Hackers drain $351.6 million from Bitget in possibly 2026’s biggest crypto heist

Bitget’s own token, BGB, fell roughly 5% after reports of the hack began circulating late in the US session. The broader crypto market is up nearly 10% over the past week, which suggests traders see this as a Bitget problem rather than a threat to the whole sector.

The attacker’s rushed ether buying on Arbitrum briefly pushed the WETH/USDC pool price to about $2,870. That was a short-lived, local distortion, not real demand. The bigger risk to sentiment is time: the longer withdrawals stay frozen, the more likely it is that doubts spread to other centralised exchanges.

—

Bitget says customers are covered after losing $351.6 million to hackers, but with withdrawals frozen and the break-in method still unknown, the real test is how quickly users can get their money out.

Summary:

  • Bitget detected unauthorised transfers from some of its hot wallets at 18:31 UTC on 24 September, and CEO Gracy Chen put the amount affected at about $351.6 million.
  • Chen said the offline cold wallets are secure and the breach was limited to parts of the hot and warm layers of its three-tier wallet system.
  • Withdrawals are suspended for all users pending a security review, while deposits and trading continue.
  • Chen said the User Protection Fund, which holds more than $464 million, covers the full loss, though what the fund holds has not been independently verified.
  • The attack method has not been disclosed. Bitget has promised hourly updates and a full incident report within 24 hours, and has notified law enforcement.
  • On-chain researchers first estimated $174 million to $183 million, about half the confirmed figure. If Bitget’s figure holds, it pushes September’s reported crypto hack losses above $684 million, the highest monthly total this year.

Crypto exchange Bitget has confirmed that about $351.6 million in digital assets was taken from its internet-connected wallets on Thursday, in what may be the largest crypto hack of 2026 so far. The exchange has suspended customer withdrawals while it investigates, although chief executive Gracy Chen said the full loss will be covered and customer balances remain accurate.

In a security notice posted on X, Chen said Bitget’s systems detected unauthorised transfers at 18:31 UTC on 24 September and emergency procedures were triggered immediately. She said the breach was confined to parts of the “hot” and “warm” layers of the exchange’s three-tier wallet setup, while its offline “cold” wallets were not affected. Deposits and trading are still running, but withdrawals are frozen for all users pending a security review. Bitget has not disclosed how the attackers got in. It has promised hourly updates and a full incident report, covering the root cause and corrective steps, within 24 hours, and said it has flagged the receiving addresses and alerted law enforcement and blockchain security firms.

For readers new to crypto, the wallet distinction matters. An exchange holds customer coins in digital wallets controlled by private keys, which work like passwords that authorise a transfer. A hot wallet stays online so the exchange can process withdrawals quickly, while a cold wallet keeps its keys offline, making it much harder to reach but slower to use. Exchanges typically keep only a working float in hot wallets, which is why those wallets are the usual target. Because blockchain transfers generally cannot be reversed, there is no bank to call once coins leave a compromised wallet.

Independent researchers spotted the outflows before Bitget spoke. Arkham Intelligence analyst Emmett Gallic said funds from several Bitget-labelled wallets on multiple blockchains were consolidated into a single address, and early estimates ran at $174 million to $183 million, roughly half the figure Bitget later confirmed. One transaction stood out: a newly created wallet swapped about $19.7 million of USDT0, a cross-chain version of the Tether stablecoin, into 7,111 ether in around six minutes, paying up to 5% above the market price, Decrypt reported. Paying that premium suggests speed mattered more than price. Stablecoins such as Tether can be frozen by their issuer, whereas ether has no central issuer able to block it, so converting quickly is a pattern analysts have linked to the early stages of past exchange hacks.

Hacks on this scale are not rare. DeFiLlama had recorded about $331 million lost across 17 incidents in September before the 19 September Fetch.ai exploit, most of it from a roughly $320 million incident at Liquid Network, whose attackers claimed to be “white hat” hackers. CryptoSlate calculated that Bitget’s losses would lift September’s reported total above $684 million, overtaking April as the costliest month of 2026, although that figure could change if funds are recovered. Social media claims that North Korea is behind the attack have not been confirmed, and Bitget has declined to speculate.

Chen said the exchange’s User Protection Fund, which holds more than $464 million, covers the entire loss. That is larger than the confirmed figure, but as TFTC noted, the fund’s asset mix has not been independently verified, and the freeze applies even to users whose funds were untouched. That is the practical lesson for newcomers: coins left on an exchange are only as safe as that exchange’s security and its ability to absorb losses.

What to watch next is the incident report due within 24 hours, which should explain how the breach happened, and whether withdrawals resume smoothly and in full. A quick reopening with a clear root cause would support Bitget’s assurances, while a longer freeze or an upward revision to the loss figure would weaken them. The path of the stolen ether also matters: if it moves through privacy tools such as Tornado Cash, recovery becomes far less likely. Anyone holding funds on the platform may be best served by waiting for that report before drawing conclusions. 

This article was written by Eamonn Sheridan at investinglive.com.

Leave a Reply