Crypto exchange Bitget has confirmed unauthorized transfers affecting approximately $351.6 million in assets, after onchain researchers detected unusual movements from wallets linked to the platform on September 24.
Bitget said its security systems detected the unauthorized transfers at 18:31 UTC, prompting its security team to activate emergency response procedures within minutes. The incident affected portions of the exchange's hot and warm wallet infrastructure, while its cold wallets remained secure, according to the company.
CEO Gracy Chen said customer balances remain accurate and user assets are protected. Bitget temporarily suspended withdrawals while conducting a security review, although deposits and trading remained operational.
[SECURITY NOTICE] Bitget Hot Wallet Incident — September 24, 2026
— Gracy Chen @Bitget (@GracyBitget) September 24, 2026
At 18:31 UTC on September 24, 2026, Bitget's security systems detected unauthorized transfers from some of our hot wallets. Our security team activated emergency response protocols immediately.
What we have…
[SECURITY NOTICE] Bitget Hot Wallet Incident — September 24, 2026
— Gracy Chen @Bitget (@GracyBitget) September 24, 2026
At 18:31 UTC on September 24, 2026, Bitget's security systems detected unauthorized transfers from some of our hot wallets. Our security team activated emergency response protocols immediately.
What we have…
Onchain Activity Raises the Alarm
Before Bitget confirmed the breach, blockchain researchers had spotted large transfers from exchange-linked addresses into newly created wallets.
One of the earliest suspicious transactions involved approximately 19.67 million USDT0 on Arbitrum, which was rapidly exchanged for around 7,111 ETH through UniswapX and 1inch Fusion. Onchain observers noted that the trades were executed quickly and at unfavorable prices, suggesting that speed was being prioritized over execution quality.
Additional transfers involving assets including ETH, USDT, USDC, AVAX, BNB and XAUT were subsequently observed moving from Bitget-labeled addresses. Early estimates from blockchain analysts placed visible suspicious transfers around $180 million before Bitget disclosed that its internal estimate of affected assets was substantially higher at $351.6 million.
Bitget has cautioned against drawing conclusions about the precise attack method before its investigation is completed.
Protection Fund Expected to Cover Losses
Despite the size of the incident, Bitget says customers should not bear the financial loss.
The exchange's User Protection Fund currently holds more than $464 million, exceeding the estimated $351.6 million affected by the breach. Bitget said the entire loss therefore falls within the fund's coverage.
The protection fund was established years before the latest attack as a financial backstop against security incidents and unexpected losses affecting customers.
Bitget said it had already identified and flagged suspicious addresses while notifying law enforcement and blockchain security companies. Withdrawals were temporarily suspended as a precaution and are expected to resume after the exchange completes its security review.
Attack Vector Remains Under Investigation
A major unanswered question is how the attackers gained the ability to initiate the unauthorized transfers.
Bitget said it would not speculate about the attack vector before completing its investigation. The exchange committed to providing hourly updates and publishing a full incident report containing a root-cause analysis and corrective measures within 24 hours of its initial announcement.
Some subsequent reports have pointed toward a possible compromise involving a third-party wallet tool or backend system rather than a straightforward private-key leak, but the precise mechanism remained under investigation at the time of reporting.
That distinction will be important for determining whether the incident exposed a weakness unique to Bitget or a vulnerability that could affect similar exchange infrastructure.
Exchange Security Faces Another Major Test
The Bitget breach adds another major incident to the crypto industry's long-running struggle with centralized exchange security.
In February 2025, Bybit suffered an approximately $1.4 billion attack involving its Ethereum cold-wallet signing process, an incident later attributed by U.S. authorities to North Korean hackers. The theft remains considerably larger than Bitget's reported loss.
Bitget's case differs because the exchange says its cold-storage reserves were untouched, with the breach contained to parts of its hot and warm wallet layers.
The incident nevertheless highlights the tradeoff exchanges face when maintaining online wallets capable of processing customer withdrawals rapidly. Those systems require greater connectivity than offline storage, increasing their potential exposure to attackers.
For Bitget, the immediate question is whether its $464 million protection fund can absorb the $351.6 million loss without disrupting customers, while its upcoming incident report will face scrutiny over exactly how such a large amount was transferred before the breach was contained.



