Bitget Exchange Suffers $351 Million Security Breach
The Bitget crypto exchange reported a major security breach on September 24, 2026, resulting in unauthorized transfers amounting to approximately $351.6 million from its hot and warm wallet facilities. Following the breach, the exchange suspended withdrawals while allowing deposits and trading to continue. Bitget reassured customers that their balances remained accurate and that its User Protection Fund was sufficient to cover the estimated losses.
At 18:31 UTC on the day of the incident, Bitget's security systems detected unusual transfers involving a limited number of hot wallets. The security team promptly activated emergency response protocols and initiated a full investigation. Initial assessments indicated that the breach was more extensive than first thought, with the total amount affected being confirmed after a thorough review of the transfers across various networks.
The unauthorized transfers were linked to parts of Bitget's operational wallet infrastructure. The incident is considered one of the largest security breaches in the cryptocurrency exchange sector for 2026. The exchange clarified that the affected amount fell within the coverage of its User Protection Fund, which had over $464 million at the time of the incident.
Bitget's security measures detected the unauthorized activity shortly after it began, leading to immediate isolation of the affected systems. The investigation revealed that the attackers did not steal private keys but compromised a critical backend component that interfered with transaction processing. This allowed them to manipulate transaction data and submit unauthorized transfer requests.
Investigation into Attack Vectors Underway
Investigators are currently working to determine how the attackers gained access to the backend environment. Various potential entry points are being considered, including software vulnerabilities and compromised credentials. The complexity of the attack highlights the risks associated with the broader cryptocurrency ecosystem, where backend services can be targeted to facilitate unauthorized asset transfers.
As the investigation continues, the stolen assets have reportedly changed hands and been laundered through various exchanges and blockchain networks. Bitget has identified abnormal transfer addresses and is monitoring subsequent movements from these flagged destinations. The exchange has emphasized the importance of security and has urged customers to remain vigilant against potential phishing attempts that often follow major hacks.
Filed & Cleared
The immediate consequence of the breach was the suspension of withdrawals, which Bitget implemented as a precautionary measure. This decision was made to prevent further unauthorized access while the security review was conducted. Customers were informed that their account balances remained intact, despite the operational restrictions on withdrawals. The exchange has not provided a timeline for when withdrawals will resume, stating that this will depend on the completion of their security review.
Bitget's leadership has indicated a possible connection to North Korean hackers, drawing on behavioral similarities and technical indicators observed during the investigation. However, definitive attribution has yet to be established, and the investigation remains ongoing as authorities work to uncover the full scope of the breach and the identity of the attackers.