Crypto exchange Bitget has confirmed a major security breach affecting approximately $351.6 million in crypto assets, after unauthorized transfers were detected from parts of its hot and warm wallet infrastructure on September 24, 2026.
The attack has already become one of the largest crypto security incidents of the year. According to DeFiLlama data and our tally of major September incidents, including the later-reconstructed D’CENT App Wallet drain, reported gross crypto losses for the month have reached approximately $715 million. That makes September the highest-loss month of 2026 so far on a gross-loss basis.
But the way the Bitget attack happened may be even more important than its size.
According to Bitget CEO Gracy Chen, attackers did not obtain the exchange's private keys. Preliminary findings instead point to a compromise inside Bitget's wallet infrastructure, potentially involving a third-party software tool, which allowed attackers to generate false transfer information and invoke the normal signing process. The exact initial intrusion method is still being investigated.
To understand what happened firsthand, we watched Bitget CEO Gracy Chen’s livestream on X following the incident. Quotes from Gracy Chen in this article are taken from this livestream. The full stream is available here:
What Happened to Bitget?
TL;DR: Bitget detected unauthorized transfers from its hot and warm wallet infrastructure on September 24, 2026. The exchange suspended withdrawals, flagged attacker-linked addresses and began working with law enforcement and security partners, while its cold wallets remained unaffected.
Bitget's security systems detected unauthorized transfers at approximately 18:31 UTC on September 24, 2026.
"At 18:31 UTC on September 24, 2026, Bitget's security systems detected unauthorized transfers from some of our hot and warm wallets," – Gracy Chen, CEO of Bitget.This and the following quotes have been edited for clarity.
Bitget says its security team activated emergency response procedures within minutes, identified and flagged attacker-linked addresses, suspended withdrawals and contacted law enforcement and blockchain security firms.
Speaking during a livestream after the incident, Chen explained that Bitget uses a three-layer wallet architecture: hot, warm and cold.
She said the compromised infrastructure involved the hot layer and part of the warm layer, while the cold-wallet layer, where the majority of platform and user funds are held, remained unaffected.
"Our cold wallets remain fully secure."
The distinction between the wallet layers matters. Hot wallets are connected to operational systems and designed to process transactions quickly. Warm wallets provide an intermediate operational layer, while cold wallets keep the majority of reserves away from internet-connected infrastructure.
The breach therefore did not reach Bitget's deepest storage layer. But attackers were still able to manipulate infrastructure controlling hundreds of millions of dollars in operational assets.
How Did the Bitget Hack Work?
TL;DR: Bitget says its private keys were not stolen. Preliminary findings instead suggest attackers compromised a backend system, manipulated transaction data and used the exchange's normal authorization process to move funds.
The most significant technical finding so far is what apparently did not happen: Bitget says the attackers did not steal its private keys.
Chen said during the livestream that investigators also found no indication that the attackers simply forged user information and submitted ordinary customer withdrawal requests.
Instead, they breached Bitget's systems and initiated transfers through infrastructure operated by the exchange.
Preliminary findings published after the livestream provide a more detailed possible attack path.
According to Chen, attackers compromised a critical backend system within Bitget's wallet infrastructure, used it to spoof transaction data and triggered the exchange's authorization process to move funds out. Bitget says private-key compromise has been ruled out, while the specific method used to breach the backend system remains under investigation.
In a conventional private-key compromise, attackers obtain the cryptographic secret required to control a wallet directly.
In this case, the private keys may have remained secure while another compromised system manipulated what those keys were being asked to sign.
Chen summarized one of the investigation's clearest findings:
"Private key compromise has been ruled out."
Bitget says the immediate vulnerability has been contained and no further unauthorized transfers are currently possible. However, investigators are still determining exactly how the attackers entered the affected system.
What Was Stolen?
Bitget's official estimate puts the affected amount at approximately $351.6 million.
Independent on-chain tracker Lookonchain calculated a slightly higher total of approximately $356.8 million, based on the assets it identified and their market values at the time of analysis.
XRP was therefore the largest individual asset identified so far, accounting for roughly $157.5 million of Lookonchain's estimate.
