Bitget Confirms $351.6 Million Hot Wallet Hack, Suspends Withdrawals
Bitget confirmed unauthorized hot-wallet transfers totaling about $351.6 million and suspended withdrawals.
Crypto exchange Bitget confirmed unauthorized transfers from part of its hot and warm wallet infrastructure, with estimated losses of about $351.6 million, detected at 18:31 UTC on September 24, 2026. Cold wallets were not affected. Bitget paused withdrawals while keeping deposits and trading online, notified law enforcement, and said its User Protection Fund of more than $464 million will cover the loss. CEO Gracy Chen promised a full incident report within 24 hours; the intrusion method and asset breakdown were not disclosed.
- Bitget detected unauthorized hot-wallet transfers at 18:31 UTC on September 24.
- Estimated losses are about $351.6 million; cold wallets were not affected.
- Withdrawals are suspended while deposits and trading continue.
- A User Protection Fund above $464 million is said to cover the loss.
- The access vector, assets, and transaction details have not been published.
Full article626 words · extracted from gbhackers.com · click to collapse
Crypto exchange Bitget has confirmed unauthorized transfers from part of its hot wallet infrastructure, resulting in estimated losses of about $351.6 million.
To conduct a security review, the company has temporarily suspended withdrawals; however, deposits and trading will remain operational, according to its official incident notice.
Bitget Hot Wallet Hack
Bitget reported that its security systems detected suspicious transfers at 18:31 UTC on September 24, 2026, which triggered an immediate emergency response.
The exchange has not disclosed the initial access vector, the identity of compromised credentials, details on any smart contract interactions, nor the specific assets involved. Bitget said it will refrain from speculating on the method of intrusion until the investigation is complete.
The incident reportedly impacted only a subset of Bitget’s hot and warm wallet layers. The company emphasized that its cold wallets were not affected.
Bitget described its custody model as a three-tier architecture designed to separate online liquidity from more isolated reserves.
Hot wallets are internet-connected and used for processing routine customer withdrawals and deposits, making them frequent targets for attackers seeking rapid access to exchange-controlled digital assets. Warm wallets generally bridge fully online hot wallets and offline cold storage, providing limited access for operational liquidity.
In response to the incident, Bitget activated an emergency incident-response team within minutes, identified and flagged abnormal destination addresses, and reported those addresses to the relevant parties.
The company has also informed law enforcement and engaged with on-chain security firms. This suggests that investigators are tracing transfers and attempting to identify exchange off-ramps, cross-chain movements, mixer usage, or other laundering activities.
Halting withdrawals is a standard containment measure after a suspected wallet compromise. Temporarily pausing outbound transactions can help prevent further unauthorized transfers, preserve evidence for transaction analysis, and allow security teams to validate wallet-signing systems, privileged-access controls, API activity, address allowlists, and operational procedures.
However, such suspensions can also hinder customers’ ability to move their funds during a period of heightened market uncertainty.
Bitget said customer account balances remain accurate and user assets are secure. Its User Protection Fund, which reportedly holds over $464 million, will cover the full estimated loss.
If this information is accurate, the fund would exceed the announced exposure of $351.6 million by approximately $112.4 million, providing a financial buffer against the incident.
The exchange has not yet released verifiable wallet addresses, transaction hashes, a complete asset breakdown, or a timeline indicating when affected funds were moved.
Chief Executive Officer Gracy Chen reiterated the incident details in a public security notice, confirming that only part of the hot and warm wallet environment was affected and emphasizing that cold wallet holdings remain safe.
Chen stated that Bitget would provide hourly updates through official channels and publish a full incident report within 24 hours, including a root-cause analysis and corrective actions.
— Gracy Chen @Bitget (@GracyBitget) September 24, 2026[SECURITY NOTICE] Bitget Hot Wallet Incident — September 24, 2026
At 18:31 UTC on September 24, 2026, Bitget's security systems detected unauthorized transfers from some of our hot wallets. Our security team activated emergency response protocols immediately.
What we have…
For customers, the immediate operational status is clear: trading and deposits continue while withdrawals are paused pending the completion of the security review. Users are advised to rely only on Bitget’s verified website and official social media accounts for updates.
They should remain vigilant against phishing pages or fake compensation claims exploiting the incident and avoid sharing account credentials, recovery codes, API keys, or wallet details with unsolicited contacts.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.