Bitget Hack: $351.6 Million Affected in Hot Wallet Exploit

By bonuz NewsroomPublished September 25, 2026
Bitget Hack: $351.6 Million Affected in Hot Wallet Exploit

Bitget, a major crypto exchange, confirmed a hack that drained about $351.6 million (USD) from its hot wallets on 24 September 2026. Anyone holding funds on centralized exchanges should care, because it shows how fast hot wallet breaches can happen and how exchanges respond under pressure.

What actually happened

Bitget CEO Gracy Chen said the exchange's security system flagged abnormal outflows from some hot wallets at 18:31 UTC on 24 September 2026. Preliminary internal accounting put affected funds at about $351.6 million (USD), according to Wu Blockchain. Cold wallets remained secure, and user account balances were not altered. Bitget said a user protection fund of more than $464 million (USD) can cover losses. Withdrawals were paused; deposits and trading stayed open. On-chain analysts tracked a separate, smaller tally: Arkham Intelligence estimated about $178 million to $183 million, and Bubblemaps put cross-chain transfers near $190 million, both citing a newly created address later tagged Bitget Exploiter 1. Bitget pledged a full incident report before 21:30 UTC on 25 September 2026.

How we got here

The hack echoes February 2025, when Bybit's Ethereum cold wallet was drained of about 400,000 ETH, worth roughly $1.4 to $1.5 billion (USD) at the time, the largest exchange theft on record. Investigators later linked that breach to a manipulated Safe multisig interface and attributed it to a Lazarus-related cluster. Bitget was one of the first exchanges to help then, lending Bybit 40,000 ETH, worth about $105 to $106 million (USD), interest-free and unsecured. Bybit repaid it within about three days. Centralized-exchange hacks commonly trace to compromised hot-wallet keys, as seen in Coincheck 2018, KuCoin 2020, and Bitmart 2021, or to multisig and signing-interface bypasses like Bybit's.

Why this matters for you

For Bitget users, the protection fund and intact cold wallets mean balances should stay whole, though the withdrawal pause limits access to funds for now. For traders across exchanges, the incident is a reminder that hot wallets, kept online for daily operations, carry more risk than cold storage. Builders and wallet vendors face fresh pressure to audit signing interfaces and hot-wallet key management, since past incidents point to both stolen keys and manipulated interfaces as root causes. Exchanges that respond fast and communicate openly, as Bitget and Bybit did in 2025, may retain more user trust than those that stay silent.

The bigger question

If exchanges keep absorbing losses through insurance funds and peer-to-peer loans, does that build genuine resilience across the industry, or does it just delay a reckoning over how much of crypto custody still depends on centralized hot wallets, where a single compromised key or manipulated interface can drain hundreds of millions of dollars within minutes, and who ultimately pays when it happens again?

What to watch

Bitget pledged hourly updates and a full incident report, including root-cause analysis, before 21:30 UTC on 25 September 2026. That report should reveal whether the breach involved leaked private keys or an interface exploit. Watch for reconciliation between the $351.6 million (USD) internal figure and the roughly $180 to $190 million (USD) on-chain tally. Law enforcement is already involved.

Keep reading