Bitget Hack: $351.6M Drained in Backend Breach as $464M Protection Fund Covers Losses
Cryptocurrency exchange Bitget detected unauthorized transfers draining approximately $351.6 million from its hot and warm wallet infrastructure at 18:31 UTC on September 24, 2026. CEO Gracy Chen said attackers compromised a backend system to spoof transaction data and trigger the exchange's authorization process rather than stealing private keys, and that cold wallets were unaffected. Bitget suspended withdrawals while keeping deposits and trading active, and said its User Protection Fund of more than $464 million will fully cover customer losses.
Key takeaways
- Bitget reported roughly $351.6 million in unauthorized transfers from hot and warm wallets, detected at 18:31 UTC on September 24, 2026.
- Cold wallets were reported secure, and the exchange says no private keys were obtained.
- The attack worked through a compromised backend system that spoofed transaction data, according to CEO Gracy Chen.
- Withdrawals are paused; deposits and trading continue, and Bitget says its $464 million User Protection Fund covers the full loss.
- Investigators and Chen cited IP addresses and VPN patterns pointing to potential North Korean involvement.
What happened at Bitget
Bitget confirmed that its systems flagged unauthorized transfers at 18:31 UTC on September 24, 2026, draining approximately $351.6 million from parts of its hot and warm wallet infrastructure. The exchange said its cold wallets were secure and unaffected, and that customer account balances remain accurate.
In response, Bitget suspended withdrawal services pending a security review while keeping deposits and trading open. Reported totals for the incident varied across outlets, between $350 million and $352 million, while an external on-chain valuation by Lookonchain put the figure at $356.8 million.
How funds moved without stolen private keys
According to Chen, the breach did not involve a private-key leak. "The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out," she said, as reported by BeInCrypto.
Chen also drew a line between the backend compromise and other common attack vectors. "They did not forge user withdrawal requests, nor did they obtain our private keys of the cold wallet and any hot, warm wallet," she said, per Cointelegraph.
What was stolen
On-chain tracker Lookonchain estimated that XRP represented the largest stolen component, comprising roughly 102.93 million tokens worth about $157.48 million, according to reporting by crypto.news and CoinGape.
Suspicions point to North Korea
Chen and on-chain investigators cited IP addresses and VPN usage patterns suggesting potential involvement by North Korean actors, as reported by Cointelegraph. "The pattern looks very much like what the North Korean team did before," Chen said. During a live Q&A reported by Cointelegraph on September 25, 2026, Chen also said some of the stolen funds had already been recovered, without specifying an amount.
User Protection Fund covers the loss
Bitget stated that the loss falls entirely within the coverage of its User Protection Fund, which holds more than $464 million. "The full amount of this loss falls within the coverage of Bitget's User Protection Fund," Chen said, as reported by CryptoSlate. She added, per CryptoPotato: "We will not run from this, and every dollar will be accounted for."
A costly month for crypto security
The breach ranks as the largest crypto breach of 2026 according to DeFiLlama, as reported by BeInCrypto. CryptoSlate reported that the exploit pushed total September 2026 crypto hack losses past $684 million, making it the costliest month for hacks in 2026.
Frequently asked questions
Are Bitget user funds safe?
Bitget says customer balances are accurate and that the loss of approximately $351.6 million is fully covered by its User Protection Fund of more than $464 million.
Can I still trade and deposit on Bitget?
Yes. Bitget suspended withdrawals during the security review but kept deposits and trading active, according to CoinCentral.
Were private keys or cold wallets compromised?
No, according to the exchange. Chen said attackers spoofed transaction data through a compromised backend system, and cold wallets were reported secure and unaffected.
Who is suspected of the attack?
Attribution is not confirmed. Chen and investigators pointed to IP addresses and VPN patterns consistent with North Korean actors, per Cointelegraph.