: Bitget raised the loss to $387.5 million, blamed a breach of a backend wallet system rather than stolen keys, said it suspects North Korea and launched a 5% recovery bounty. The full incident report promised within 24 hours is still not out, and withdrawals are still frozen for everyone, including on our own Bitget account. Bitget says it will announce a withdrawal plan by 04:00 UTC on September 26.
- Sep 24, 23:40 UTC: Bitget has not yet published its incident report. Withdrawals remain suspended; deposits and trading are open.
Crypto exchange Bitget was hacked on September 24, 2026. The exchange now puts the damage at $387.5 million, up from the $351.6 million it first reported, taken from parts of its hot and warm wallets. Withdrawals are still suspended for all users more than a day later. CEO Gracy Chen says the attackers broke into a backend system of the wallet service rather than stealing private keys, that the company suspects a North Korean group, and that Bitget’s User Protection Fund of more than $464 million covers the full loss. It is the largest crypto hack of 2026 so far.
Bitget hack: key facts
- Amount: $387.5 million, according to Bitget’s revised estimate on September 25. The first figure was $351.6 million; on-chain trackers had counted $178–183 million in the first hours.
- Largest part: about 103 million XRP, worth roughly $157 million.
- Detected: September 24, 2026, 18:31 UTC.
- What was hit: part of the hot and warm wallet layers. Bitget says its cold wallets and the separate Bitget Wallet app are safe.
- Cause, preliminary: a compromised backend system used to spoof transaction data and trigger Bitget’s own authorization process. Bitget says no private keys were leaked.
- Who did it: Bitget suspects a North Korean group. It has not published technical evidence, and no government agency has confirmed it.
- Withdrawals: still suspended. Bitget promised to announce a resumption plan by 04:00 UTC on September 26. Deposits and trading work.
- Coverage: the User Protection Fund, stated at over $464 million. The loss is about 84% of it. The fund has not been independently audited.
- Recovery: a bounty of 5% of any frozen or recovered amount. Bitget says some assets have been frozen but has not said how much.
Timeline of the Bitget hack (UTC)
| Time | What happened |
|---|---|
| Sep 24, 18:31 | Bitget’s security systems detect unauthorized transfers from some hot wallets. On-chain data shows a first test transfer of 0.84 ETH at about the same time. |
| Minutes later | A freshly created wallet spends $19.67 million in USDT0 to buy 7,111 ETH on Arbitrum in six minutes through UniswapX and 1inch Fusion, paying up to 5% above the market price. The trade was first flagged by the researcher DCF GOD. |
| Within the first hour | Bubblemaps and Arkham analyst Emmett Gallic flag roughly $180 million leaving Bitget wallets on several chains and landing at a single address. |
| Around 20:55 | Outflows continue, including 8.2 million USDC bridged to Avalanche. |
| Evening of Sep 24 | Gracy Chen confirms the breach on X, puts the loss at $351.6 million, pauses withdrawals and promises hourly updates plus a full incident report within 24 hours. |
| Early Sep 25 | Chen gives a preliminary cause: a compromised backend system in the wallet infrastructure, spoofed transaction data, no private keys leaked. She says loss containment is confirmed. |
| Sep 25 | In a livestream on X, Chen says Bitget suspects North Korea. Bitget raises the estimate to $387.5 million, names XRP as the largest loss and launches a 5% recovery bounty. |
| Sep 25, 18:31 | 24 hours after detection. The promised full incident report has not been published; only the preliminary findings are out. |
| Sep 26, 04:00 | Deadline Bitget set itself to announce a plan for resuming withdrawals (1 p.m. Korea time). |
What was taken

Bitget’s revised figure is $387.5 million, about $36 million more than its first estimate. The biggest single piece is on the XRP Ledger: about 103 million XRP, roughly $157 million. That explains most of the gap with the first on-chain tallies, which tracked only the EVM chains and came to $178–183 million. The rest, about $183 million in stablecoins, ether and other tokens, was spread over several networks, including Ethereum, Arbitrum, Avalanche, Optimism, BNB Chain and Base.
According to a tally of on-chain data published by Unchained on the first night, the EVM assets included:
- about 48,800 ETH, roughly $131 million;
- about $34.75 million in USDT;
- about $12.85 million in USDC;
- 3,000 XAUT, the tokenized gold, about $12.8 million;
- about 821,000 AVAX, roughly $8.5 million.
Different trackers took their snapshots at different times, so these numbers do not add up exactly to Bitget’s total. Treat them as estimates until the full report is out.
How the attack worked, according to Bitget
Bitget’s preliminary explanation is that the attackers never needed the keys. They got into a backend system that feeds transfer requests to Bitget’s signing process and made fake transfers look legitimate, so Bitget’s own infrastructure approved and signed them:
“The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out.”
Chen also said the attackers “did not forge user withdrawal requests, nor did they obtain our private keys of the cold wallet and any hot, warm wallet”, and that “loss containment is confirmed. No further unauthorized transfers are possible.” If that holds, it is the same class of attack as the $1.5 billion Bybit hack in February 2025, where the signing process was tricked rather than the keys stolen.
Where the stolen funds are going