Bitget has not yet published its own final asset-by-asset accounting, so these figures should be treated as independent on-chain estimates rather than a final official breakdown.
What Is Bitget Doing After the Hack?
Chen said during the livestream that Bitget had mobilized its security, engineering and product teams immediately after detecting the unauthorized transfers and had already stopped further suspicious movement by the time she addressed users.
"We have our full security, technology and product teams activated now. We have identified that there are no more transfers."
The next priority, she said, is tracing the stolen assets and recovering as much as possible. Bitget is working with external security specialists, law enforcement, blockchain organizations and other industry participants, including platforms that may encounter the stolen funds as they move.
Chen said the stolen assets were already being followed in real time:
"The money that was stolen today is being tracked right now. Our internal analytics and security teams, together with external partners and law enforcement, are following the movement of the funds. The money is traceable."
Why Funds Recovering is Difficult
She also explained why recovering funds from sophisticated crypto attackers can become difficult very quickly. According to Chen, stolen assets are often dispersed across a large number of addresses almost immediately and then moved through different services and networks.
"As soon as they steal the money, they distribute it into hundreds and thousands of addresses. They can use mixing, convert into cash or privacy currencies such as XMR, use cross-chain bridges, and then look for ways to off-ramp."
Chen said major centralized exchanges are generally harder places to cash out stolen assets because they enforce KYC and cooperate closely with one another. Smaller platforms with weaker compliance controls can therefore become more attractive to attackers trying to move funds into fiat.
This is also where cooperation across the crypto industry becomes critical. If funds linked to the Bitget hack reach ChangeNOW and are detected by our AML and risk-prevention systems, the transaction will be stopped immediately. We will preserve the relevant information and do everything possible to assist Bitget, investigators and law enforcement with tracing and recovering the assets.
She singled out North Korea-linked groups such as Lazarus as particularly sophisticated in both stages of the operation:
"They are very sophisticated hackers. They are very smart not only in stealing the money, but also in laundering the money. They use different methods and different architectures to move the funds."
Chen added that such laundering operations can continue for extended periods, with stolen assets repeatedly moved across wallets, networks and services.
Are Bitget User Funds Safe?
Bitget says customer account balances remain accurate and that its User Protection Fund, currently valued at more than $464 million, is sufficient to cover the estimated loss.
The company explicitly said:
"The amount is much smaller than our User Protection Fund."
The exchange had also reported a 135% total reserve ratio in its September Proof of Reserves update.
However, the immediate test for users is not the balance displayed in their accounts. It is when withdrawals become available again.
They currently remain suspended.
During the livestream, Chen tried to reassure users whose account balances remained unchanged, while acknowledging that withdrawals would stay paused until the security review was complete.
"If your balance looks fine, don't worry – your funds are safe. Withdrawals are not available right now, but deposits are still open. We are working to resolve this as quickly as possible. It could take a few hours, or at most a few days. It should not take weeks."
She explained that the withdrawal suspension was a temporary security measure rather than an indication that user balances had been lost.
"We need to finish the security review and understand the root cause of the issue before reopening withdrawals. Not allowing withdrawals right now is a temporary solution while we make sure the system is secure."
Bitget has nevertheless avoided giving users a fixed restoration deadline, and the uncertainty has already drawn criticism under the livestream.
One commenter wrote:
"At the very least, you must provide a specific timeframe and take responsibility for completing the investigation within that period."
Another argued:
"If that deadline is exceeded, users should be allowed to withdraw their funds. Users cannot be expected to bear the consequences of an issue they did not cause."
Others were considerably less worried:
"The only people who are freaking out and want to withdraw are the ones with $5 in their account. The whales are chilling."
The comments capture the uncertainty created by the withdrawal suspension, but Bitget's position is understandable: before reopening withdrawals, the exchange wants to make sure the root cause of the incident has been identified and the affected systems are secure.
So far, Bitget has also made a visible effort to communicate openly with users. Chen spent around three hours livestreaming the response, answering questions directly and sharing updates as the investigation progressed. In a fast-moving security incident, that level of communication is valuable, particularly when users are waiting for access to withdrawals to be restored.
