
Bitget Hack: How $388 Million Was Stolen and What Users Should Do
The Bitget hack ranks among the biggest crypto exchange hacks to date: on the evening of September 24, 2026, attackers drained about $388 million from the exchange's wallet infrastructure. Bitget halted withdrawals, brought in Mandiant and SlowMist, and says its user protection fund will cover the loss. Below is what happened, how the attackers got past security, where the money went, when withdrawals resume and what to do if your exchange is hacked.
Key takeaways
- Attackers drained about $388 million from Bitget on September 24, 2026; the first estimate was $351.6 million.
- Bitget says user balances are intact and its protection fund of more than $464 million covers the loss.
- The attackers exploited a flaw in a third-party security product to obtain privileged internal credentials, not private keys.
- Bitget's CEO links the attack to North Korean hackers.
- Withdrawals reopen in phases: BTC on September 28, ETH on September 29, USDT on September 30, everything else on October 2.
Key terms
- Hot wallet is an exchange wallet connected to the internet that holds a small float for day-to-day withdrawals.
- Cold storage is offline storage of private keys, where exchanges keep most customer funds.
- Privileged credentials are internal accounts with the right to approve or send transactions.
- User protection fund is a reserve an exchange sets aside to cover customer losses from incidents such as hacks.
- Proof of reserves is public evidence that an exchange holds enough assets to cover all customer balances.
What happened in the Bitget hack
On-chain analysts spotted suspicious transfers before Bitget made any statement. According to Bubblemaps, 15 large transactions moved about $192 million across seven assets, with ether accounting for 44.4% of the tracked volume. On Arbitrum, roughly 19.67 million USDT0 was swapped for 7,111 ETH in about six minutes, with the attacker paying up to 5% above the market price to move fast.
Bitget triggered its emergency protocol and paused withdrawals for additional security checks. The first loss estimate was $351.6 million. After reconciling transactions on Zcash and TRON, the exchange raised it to $388 million, stressing that these were the same operations rather than new thefts.
How the attackers got past Bitget's security
According to Bitget's investigation, the attackers exploited a vulnerability in a third-party security product and obtained privileged internal credentials. With them, they sent fraudulent withdrawal commands to the wallet system, and the transfers bypassed the exchange's risk controls. CEO Gracy Chen said the attacker first tested those controls with small transfers. Private keys and cold wallets were not compromised, the company says.
In other words, the attack targeted neither the blockchain nor the keys, but the system's trust in its own commands: the forged request looked routine.
Chen links the attack to North Korea. Investigators found IP addresses of VPN services previously used by a North Korean group, and the pattern resembles that group's past operations. Bitget expects to publish an official security report this week.
Where the stolen funds went
Stolen tokens were quickly swapped into ether and routed through decentralised services. Chen asked THORChain to stop serving the attacker's addresses; its developers declined, saying the network's architecture does not allow censorship. NEAR Intents, by contrast, said it blocked $50 million tied to the attack. On-chain investigator ZachXBT identified five intermediaries laundering the proceeds, and part of the stolen funds has already been frozen.
Speed is the point: the longer stolen tokens sit on the attacker's addresses, the higher the chance they get frozen, so they are swapped within minutes even at a loss.
When Bitget withdrawals resume
Bitget is reopening withdrawals in phases (times in UTC):
| Asset | Resumes | Networks |
|---|---|---|
| BTC | September 28 | Bitcoin, BNB Smart Chain |
| ETH | September 29, 08:00 | Ethereum, BNB Smart Chain, Arbitrum, Base, Optimism |
| USDT | September 30, 08:00 | Ethereum, BNB Smart Chain, Solana, Tron |
| Other tokens, fiat, P2P | October 2, 08:00 | all supported |
In the first hours after BTC withdrawals reopened, the exchange processed 9,585 requests for about 4,098 BTC. Queues are long in the first days, so send a small test transfer before moving a large balance. Our guide on how to withdraw crypto from exchange accounts covers networks, fees and common mistakes.
Why hackers target crypto exchanges
An exchange holds the funds of thousands of customers on its own addresses, so one successful attack can yield hundreds of millions of dollars. Funds are usually split in two: a hot wallet with a small float for daily withdrawals, and cold storage for the rest. Attackers go after the hot side and the processes used to refill it and sign transfers.
Two mechanisms protect customers from the fallout. The first is a reserve fund, like the one Bitget is using to cover this loss. The second is proof of reserves, which lets any customer check that their coins are actually on the balance sheet.
The biggest crypto exchange hacks
| Exchange | Year | Loss | Suspected attacker |
|---|---|---|---|
| Bybit | 2025 | about $1.46 billion | North Korea, according to the FBI |
| Coincheck | 2018 | about $530 million in NEM | not identified |
| Bitget | 2026 | $388 million | North Korea, according to Bitget |
| DMM Bitcoin | 2024 | 4,502.9 BTC, over $300 million | North Korean hackers, according to the FBI |
| WazirX | 2024 | about $230 million | Lazarus Group, according to blockchain analysts |
Almost every crypto exchange hack follows the same pattern: attackers go after internal systems - transaction signing, servers, staff access - rather than the blockchain itself. In the Bybit case, for example, the interface used to sign a transfer was tampered with.
What to do if your exchange is hacked
- Follow official channels only. Every major incident is followed by a wave of phishing: fake "support" on messengers offers to "recover funds" or "migrate your balance". We explain these tricks in our guide to crypto phishing scams.
- Keep evidence. Screenshots of your balance and transaction history help if you need to support a claim.
- Review API keys and active sessions. Delete anything you do not use.
- Turn on address whitelisting. Even with stolen access, coins can then go only to pre-approved addresses.
- Do not panic-sell. If the exchange says it covers the loss, selling at a discount only adds to it.
- Keep only trading funds on an exchange. Long-term savings are safer in self-custody.
Was the Bitget hack caused by stolen private keys?
No. According to Bitget, the attackers used privileged internal credentials obtained through a flaw in a third-party security product. Private keys and cold wallets were not compromised.
Will Bitget users get their money back?
Bitget says user balances were not affected and its protection fund covers the loss. Withdrawals reopen in phases through October 2.
Who was behind the Bitget hack?
No one has been officially named. Bitget's CEO points to North Korean hackers, and final conclusions are expected in the exchange's security report.
Is it safe to keep crypto on an exchange?
For active trading it can be, if the exchange publishes proof of reserves and maintains a protection fund. Long-term savings are safer in a wallet whose keys the exchange cannot access.
Crypto markets expert and head of content and marketing at EIDEX. Covers market structure, exchange infrastructure and cross-chain trading - turning on-chain data and market shifts into clear, actionable research for traders.


