Bitget Confirms $351.6M Hot Wallet Hack, Pauses Withdrawals

Bitget confirms a $351.6M hot wallet hack via a breached wallet backend. Withdrawals are paused; Bitget Wallet urges users to revoke approvals.

By Sulochana • • 4 Min Read • 0 • Follow on Google News Add to Preferred Source
Bitget Says Hackers Forged Transfers to Take $351.6M

Bitget has confirmed that attackers drained about $351.6 million from its hot and warm wallets on September 24, 2026, the largest crypto theft of the year so far. CEO Gracy Chen said on X that the exchange detected the unauthorized transfers at 18:31 UTC (12:01 a.m. IST on September 25), paused withdrawals for all users, and will cover the full loss from its User Protection Fund, which she said holds more than $464 million.

A day later, Bitget gave its first account of how the break-in worked. On September 25, Chen said the attackers breached a core backend system behind Bitget’s wallet service. They used it to generate forged transfer requests and ran those requests through the exchange’s own approval-and-signing process, according to Bloomingbit and TechFlow.

She said Bitget has ruled out a private key leak, meaning the attackers did not steal the keys. Instead they got the system that holds those keys to sign transfers it should have rejected. How they first got into that backend is still under review.

Chen said the losses have been fully tallied and there is no further risk of funds leaving the platform. In a live Q&A covered by Cointelegraph, she listed the affected assets as ETH, XRP, USDT, USDC, AVAX, BNB and USDT0 on Arbitrum. The affected networks were Ethereum, the XRP Ledger, Avalanche, BNB Smart Chain and Arbitrum. She said withdrawals could reopen within hours or days. Deposits and trading were never halted.

Bitget’s figure is roughly double what outside researchers first spotted. Pseudonymous analyst DCF GOD, Bubblemaps and Arkham analyst Emmett Gallic flagged $174 million to $183 million moving from Bitget-labeled wallets to a freshly created address. Chen said those early estimates only captured the Ethereum side of the attack.

The on-chain trail shows an attacker in a hurry. A 0.84 ETH test transfer left a wallet labeled “Bitget 6” at 18:31:11 UTC, Forbes reported. It was followed by about $34.75 million in USDT, $19.67 million in USDT0, $12.85 million in USDC and 3,000 XAUT, Tether’s gold-backed token. Tether and Circle can freeze their tokens, so the attacker quickly swapped them into ether, which no issuer can freeze. DCF GOD noted the buyer was “paying up to +5% over spot” on Arbitrum. TechFlow later put the attacker’s holdings at roughly 68,500 ETH.

The same data complicates Bitget’s account of its response. Chen said emergency protocols kicked in immediately. But Forbes traced a final 223 ETH outflow at 21:23 UTC. That was nearly three hours after detection and seven minutes before Chen’s public notice went up.

Several of Bitget’s reassurances also rest on its own word for now. Some early on-chain reports described cold reserves among the drained wallets. Bitget says its offline cold storage was untouched, and that claim has not been independently verified. The protection fund launched in 2022 with a $300 million commitment and averaged $382 million in August, according to the company’s own reports cited by TheStreet. Outside auditors have not confirmed what the fund currently holds. Bitget’s token, BGB, fell as much as 5% as news spread.

Security specialists say this kind of breach rarely involves breaking cryptography. Ido Sofer, CEO of key management firm Sodot, described the pattern behind the Bybit theft and similar cases this way: “Those are off-chain hacks that led to on-chain loss of funds.” His examples included stolen developer credentials, deployment keys and API keys.

Chen, for her part, struck a defiant tone: “We will not run from this.”

What Bitget users should do

Bitget exchange customers don’t need to take action. The company says balances are accurate and withdrawals will resume after its security review. Users of Bitget Wallet, the company’s separate self-custody app, got different advice.

In a post on X, the Bitget Wallet account urged all users to temporarily revoke approvals granted to its smart contracts while it investigates. Approvals are standing permissions that let a contract move tokens from your wallet. The post did not say whether any wallet contracts were compromised. In the app, approvals can be reviewed and revoked under Wallet > More > Approvals.

Within hours of the theft, spoofed tokens named “ETH,” “USDC” and “USDT” began sending transfers from lookalike addresses that differ from the attacker’s only in the middle characters, Forbes reported. Addresses copied from a block explorer right now may be fakes. Treat any “recovery” or “verification” prompt tied to the incident as phishing.

The Bitget breach is the largest exchange loss since Bybit lost $1.4 billion in February 2025. It also tops the roughly $319 million drained from Blockstream’s Liquid Network Liquid Network, which TRM Labs had called 2026’s biggest hack until now.

Bitget has not attributed the attack, and no investigator has publicly tied it to a specific group. Chen said a full incident report with root-cause analysis and corrective actions would follow within 24 hours of her first notice.

Community Discussion

Join the conversation. Ask questions, share solutions, and help others.

0 Comments

Be the first to start the discussion!

Leave a Comment

Your email address will not be published. Required fields are marked *

We respect your privacy, your information is safe with us.

Latest Articles

View all