- Stablecoins into ETH first. Tether and Circle can freeze USDT and USDC at a flagged address. Nobody can freeze ETH, so swapping out of stablecoins within minutes was the attacker’s priority, even at a premium of up to 5%.
- Across chains. Funds moved on Ethereum, Arbitrum, Avalanche and BNB Chain through the Stargate and cBridge bridges, while the XRP left separately on the XRP Ledger.
- Into one address. Researchers traced consolidated EVM funds to
0x469Ac1406dE92f82C0563477240a3627057425DC. An attacker address is labelled “Bitget Exploiter 1” on Etherscan. - Some of it is frozen. Bitget says some assets were frozen together with other exchanges, blockchain projects and security firms, but has not said how much.
To speed that up, Bitget launched a Recovery Bounty Program: anyone who directly helps freeze or recover the funds can earn 5% of the frozen or recovered amount. The next thing investigators will watch is whether the ether starts moving through mixers such as Tornado Cash, which would make recovery much harder.
Who is behind it: Bitget suspects North Korea
In a livestream on X on September 25, Chen said investigators had found “some IP addresses that match the VPN choices by a certain DPRK group” and that “the pattern looks very much like what the North Korean team did before.” Bitget has not published the technical evidence behind that, and no security firm or government agency has confirmed the attribution so far. For context, the biggest exchange hacks of recent years, including Bybit, were attributed by the FBI and on-chain investigators to North Korea’s Lazarus Group.
What still doesn’t add up
Bitget’s messaging has been quick and reassuring. Its actions over the first 26 hours leave several gaps that users should keep in mind:
- The 24-hour report did not arrive. Bitget promised a full incident report, with root cause and corrective actions, within 24 hours. At the 24-hour mark there were only preliminary findings given in posts and a livestream. The full report is now promised “once confirmed”.
- Withdrawals have no date. The message moved from reopening “once the security review is complete” to “we will not commit to a window we cannot guarantee” to announcing only a plan by 04:00 UTC on September 26. When we checked our own Bitget account on the evening of September 25, withdrawals were still unavailable.
- The number keeps changing. The loss went from $351.6 million to $387.5 million a day later, after Bitget had already said the loss was contained. The increase appears to be a fuller count rather than new theft, but Bitget has not said so explicitly.
- The safety net is thinner than it sounds. A $387.5 million loss uses about 84% of a $464 million fund whose holdings have never been audited. Bitget has not said how much has been frozen or how exactly compensation will be paid.
- The attribution comes without evidence. Pointing at North Korea may well be right, but so far it rests on Bitget’s own description.
None of this means user balances are at risk; Bitget insists they are accurate and fully backed. It does mean that “your funds are safe” and “you can withdraw your funds” are, for now, two different statements.
How the market reacted
Bitget’s exchange token BGB fell roughly 5% as the news spread, trading around $2.02–2.06. The wider crypto market barely reacted: it was up nearly 10% over the week, which suggests traders see this as a Bitget problem rather than a threat to the whole sector.
September 2026 is now the worst month of the year for crypto hacks
Before Bitget, DeFiLlama had recorded roughly $331–342 million lost across 17 incidents in September, including about $320 million at Liquid Network. With Bitget’s revised $387.5 million, the month’s total is now above $700 million by our count, well past April’s $646.9 million. It is another reminder that exchange hot wallets remain one of the most attractive targets in crypto, as we saw with the Balancer exploit and the questions around MEXC’s withdrawals last year.
What Bitget users should do now

- Don’t panic-trade. Bitget says balances are unaffected and trading works. Selling into a falling market because you can’t withdraw usually locks in a loss.
- Follow only official channels. Get updates from the Bitget app, its website and the verified accounts of Bitget and its CEO, not from screenshots shared in chats.
- Expect scams, now including fake “bounty” and “claim” pages. The recovery bounty is for people who help freeze stolen funds, not for users. Anyone promising to unlock your withdrawal, speed up compensation or pay you a bounty in exchange for a login, a fee or your seed phrase is a scammer. Our guide to crypto scams and red flags covers the tricks to watch for.
- Tighten your account. Delete API keys you don’t use and make sure the rest have withdrawals disabled. Turn on the withdrawal address whitelist, an anti-phishing code and app-based 2FA.
- Keep records. Take screenshots of your balances and recent history now, in case you ever need them for a claim.
- Expect a queue when withdrawals reopen. After long freezes, exchanges often reopen in stages or by asset, and large withdrawals can take longer. Plan for that before you need the money.
- Rethink what you keep on exchanges. Keep only what you actively trade on any exchange and hold the rest in self-custody. Our guide to securing your crypto wallet explains how.
FAQ
Was Bitget hacked?
Yes. On September 24, 2026, Bitget detected unauthorized transfers from parts of its hot and warm wallets. It now puts the loss at $387.5 million.
How was Bitget hacked?
According to Bitget’s preliminary findings, attackers compromised a backend system of its wallet infrastructure, spoofed transaction data and triggered Bitget’s own authorization process. Bitget says no private keys were leaked. The full technical report has not been published yet.
Are Bitget user funds safe?
Bitget says balances are unchanged, cold wallets were not breached, and its User Protection Fund of over $464 million covers the loss. The fund has not been independently audited, and the loss is about 84% of it.
When will Bitget withdrawals resume?
No date yet. Bitget said it would announce a plan for resuming withdrawals by 04:00 UTC on September 26, 2026.
Can I still trade on Bitget?
Yes. Deposits and trading continue; only withdrawals are paused.
Who hacked Bitget?
Bitget suspects a North Korean hacking group, citing IP addresses linked to VPN services such groups have used before. It has not published the evidence, and no government agency has confirmed the attribution.
Sources
- Gracy Chen, security notice on X
- CoinDesk: spoofed transfers, not private keys
- Decrypt: losses climb to $387M
- CryptoSlate: the hack got $36 million bigger
- Crypto Briefing: recovery bounty
- Finance Magnates: 84% of the protection fund
- Bloomingbit: withdrawal plan by Sept 26
- CoinDesk: first report
- Decrypt: first report
- Unchained
- CryptoSlate: September losses
- TFTC
- InvestingLive
This article is for information only and is not financial advice.