Bitget, one of the largest centralized crypto exchanges, has confirmed a security breach affecting several of its hot wallets. In a security notice posted by CEO Gracy Chen, the exchange said its systems detected unauthorized transfers at 18:31 UTC on September 24, 2026, and that emergency response protocols were triggered immediately.

Bitget Hack - gmcrypto.news source
Bitget Hack

The incident was first surfaced not by the exchange but by on-chain investigators, who flagged unusual outflows from wallets labeled as Bitget's roughly an hour before the company's public statement, a now-familiar pattern in which blockchain analysts detect exchange breaches in real time.

What Bitget confirmed

According to Chen's statement, Bitget has verified the following:

  • Estimated funds affected: approximately $351.6 million.
  • Cold wallets remain fully secure. Bitget said it operates a three-tier wallet architecture, and the breach was contained to a portion of its hot and warm wallet layers.
  • User funds are described as safe. The exchange said the full loss falls within the coverage of its User Protection Fund, which it says currently holds over $464 million.

The exchange said deposits and trading remain fully operational, but withdrawals were temporarily suspended as a precautionary measure pending a security review. Bitget said it has notified law enforcement and on-chain security firms, and pledged an hourly update cadence along with a full incident report — including root cause analysis — within 24 hours. The company said it would not speculate on the attack vector until its investigation concludes.

"Bitget has navigated multiple market cycles. We will not run from this," Chen wrote. "Every dollar and every decision will be accounted for, transparently and in full."

What the on-chain data shows

Independent blockchain investigators began tracking the incident before Bitget's confirmation. Threat researcher @officer_secret and @gm_cryptonews
reported that three hot wallets and one cold wallet appeared to have been affected, and that the impacted wallets still held around $530 million in assets. The researcher also noted that Bitget itself appeared to begin moving funds out of the affected wallets into other addresses, consistent with an effort to secure remaining assets.

The wallets identified in connection with the incident include:

  • 0xffa8DB7B38579e6A2D14f9B347a9acE4d044cD54
  • 0x1AB4973a48dc892Cd9971ECE8e01DcC7688f8F23
  • 0x97b9D2102A9a65A26E1EE82D59e42d1B73B68689
  • 0x5bdf85216ec1e38D6458C870992A69e38e03F7Ef

Blockchain analytics platform Arkham bundled a set of 13 addresses under a community label of "bitget-hacker," showing a consolidated balance of roughly $177 million at the time of writing. The holdings were spread across several assets, led by approximately 59,840 ETH (around $160.8 million), alongside AVAX, BNB, and USDT positions.

Investigators also traced part of the stolen funds being rapidly converted into ETH. In one early transaction, a freshly created wallet swapped roughly 19.67 million USDT0 for about 7,111 ETH on Arbitrum in the span of six minutes, paying as much as 5% over the market rate — a level of slippage that suggests speed was prioritized over price, a common signature of an attacker moving to consolidate stolen assets into a harder-to-freeze form. Funds from the affected Bitget wallets were routed through an aggregator address, 0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee, before moving onward.

A gap between the two figures

One notable point is the discrepancy between Bitget's stated loss of approximately $351.6 million and the roughly $177 million currently visible in the wallet cluster attributed to the attacker by on-chain investigators.

There are several possible explanations for the gap, none of which are yet confirmed: the stolen assets may be spread across more addresses than have been publicly bundled so far; some funds may have already been moved, bridged, or swapped in ways that complicate tracing; or Bitget's internal estimate of "funds affected" may include assets it was able to secure or that remain in transit. Bitget has said it will publish a full accounting, and the true figure may become clearer as its incident report and further on-chain analysis emerge.

Withdrawal status remains a live question

While Bitget said withdrawals were paused as a precaution, some on-chain observers reported continued outflow activity across a range of transaction sizes following the announcement. It is not immediately clear whether this reflects transactions already in flight, a partial or staggered restoration of services, or activity from wallets not covered by the pause. Users should rely on Bitget's official channels for the current, authoritative status of withdrawals.

What happens next

Bitget has committed to hourly updates and a full incident report within 24 hours. The key open questions that report will need to answer include the attack vector (how the hot wallets were compromised), the final confirmed loss figure, and the timeline for restoring withdrawals.

For now, the exchange's position is that the loss is contained to its hot and warm wallet layers, that cold storage is untouched, and that its User Protection Fund is large enough to cover affected users in full. Those claims — particularly the assertion that user funds are fully protected — will be tested in the hours and days ahead as the exchange restores withdrawals and accounts for the missing assets.

This is a developing story. Figures cited from on-chain analytics reflect the state of investigations at the time of writing and may change as funds move or additional addresses are identified. This article is for informational purposes only and does not constitute financial advice.