Bitget Hit by $350M+ Security Breach as Exchange Suspends Withdrawals

Why Trust Web3Bet
Our team of experts has independently reviewed and evaluated all the products and services featured on this page to ensure you receive accurate and reliable information
Crypto exchange Bitget has suffered a major security breach after unauthorized transfers moved hundreds of millions of dollars from its wallet infrastructure.
The incident was detected on September 24, 2026, when Bitget’s security systems identified suspicious transactions involving its hot and warm wallets. The exchange initially estimated that approximately $351.6 million in digital assets had been affected. A subsequent investigation increased the figure to approximately $387.5 million.
Bitget temporarily suspended withdrawals while its security teams investigated the attack and worked to secure the affected systems.
Bitget Detects Unauthorized Wallet Transfers
According to Bitget CEO Gracy Chen, the exchange detected unauthorized transfers at 18:31 UTC on September 24 and activated its emergency response procedures within minutes.
The incident affected parts of Bitget’s hot and warm wallet infrastructure. The company said its cold wallets remained secure and that no further unauthorized transfers were possible after the attack was contained.
Initial blockchain monitoring quickly identified unusually large movements from wallets associated with Bitget. On-chain analysts subsequently tracked assets being transferred to attacker-controlled addresses.
More Than $350 Million in Crypto Was Transferred
The first estimate released by Bitget put the value of the affected assets at approximately $351.6 million.
Further on-chain analysis identified additional transfers involving networks that were not included in the initial calculation. Bitget later revised the total to approximately $387.5 million. The updated figure includes assets transferred across Ethereum and other EVM networks, the XRP Ledger, Zcash and TRON.
The assets involved included XRP, ETH, USDT, USDC, USDT0, XAUt, BNB, AVAX and TRX.
Lookonchain’s analysis indicated that XRP and ETH represented two of the largest components of the stolen assets, with approximately 102.93 million XRP and 31,890 ETH among the funds identified.
Withdrawals Suspended After the Attack
Bitget suspended withdrawals as a precaution while it investigated the security breach.
At the same time, the exchange said that deposits and trading remained operational and that customer account balances were accurate. Bitget also stated that the affected loss was covered by its User Protection Fund, which held more than $464 million in publicly verifiable assets.
The exchange initially said that an update on the withdrawal status would be provided after the security review and remediation work were completed.
Investigation Points to Backend Compromise
Bitget’s preliminary investigation indicated that the incident was not caused by a leak of private keys.
Instead, the company said attackers compromised a backend component within its wallet infrastructure and used manipulated transaction data to trigger the authorization process for transfers. The precise attack method remained under investigation at the time of the initial reports.
Bitget has been working with external cybersecurity specialists, including Mandiant and SlowMist, while tracing the stolen assets and investigating how the attackers bypassed the exchange’s security controls.
Bitget Begins Asset Recovery Efforts
Following the breach, Bitget began tracking the transferred funds and identifying the addresses controlled by the attackers.
The exchange has also launched a fund-tracing and recovery bounty program as part of its response. Bitget said its security teams had identified the attack path and remediated the underlying vulnerability, with further security validation required before withdrawals could safely resume.
Blockchain security firms have continued monitoring the movement of the stolen assets across different networks.
Possible North Korean Connection Under Investigation
The incident has also attracted attention from blockchain intelligence companies investigating potential links to North Korean cybercrime groups.
Elliptic said multiple indicators suggest the attack is highly likely to be linked to DPRK-associated actors, citing infrastructure overlaps and similarities with previous attacks attributed to North Korean groups.
However, attribution remains part of the ongoing investigation, and the available evidence does not establish the identity of the attackers with certainty.
What Happens Next for Bitget?
The Bitget incident has become one of the largest cryptocurrency exchange security breaches reported in 2026.
For the exchange, the immediate priorities are securing its infrastructure, completing the investigation, restoring withdrawals and tracing the transferred assets.
Bitget has said that the incident is contained and that its User Protection Fund is sufficient to cover the reported loss. The company is also expected to provide additional technical details as its investigation progresses.
Source: https://x.com/bitget/status/2103236552482848927?s=20

