Cryptocurrency exchange Bitget suffered a $351.6 million security breach on September 24, 2026, targeting its hot and warm wallets. CEO Gracy Chen confirmed that offline cold wallets remained secure and that the exchange's $464 million User Protection Fund will fully cover the losses. While Bitget suspended withdrawals to conduct a security review, on-chain data tracked the attacker rapidly swapping stablecoins and tokenized gold for ether to evade issuer freezes. The incident marks the largest exchange hack of 2026.
Status of Bitget's wallets
- ▪Cryptocurrency exchange Bitget suffered a security breach on September 24, 2026, resulting in approximately $351.6 million in unauthorized transfers from its hot and warm wallets
- ▪Bitget Chief Executive Officer Gracy Chen confirmed that the exchange's cold wallets remained fully secure and unaffected by the September 24, 2026 breach that drained $351.6 million
Affected assets
- ▪Two XRP Ledger wallets labeled as Bitget's transferred 93.7 million XRP, worth about $143 million, to a new address on September 24, 2026
- ▪The assets affected in Bitget's $351.6 million breach on September 24, 2026 included Ether, XRP, USDT, USDC, Avalanche, BNB, and Tether Gold across multiple blockchain networks
Conversion of stolen assets
- ▪The attacker behind the Bitget hack routed stablecoins and tokenized gold through decentralized exchange routers, paying up to a 5% premium over spot prices to rapidly convert the assets into ether
- ▪On-chain data showed a newly created wallet address swap $19.67 million in USDT0 for 7,111 ether on Arbitrum within six minutes of the initial breach at Bitget on September 24, 2026
Bitget's response to the breach
- ▪Bitget pledged to provide hourly updates and publish a full incident report detailing the root cause and corrective measures within 24 hours of the $351.6 million breach
- ▪Bitget temporarily suspended customer withdrawals on September 24, 2026, to conduct a comprehensive security review, while deposits and trading remained operational
- ▪Bitget Chief Executive Officer Gracy Chen stated that the entire $351.6 million loss from the September 24, 2026 hot wallet hack is covered by Bitget's User Protection Fund, which holds over $464 million
Comparison to the Bybit breach
- ▪The $351.6 million Bitget exploit represents the largest centralized cryptocurrency exchange loss since the February 2025 Bybit breach, which resulted in a $1.4 billion to $1.5 billion theft
- ▪Attackers spoofed a signing screen to hijack a routine cold-wallet transfer from Bybit in February 2025, resulting in a $1.4 billion loss
Debatable claims
- ▪Centralized exchanges are too insecure to be trusted with custody of user cryptocurrency
- ▪Bitget's three-hour delay in halting unauthorized transfers represents an unacceptable security failure
- ▪Bitget was justified in keeping trading and deposits operational during its security review
- ▪Bitget's User Protection Fund is sufficient to guarantee the safety of its users' assets
Story comments
Loading comments…