Bitget Hot Wallet Hacked – Attackers Stole $351.6 Million From Hot Wallets
Bitget confirmed a $351.6 million theft from hot and warm wallets while cold storage stayed secure.
Cryptocurrency exchange Bitget confirmed unauthorized transfers of about $351.6 million from parts of its hot and warm wallets, detected at 18:31 UTC on September 24, 2026. Offline cold wallets were unaffected, customer balances still reflect holdings, and withdrawals were paused while deposits and trading continued. On-chain observers tracked ETH, BNB, AVAX, USDT, and USDC; CEO Gracy Chen said the User Protection Fund, valued above $464 million, covers the loss. Preliminary evidence resembles earlier North Korean activity, including Lazarus Group, but attribution is unconfirmed; investigators suspect a backend or third-party compromise that forged transfers without stealing private keys.
- About $351.6 million was stolen from Bitget hot and warm wallets on September 24, 2026.
- Cold wallets stayed secure; balances remain accurate; withdrawals were suspended.
- A User Protection Fund above $464 million is said to cover the loss.
- North Korean and Lazarus-like patterns were cited, but attribution is unconfirmed.
- Attackers moved funds after system access without obtaining private keys.
Full article570 words · extracted from cybersecuritynews.com · click to collapse
Cryptocurrency exchange Bitget has confirmed a security breach affecting approximately $351.6 million in assets after unauthorized transfers were detected in parts of its hot and warm wallet infrastructure.
The incident was identified at 18:31 UTC on September 24, 2026, prompting the security team to activate emergency response procedures within minutes. Bitget said its offline cold wallets remained secure and that customers’ account balances continue to reflect their holdings accurately.
The compromise was contained within portions of Bitget’s three-tier wallet architecture, according to an official security notice. Although the exchange has not yet published a complete inventory of stolen assets, on-chain observers tracked movements involving ETH, BNB, AVAX, USDT, and USDC.
Early estimates placed suspicious transfers between $174 million and $183 million before Bitget established the $351.6 million exposure.
Bitget temporarily suspended withdrawals while investigators review its wallet systems and determine whether any infrastructure is at risk. Deposits and trading remain available. The exchange said it identified and flagged recipient addresses, informed law-enforcement agencies and engaged blockchain-security companies to trace the funds.
Bitget Hot Wallet Hacked
Chief executive Gracy Chen said the loss is covered by Bitget’s User Protection Fund, which the company values at more than $464 million. That assurance leaves a buffer of roughly $112.4 million above the estimated loss, but users will watch how the fund is deployed and whether withdrawals resume without reducing the balance.
The incident demonstrates why protection reserves must be verifiable, liquid, and accessible during a large exchange compromise.
— Gracy Chen @Bitget (@GracyBitget) September 24, 2026[SECURITY NOTICE] Bitget Hot Wallet Incident — September 24, 2026
At 18:31 UTC on September 24, 2026, Bitget's security systems detected unauthorized transfers from some of our hot wallets. Our security team activated emergency response protocols immediately.
What we have…
During a live question-and-answer session, Chen said preliminary evidence included IP addresses resembling VPN infrastructure previously associated with a North Korean threat group. She also said the activity followed patterns seen in earlier North Korean operations, raising suspicion around the Lazarus Group.
However, attribution remains unconfirmed, and Bitget has said it will not formally speculate until its investigation is complete. North Korean actors were blamed for the approximately $1.5 billion Bybit theft in 2025, making any tactical overlap significant but not conclusive.
Chen further indicated that the attackers transferred assets directly after gaining access to Bitget systems, rather than submitting fraudulent customer withdrawal requests. Preliminary findings reportedly suggest the intruders did not obtain private keys and may have compromised a critical backend component supporting wallet services.
Investigators are examining whether a third-party tool or supply-chain attack enabled forged transfer instructions to reach authorized signing infrastructure.
Bitget has promised hourly updates through official channels and a full incident report within 24 hours, covering the root cause, affected systems, and corrective actions. Until that report appears, the precise initial-access vector, persistence mechanism, and control failures remain unknown.
Customers should rely only on verified Bitget communications, remain alert to phishing messages exploiting the withdrawal pause and avoid sharing credentials or signing unsolicited wallet requests.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.