CryptoMedium•25 September 2026•
5 min read

Bitget Exchange Wallet Breach Affects $351.6 Million; Fund Covers Loss, Company Says

Key Facts

1Bitget said unauthorized transfers on September 24, 2026 affected about $351.6 million in exchange hot and warm wallets.
2Bitget Wallet said its separate self-custody service and users’ assets were unaffected.
3The exchange said its User Protection Fund exceeds $464 million and covers the estimated loss, while withdrawals remained paused for a security review.

Crypto exchange Bitget said unauthorized transfers affected about $351.6 million in assets held in its hot and warm wallets on September 24, 2026. The exchange temporarily suspended withdrawals for a security review and said its User Protection Fund covers the loss. The incident involved infrastructure through which the exchange holds assets and processes transfers for customers. The separate self-custody product Bitget Wallet said its systems and users’ assets were unaffected. That distinction matters for identifying whose access was disrupted and which losses the exchange has undertaken to cover.

Bitget’s security systems detected the transfers at 18:31 UTC on September 24, according to the company’s security notice. The exchange estimated that approximately $351.6 million was affected and said the breach was confined to parts of its hot and warm wallet layers. It said its cold wallets remained secure and customer account balances stayed accurate. The affected-asset figure is the company’s estimate of the incident’s scale, rather than a declaration that customers have suffered a final loss of that amount. Recoveries from the transferred assets may change the eventual financial burden, but they do not change the volume of unauthorized transfers Bitget reported.

Hot wallets connect to an exchange’s operating systems so it can process asset movements, making a breach there different from one involving assets held apart from those systems. Chief Executive Gracy Chen said attackers entered a backend wallet-service system and fed forged transfer data into the approval and signing process, according to independent accounts of her remarks. She also said investigators had ruled out theft of the affected wallets’ private keys. If that preliminary account holds, the failure lay in the instructions presented for approval before a transfer was signed, rather than in possession of the keys themselves. Investigators were still examining how the attackers first entered the backend system.

Chen said the affected assets included ETH, XRP, BNB, AVAX, USDT and USDC, along with other tokens, according to reports of her update. She listed Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Smart Chain and Base among the affected networks. That spread means the overall loss estimate combines transfers across several chains, rather than the balance of a single wallet. The distribution also matters for tracing funds: freezing an address or recovering a token on one network would not settle the status of assets moved on other networks. Bitget said it identified addresses linked to the transfers and notified authorities and onchain security firms.

Bitget Wallet said its self-custody systems and users’ assets were unaffected by the exchange incident. It said users of that product retain control of their private keys and onchain assets, and that its operating infrastructure is separate from Bitget Exchange. The exchange’s security notice, by contrast, concerns wallets used by the centralized trading platform to hold assets and operate transfers. The shared brand can obscure the difference in who controls assets in each service, a distinction that changes a customer’s exposure to this event. Bitget’s withdrawal pause applied to the exchange, while Bitget Wallet said its services continued to operate.

Bitget said its User Protection Fund held more than $464 million and that the incident’s loss fell within the fund’s coverage. That stated amount exceeds the exchange’s $351.6 million estimate of affected assets, but the comparison describes claimed coverage, not recovery of stolen assets or completed compensation. The exchange said customer balances remained accurate and deposits and trading continued during the withdrawal pause. For customers holding assets on the platform, the practical test is whether withdrawals resume while those stated balances remain intact. The final burden on the fund will also depend on the completed investigation and any assets recovered.

The company activated its emergency response after detecting the transfers, flagged unusual addresses and contacted authorities and onchain security specialists, its notice said. A temporary withdrawal halt limits outgoing activity while transfer systems are examined, but it also delays customers’ access to assets held on the exchange. Bitget said deposits and trading remained available, separating activity within its marketplace from the ability to move assets away from it. For a customer who needs to withdraw, the restoration of that service matters more immediately than continued trading alone. The operational test is whether the security review permits withdrawals to resume without further unauthorized transfers.

Chen described preliminary similarities between the attack and patterns associated with North Korean groups, citing internet-address behavior and onchain analysis in reported remarks. That remains the company’s suspicion, not an independent or final identification of the perpetrators. Suspected attribution does not, by itself, explain how the attackers entered the backend system, which is a separate question from tracing assets after they left. An assessment of continuing operational risk therefore rests on the findings about the approval and signing process and the steps Bitget takes to repair it. Prospects for recovering assets also depend on tracing transfers and cooperation with the parties the company notified.

Bitget said withdrawals would return after its security review and that it would publish investigation updates, without giving a firm restoration time. The decisive next step for customers is an announced withdrawal restart alongside the continued accuracy of the balances the exchange has affirmed. A root-cause account should show whether the reported backend intrusion and forged transfer data fully explain the incident. Any assets recovered could reduce the amount ultimately drawn from the protection fund; the company’s coverage commitment is its stated position in the meantime. Until the investigation concludes, the technical account and the suspected link to North Korea remain preliminary.