theTLDR
- Bitget confirmed a $351.6 million hack affecting parts of its hot and warm wallet infrastructure.
- CEO Gracy Chen said attackers spoofed transaction data after compromising a backend wallet system.
- Bitget said it did not steal private keys, and its cold wallets remained secure.
- The exchange paused withdrawals during its security review, while deposits and trading remained open.
- Bitget said its $464 million User Protection Fund is enough to cover the estimated loss.
The Bitget hack drained $351.6 million from parts of the exchange’s hot and warm wallet system overnight. CEO Gracy Chen said attackers compromised a backend wallet system, spoofed transaction data, and triggered the exchange’s normal approval process. She said investigators ruled out private key theft.
Bitget detected unauthorized transfers at 18:31 UTC on September 24 and activated emergency controls. Chen said the team stopped outflows and secured the affected systems. Cold wallets remained secure, while deposits and trading continued during the review. Hot wallets keep funds online for fast transfers, while warm wallets act as a buffer between online systems and offline storage.
Here is what we can confirm at this stage:
On the attack:
Our security team has made initial progress in tracing the source. The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization… https://t.co/5nINjwbXpC— Gracy Chen @Bitget (@GracyBitget) September 25, 2026
Exchange Says Protection Fund Covers Loss
Bitget said its User Protection Fund holds more than $464 million, enough to cover the estimated loss. The exchange said customer balances remain accurate and the fund protects customer assets. The incident follows a North Korea-linked fake job scam that compromised thousands of crypto wallets this week.
Bitget suspended withdrawals while technical teams review the breach and strengthen wallet controls. Bitget has not provided a reopening time. Chen said the exchange will publish a timeline only after teams confirm that withdrawals can resume safely. The review covers both wallet layers.
Attack Did Not Expose Private Keys
Chen said attackers manipulated transaction information rather than stealing the private keys that authorize wallet transfers. That means the breach targeted Bitget’s internal transaction process instead of gaining direct control over wallet credentials.
The case comes days after scammers hijacked Cardano’s official YouTube channel and used a fake livestream to target users. The exchange said its investigators are still examining how attackers accessed the backend system and bypassed normal safeguards.
Bitget Investigates Breach and Halts Withdrawals
Bitget has identified and flagged addresses linked to the unauthorized transfers. The exchange also contacted law enforcement and blockchain security firms. Separately, a Coinbase phishing scheme led to a prison sentence this week after the scheme stole nearly $16 million from users.
Chen said technical teams are working on system repairs and security checks. Bitget plans to release a full technical report after confirming the cause, attack path, and security changes. Until then, withdrawals will remain unavailable while deposits and trading stay open.







