Ticker

20/recent/ticker-posts

Bitget’s $351.6 Million Security Breach: What Happened, How Safe Are Users’ Funds, and a Full Investigation of Viral Claims



News of approximately $351.6 million in unauthorized transfers linked to cryptocurrency exchange Bitget emerged rapidly on September 24–25, 2026. On social media, it is being directly described as a “$351 million Bitget hack,” while some posts claim that several cryptocurrencies, including ETH, USDT, BNB, AVAX, and XRP, were drained from hot wallets in less than an hour.

Based on the available official information and independent on-chain monitoring, Bitget has confirmed that assets worth approximately $351.6 million were affected and that unauthorized transfers occurred from parts of its hot/warm wallet infrastructure. However, the complete technical cause of the incident and the final loss have not yet been established through a fully verified and detailed incident report. Therefore, claims that exactly $351.6 million was ultimately stolen and definitive statements about how the attack was carried out should be treated cautiously until the investigation is completed.

What Exactly Happened at Bitget ?

According to Bitget’s official Security Notice, at 18:31 UTC on September 24, 2026, its security systems detected unauthorized transfers from certain hot wallets. The company’s security team then immediately activated its emergency response protocol. Bitget’s initial assessment estimated that approximately $351.6 million in assets were affected.

In Indian Standard Time, the incident occurred at approximately 12:01 AM IST on September 25. Following the incident, Bitget temporarily suspended all withdrawals as a precautionary measure, while stating that deposits and trading remained operational. The company also said that abnormal transfer addresses had been identified and reported, and that relevant authorities and on-chain security firms had been notified to assist with the investigation.

Was the Entire Bitget System Affected ?

No. This distinction is very important.

According to Bitget, its wallet infrastructure consists of three layers: hot wallets, warm wallets, and cold wallets. The company said that the incident was limited to a portion of its hot and warm wallet layers and that cold wallets remained unaffected.

Hot wallets are generally connected to the internet and are used for regular transactions, whereas cold wallets are maintained in comparatively offline environments. Therefore, a security incident involving some hot wallets does not automatically mean that all of an exchange’s wallet reserves were compromised.

Bitget has also stated that user account balances remain correct and user assets are safe. According to the company, the losses associated with this incident are covered by its User Protection Fund, which at the time held more than $464 million.

It is important to note that this $464 million figure is Bitget’s own official claim. It should not be interpreted as an independent government guarantee or as bank-style deposit insurance.

Which Cryptocurrencies Were Affected ?


Social media posts have primarily mentioned ETH, USDT, BNB, AVAX, and XRP. Independent blockchain-monitoring firm Lookonchain later identified several assets in its on-chain analysis, including XRP, ETH, USDT, USDC, USD₮0, XAUt, BNB, AVAX, and TRX.

One of its updates mentioned approximately 102.93 million XRP and 31,890 ETH, along with various other assets, and estimated the total on-chain value at around $356.8 million.

This figure is somewhat different from Bitget’s official preliminary estimate of $351.6 million. Differences can arise because of the timing of valuation, subsequent blockchain movements, and changes involving tracked addresses. Therefore, for factual reporting, it is better to keep Bitget’s official $351.6 million figure and independent on-chain estimates clearly separated.

Lookonchain also reported that a significant portion of the affected assets on EVM-compatible chains was later swapped into ETH, with the amount estimated to have reached approximately 67,982 ETH. This is based on blockchain monitoring and should not be treated as Bitget’s final forensic accounting.

Was Bitget’s Private Key Stolen ?

There are also several claims circulating on social media regarding this issue.

In its initial official Security Notice, Bitget avoided speculating about the attack vector and stated that it would not speculate about the cause until the investigation was completed.

Subsequent preliminary investigations by cybersecurity researchers have pointed toward the possibility of a compromise of the wallet-backend infrastructure. SlowMist’s incident database has listed preliminary findings involving a compromise of the core wallet-backend system and the spoofing of transfer data, while distinguishing this from a direct private-key leak.

Therefore, the more appropriate description at this stage is that preliminary findings point toward a possible backend/system compromise. However, the final technical root cause should only be considered established once Bitget’s complete incident investigation is released.

Was Bitget Wallet Also Hacked ?

Here, it is extremely important to distinguish between Bitget Exchange and Bitget Wallet.

Bitget issued a separate clarification regarding its self-custodial Bitget Wallet, stating that its infrastructure is independent of Bitget Exchange and that the current investigation had found no impact on Bitget Wallet’s systems or users’ self-custodied assets.

In a self-custodial wallet, private keys and the seed phrase are controlled by the user. Therefore, the incident involving Bitget Exchange should not automatically be interpreted as an attack on the assets of Bitget Wallet users.

The company has also warned users about phishing attempts and fake messages related to “security verification” or “asset migration.” Users should never share their private keys, seed phrases, or verification codes with anyone.

When Will Withdrawals Resume ?

As of September 25, 2026, according to the available official information, withdrawals remain temporarily suspended.

Bitget has stated that withdrawals will be restored after the security review is completed. The company has not committed to a specific time for resuming withdrawals.

This type of response is not unusual following a major wallet-security incident. Continuing withdrawals before completing security checks could potentially create additional unauthorized-transfer risks. Therefore, temporarily suspending withdrawals while an investigation and security review are conducted is a standard incident-response measure.

What Is True and What Is Misleading in the Viral Claims ?
Bitget has officially confirmed that approximately $351.6 million worth of assets were affected.

Unauthorized transfers occurred from parts of the hot/warm wallet infrastructure, and withdrawals were temporarily suspended.

Bitget says that its cold wallets remained secure and that its User Protection Fund contained more than $464 million.
Requires Caution:


The statement that “hackers definitely stole exactly $351.6 million” is more definitive than Bitget’s initial wording of “estimated funds affected.” Independent on-chain trackers have also produced a different valuation of approximately $356.8 million.

The complete technical method of the attack, the identity of the responsible attacker, and the final recovery amount should not be presented as established facts before the investigation is completed.

The incident that occurred at Bitget on September 24, 2026, is a significant cryptocurrency security incident. According to the company, approximately $351.6 million worth of assets were affected. The incident has been described as being limited to portions of the hot and warm wallet infrastructure, while Bitget has stated that its cold wallets remained secure.

Withdrawals are currently temporarily suspended, while the company has stated that deposits and trading remain operational.

The most important point is that the Bitget Exchange incident should not be equated with a hack of the self-custodial assets of Bitget Wallet users. Similarly, Bitget’s statements regarding its more-than-$464-million User Protection Fund and the safety of user funds are official claims by the company. The final extent of the loss, asset recovery, and technical root cause will depend on the findings of the ongoing investigation.

Therefore, the basic claim that Bitget experienced unauthorized transfers/security breach involving approximately $351.6 million is officially confirmed. However, turning this into broader claims such as “the entire Bitget system was hacked,” “all user funds were stolen,” “Bitget Wallet was also hacked,” or “the final loss was definitely exactly $351.6 million” is not supported by the currently available official information.