Cryptocurrency exchange Bitget confirmed a major security incident after someone made unauthorised transfers, affecting about $351.6 million from parts of its hot and warm wallet system on September 24, 2026. Bitget said its security systems spotted the transfers at 18:31 UTC, and its emergency team took action within minutes. The exchange in an X post explained that its cold wallets are safe and the problem only reached part of its three-tier wallet setup.
Bitget has stopped withdrawals for now but has kept deposits and trading open. According to the exchange, user account balances are still intact, and its User Protection Fund, which has been more than $464 million, covers the entire reported loss. The exchange also said it found and flagged the unusual transfer addresses and told law enforcement and on chain security companies about them.
The latest update from Gracy Chen, CEO of Bitget, states that the exchange is working with independent third-party security firms Mandiant and SlowMist to investigate the whole incident. Moreover, Bitget Wallet, which operates separately from the exchange, has not been affected.
Unauthorized Transfers Trigger Emergency Response
The first signs of trouble came from strange movements in wallets linked to Bitget. Early reports from people watching the blockchain showed over $170 million leaving different wallets, while another analysis put the first transfers at about $183 million.
The stolen assets included ETH, USDT, USDC, AVAX, and BNB. One of the transactions showed an address using $19.67 million in USDT to buy 7,111 ETH on Arbitrum in just six minutes. These early numbers turned out to be lower than what Bitget reported later, the exchange put the final affected amount at $351.6 million.
Bitget’s CEO Gracy Chen stated the breach only hit part of its hot and warm wallet levels. Cold wallets stayed safe. The exchange uses a three tier wallet system; hot and warm wallets handle daily operations, while cold wallets are offline and separate. The exchange pointed out that most assets were not affected.
After finding the problem, Bitget quickly stopped withdrawals while its security team checked the situation. Deposits and trading stayed online as usual. Bitget promised to send updates every hour and will publish a full report within 24 hours covering what went wrong and what they are doing about it.
Bitget States that the User Funds are Covered
Bitget has stressed over and over that customer balances are still accurate and users’ assets are safe. The exchange states that the entire amount lost is covered by its User Protection Fund, which holds more than $464 million, which is more than the $351.6 million loss. This protection fund has been part of Bitget’s security since 2022 when it started with $300 million. In 2023, it grew to 5,500 BTC, based on statements released alongside news of the incident.
Bitget’s main focus right now is to contain the breach and track down where the stolen assets went. The exchange said it found, flagged, and reported the suspicious addresses. Law enforcement and on chain security companies have been brought in to help with the investigation. People have also noticed that initial blockchain estimates were lower than the exchange’s final numbers. At first, observers tracked about $183 million in transfers, but the exchange later said the true amount was about $351.6 million. This shows that the first transfers people saw did not add up to the whole loss.
Backend System Compromise Under Investigation
Later, Bitget shared more details about how the breach happened. The security team made early progress tracing the source and found that a key backend system managing the wallets was hacked. The exchange explained that the hacker used this compromised system to fake transaction data and trick the exchange’s system into authorizing transfers. Bitget also said the attacker did not steal a private key, which would have been a bigger problem.
The exchange still has not said exactly how the attacker got into the backend system. Moreover, the details are still under investigation and that it would not make guesses until the inquiry is done. The exchange also brought in a third party security company for an independent forensic check. This team will verify repair steps, find out how the attack happened, and help work with law enforcement.
The incident has drawn support from others in the crypto industry. Bybit CEO Ben Zhou said his team is ready to help Bitget and mentioned that the affected exchange had helped Bybit after its own hack. Bybit is also updating LazarusBounty.com to help track the stolen money. Right now, Bitget is focused on fixing security and reopening date yet, withdrawals will start again when the technical review is finished and new security measures are in place.
