• security
  • news
  • 47 min

Bitget Halts Withdrawals After $352M Theft. Exchange Promises to Cover the Losses

Hundreds of millions of dollars have been stolen from one of the largest centralized crypto exchanges. Withdrawals remain suspended as customers wait to regain access to their funds, while investigators piece together how the attack happened. Here’s what we kn

0

nft.eu
  • rating +20
  • subscribers 91

On September 24, Bitget’s security systems detected unauthorized transfers. Several hours later, the exchange confirmed the incident: Bitget CEO Gracy Chen said that hackers had stolen $351.6M from its wallets. By the evening, the figure had risen to $387.5M, according to the latest information available at the time of publication. This is the largest confirmed theft from a crypto exchange in 2026.

Withdrawals remain suspended, while trading and deposits continue. The company says it will cover the full loss.

What Happened

At 18:31 UTC on September 24, Bitget detected unauthorized transfers. According to Gracy Chen, the attacker gained access to the exchange’s internal wallet management system, altered transaction data and got the transactions approved through the exchange’s standard signing process. The system approved 19 transfers, treating them as routine payouts.

Bitget stores funds in hot, warm and cold wallets. The attack affected some of the hot and warm wallets used for daily operations and to maintain liquidity. The company says its cold wallets were not affected, along with the non-custodial Bitget Wallet, which runs on separate infrastructure.

Company statement. Source: Bitget CEO on X
Company statement. Source: Bitget CEO on X

Blockchain security firms Mandiant and SlowMist are investigating the incident together with law enforcement agencies.

Chen promised to publish a full analysis of the attack and its causes within 24 hours. It is still unclear exactly when Bitget will resume withdrawals: the exchange officially says it could take several hours or several days.

Early analyst estimates put the losses at around $183M. Lookonchain now estimates the stolen assets at roughly $351.6M, including around 103M XRP worth $157M, 31.9K ETH worth $86M, plus USDT, USDC, USDT0, XAUt, BNB, AVAX, TRX and ZEC. The exchange identified Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Smart Chain, Base and Tron as the affected networks. XRP accounts for the largest share. The discrepancy arose because some XRP transactions were not initially picked up by certain tracking systems.

List of stolen coins. Source: Lookonchain
List of stolen coins. Source: Lookonchain

The attacker has already converted a significant portion of the assets moved through Ethereum-based networks into ether — around 68K ETH worth approximately $183M.

By the evening of September 25, Bitget announced a bounty program offering a 5% reward on funds successfully frozen and another 5% on assets successfully recovered.

Will Bitget’s Reserves Be Enough to Cover the Losses?

Bitget said that its user protection fund holds more than $464M in Bitcoin, enough to cover the entire loss. Whether the exchange will actually use those funds to do so is one of the key questions for the market.

Having funds in a reserve does not necessarily mean customers will be able to withdraw their money as soon as withdrawals resume. The exchange first needs to complete its review, determine how the payouts will be handled and make sure its available liquidity is sufficient to meet its obligations to users.

Who Could Be Behind the Attack?

Chen said North Korean hackers were likely behind the attack but did not name a specific group. She also denied that any Bitget employees were involved.

“Investigators found internet addresses used by a North Korean group through virtual private networks. The attack methods are similar to those previously associated with North Korean hackers,” she said.

Unconfirmed reports say North Korean hackers are behind the attack. Source: X
Unconfirmed reports say North Korean hackers are behind the attack. Source: X

As of midday on September 25, neither law enforcement agencies nor on-chain investigators had officially confirmed the claim, so the North Korea attribution remained unconfirmed.

On-chain investigator ZachXBT said he had no plans to investigate the hack, at least for now.

“I currently have no plans to monitor this exploit. I stopped spending time helping people in the industry who do not support my work,” he wrote.

On-chain researcher Specter linked the Bitget hack to a North Korean cluster and to the July theft from AFX Trade.

“Who is behind the hack? I present to you the Lazarus Group. I linked it to the AFX hack, where $24M was stolen in July and which is attributed to TraderTraitor. The XRP stolen from Bitget was moved through a bridge and can be directly linked to funds from the AFX attack,” he said.

Industry’s Opinions

Esme Pau of CertiK called the Bitget attack “another warning sign for the digital asset industry.”

“The scale of the losses is roughly equivalent to three-quarters of the exchange’s reserve fund and goes beyond a simple security breach, making this a crisis-level event,” she said.

Aneirin Flynn, head of Singapore-based cybersecurity company FailSafe, said that a major theft from hot wallets “shatters the illusion that major CEXs have solved their security problems.”

Ledger CTO Charles Guillemetthinks the growing capabilities of AI are making it cheaper to find vulnerabilities and develop exploits, giving attackers an advantage.

“Security in crypto has always been a difficult challenge. AI is shifting the advantage toward attackers. Closing this gap requires more than simply fixing the aftermath of the next attack — it requires changes to the underlying principles and architecture of security,” he wrote.

Bybit CEO Ben Zhou offered to help Bitget with the investigation, as Bitget also helped Bybit investigate its incident after the exchange lost around $1.5B in February 2025.

Support from CZ. Source: Changpeng Zhao on X
Support from CZ. Source: Changpeng Zhao on X

How Bitget’s Hack Compares With Other Major Crypto Thefts

The closest comparison in terms of scale is the Bybit hack, in which $1.5B was stolen in February 2025. The attackers drained the funds from one of the exchange’s cold ETH wallets. The investigation linked the attack to Lazarus.

The Bitget incident is more similar in its mechanics to the $308M theft from DMM Bitcoin in 2024. In that case, the FBI also linked the attack to TraderTraitor. The key difference is that Bitget says its private keys were not compromised.

In September 2026, “white hat” hackers took around $320M in BTC from a Liquid Network wallet. Most of the funds, 3,400 BTC, were later returned.

According to Lookonchain, September was the costliest month of 2026 so far in terms of crypto losses from hacks. Total losses for the year have already exceeded $2.3B.

Our Take

The main question right now is not how much Bitget lost, but how the attackers got around its security controls. Based on the preliminary data, the attack appears to have targeted the logic used to manage transactions rather than the cryptography protecting the wallets. Even multisignature protection cannot prevent an attack if the system itself can be tricked into treating a fraudulent transaction as legitimate.

The incident shows how sophisticated attacks on exchange infrastructure are becoming. A well-prepared social engineering campaign can bypass even multiple layers of security, so exchanges will likely make transaction checks and approval processes even more complex after an incident like this.

Another interesting detail is that the attackers converted a significant share of the stolen assets into ETH. This may have been driven by liquidity and the ease of moving funds, but the choice also suggests a strong understanding of the Ethereum infrastructure.

We still do not know the true scale of the losses. On-chain estimates only track addresses already identified as belonging to Bitget. If some of the exchange’s wallets have not yet been identified, transfers from those wallets will not appear in these figures.

It is also impossible for the market to confirm how much will actually remain in the protection fund after payouts. The experience of FTX shows what can happen when there is a gap between public statements and the actual state of a company’s finances. It is too early to call this a “black swan,” but if the losses turn out to be higher than the reported reserves, the question will be where the exchange will get the additional funds needed to cover the shortfall.

This post is for informational purposes only and does not constitute advertising or investment advice. Please do your own research before making any decisions.

0

Comments

0