- Bitget said attackers moved roughly $351.6 million out of its hot and warm wallets on September 24, 2026, in what could rank as the largest crypto theft of the year.
- CEO Gracy Chen said the breach came from a compromised backend system rather than stolen private keys, and pointed to a group linked to North Korea as the likely culprit.
- Withdrawals are suspended while deposits and trading continue, and Bitget said its User Protection Fund of more than $464 million covers the full loss.
Crypto exchange Bitget lost about $351.6 million in a hack on Thursday, September 24, after attackers drained parts of its hot and warm wallets, the company said, in what could rank as the largest crypto theft of 2026. The Bitget hack surfaced first through onchain trackers, then through a statement from the exchange itself.
Bitget’s security systems flagged the unauthorized transfers at 18:31 UTC, CEO Gracy Chen wrote on X. The Seychelles-based exchange, which ranks among the six largest by volume, halted withdrawals within the hour while keeping deposits and trading open. The loss now sits above the roughly $319 million drained from Blockstream’s Liquid Network on September 6, which analysts had called the year’s biggest to that point.
“At 18:31 UTC on September 24, 2026, Bitget’s security systems detected unauthorized transfers from some of our hot wallets,” Chen wrote. “Our security team activated emergency response protocols immediately.”
Chen said the attack did not involve stolen keys. “The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out,” she wrote. Bitget runs a wallet setup split across three tiers, and Chen said the breach reached only portions of the hot and warm layers, which sit between the automated hot wallets and offline cold storage. The cold wallets, she said, remain fully secure.
Onchain analysts tracked the money as it left. Emmett Gallic, an analyst at Arkham Intelligence, said the transfers touched three Bitget hot wallets and one cold wallet across several blockchains before the funds consolidated into a single address, with assets including ether, BNB, AVAX, and USDT0. Two figures have circulated since: Bitget’s internal tally of $351.6 million, and a smaller onchain count of roughly $180 million tied to publicly labeled addresses, as the attacker converted a large share of the proceeds into ether.
Chen attributed the intrusion to North Korea. In a September 24 post, industry outlet WuBlockchain reported that Bitget’s team had identified IP addresses whose VPN usage patterns matched those of a specific group linked to the Democratic People’s Republic of Korea, making the connection “very likely.” Chen ruled out an inside job and said the attribution was not yet fully confirmed. Bitget promised a full incident report, including a root cause analysis, within 24 hours.
The suspicion carries weight because of precedent. The U.S. Federal Bureau of Investigation attributed the record $1.5 billion Bybit theft in February 2025 to North Korea’s TraderTraitor cluster, part of the Lazarus Group, after attackers compromised a developer at the multisig provider Safe and injected malicious code into its interface. Bitget had helped Bybit recover from that breach, lending 40,000 ether at the time.
Bitget said user balances are intact and that its User Protection Fund, which holds more than $464 million, covers the entire loss. The company set up the fund in 2022 with a $300 million commitment. Its token, BGB, fell on the news before recovering part of the drop.
The theft caps a punishing quarter for crypto security. On September 6, roughly 4,000 bitcoin worth about $319 million left Liquid Network’s federation wallet, draining close to 95% of the bitcoin it held; the attackers called themselves white-hat hackers and later returned most of the coins. In August, Tectonic, the largest lending protocol on the Cronos chain, lost about $74 million to a price manipulation exploit that forced Cronos to halt and roll back its chain. And starting July 30, attackers exploited a 2021 firmware flaw in Coinkite’s Coldcard hardware wallets to drain more than $116 million in bitcoin from thousands of addresses. Bitget’s loss, if the $351.6 million figure holds, tops them all.
Editorial Note: Reported and edited by the Crypto India Magazine editorial team. We use AI tools to assist with research and drafting; every article is reviewed and fact-checked by our editors.
Interested in advertising with CIM? Talk to us!