What Should Bitget Users Do Now?
TL;DR: Users should rely only on Bitget's official channels, avoid anyone offering early withdrawals or fund recovery, and never share seed phrases or private keys. It is also worth reviewing account sessions, connected devices, 2FA and API access.
For users whose account balances remain correct, Bitget's message is essentially to wait for the security review rather than take action through unofficial channels.
There is currently no evidence that individual users' external wallet private keys were compromised as part of the Bitget breach.
Users should check updates only through Bitget's official website, app and verified social accounts. A major exchange hack creates an obvious opportunity for phishing campaigns built around fake withdrawal reopening notices, “compensation” forms and supposed fund-recovery services.
No legitimate support representative should need a user's seed phrase or private key.
Users should also review their Bitget login history, connected devices, two-factor authentication and API access. Anyone seeing activity they do not recognize should secure the account and contact Bitget through its official support channels. Read our guide on keeping your hot wallet safe.
Most importantly, nobody should transfer crypto to a third party claiming they can bypass the withdrawal suspension or release funds early.
Was North Korea Behind the Bitget Hack?
TL;DR: North Korean involvement is currently one of Bitget's leading theories, but it has not been confirmed.
Bitget says a North Korea-linked group is now one of its leading theories, but the attribution is not confirmed.
During the livestream, Chen said investigators had identified IP data that appeared to correspond with VPN choices previously associated with a DPRK-linked group.
"We've identified some IP addresses that match the VPN choices by a certain DPRK group."
She therefore described North Korean involvement as “very likely,” while acknowledging that Bitget was not yet 100% certain about the attacker.
On-chain analyst Specter has separately reported links between XRP stolen from Bitget and funds associated with the earlier AFX incident, which had been attributed to TraderTraitor, a Lazarus-linked operation.
That evidence adds to the investigation but does not yet constitute definitive attribution of the Bitget attack itself.
Chen also brought up her own previous experience with sophisticated crypto phishing during the livestream.
She said she had personally encountered what she described as a Lazarus-linked operation about a year and a half earlier, when her MetaMask wallet was compromised and she lost around $80,000.
"I have personally faced Lazarus Group before. About a year and a half ago, my MetaMask wallet was hacked and I lost around $80,000. They used social engineering. They pretended to be journalists from a crypto media outlet, compromised the media outlet's official X account and contacted me about an interview. They even communicated with my PR team and assistant, and compromised the journalist's Telegram account as well. We eventually joined a Zoom call, and somehow they still managed to hack me. It was a very sophisticated attack."
Chen said that experience gave her a firsthand view of how elaborate these operations can become. Rather than relying on a single phishing message, the attackers built credibility across several compromised communication channels and involved people around her before the wallet compromise took place.
"Crypto people are one of the biggest target groups because there is a lot of money in this industry. These hackers are extremely sophisticated. They are very smart not only at stealing the money, but also at laundering the money. They use different methods and different architectures to move the funds."
Her personal experience does not prove that the same group attacked Bitget. It does, however, help explain why the exchange is taking the possibility of DPRK involvement seriously.
Some Attacker Addresses Have Been Frozen
Bitget says it has contacted the foundations behind all affected blockchain networks, with some confirming that hacker-linked wallet addresses have already been frozen.
The company has not yet provided a complete public breakdown of the amount frozen or potentially recoverable.
Recovery prospects vary substantially by asset. For now, the final recovery amount remains unknown.
ChangeNOW actively participates in investigations involving stolen and suspicious crypto across a wide range of scenarios, from phishing and compromised wallets to major protocol incidents and law-enforcement investigations. You can find documented examples of how funds were detected, stopped and recovered with investigators and industry partners in our AML Cases section.
This is a developing story and will be updated as Bitget releases its full technical findings, restores withdrawals or reports progress in recovering the stolen assets.
Best Monero Wallets: How to Choose the Right XMR Wallet
Choosing a Monero wallet isn’t just about convenience. In this guide, we break down the best Monero wallets and explain how to pick a secure XMR wallet that fits your needs.