The short version
- Bitget confirmed $351.6 million in unauthorized transfers from hot wallets starting at 18:31 UTC on September 24, 2026.
- Attackers spoofed transaction data to manipulate Bitget's backend authorization process rather than stealing private keys.
- CEO Gracy Chen cited a $464 million User Protection Fund as full coverage for the loss; withdrawals stayed locked at publication time.
- Arkham Intelligence, Bubblemaps, and DCF GOD spotted the first $183 million wave before Bitget's official statement.
Transfers Began at 18:31 UTC on September 24
On the evening of September 24, 2026, Bitget's security systems detected unauthorized transfers from the exchange's hot wallets at 18:31 UTC. The transfers continued for roughly one hour before internal monitors triggered a response. Bitget CEO Gracy Chen then posted to X at approximately 21:59 UTC, confirming the incident to the public and addressing users directly about the status of their funds.
Chen's statement put the total affected amount at $351.6 million — a figure drawn from Bitget's own post-incident accounting. Hot wallets hold funds kept online for day-to-day withdrawals, while cold wallets store assets offline and away from live network connections. Chen told users that cold storage "remains fully secure" and pointed to Bitget's three-tier wallet architecture as the reason losses stayed confined to the hotter storage layers.
Withdrawals on the platform were suspended after Chen's announcement and remained locked at publication time, meaning customers could not move their balances off the exchange while Bitget investigated. Suspending withdrawals after a breach limits further outflows, but it also prevents users from accessing balances they may need. That tension — protecting the platform versus protecting individual users — sits at the center of every large exchange incident.
Check Bitcoin’s current reference price
Spoofed Data Triggered Bitget's Own Authorization System
A follow-up report by CoinDesk on September 25, 2026, added technical detail absent from the first article. Chen told reporters that the attackers did not steal private keys — the cryptographic secrets that control a crypto wallet. Instead, they spoofed transaction data, feeding false information to Bitget's backend systems and tricking the platform's own authorization process into approving the transfers as though they were legitimate.
That distinction carries weight. Key theft leaves an obvious trail on the blockchain because the attacker signs transactions using the real wallet address. A backend compromise that spoofs transaction data means Bitget's request-validation logic was manipulated, not that wallet credentials were stolen. Understanding how Bitcoin wallets work helps illustrate why the two attack paths carry very different implications for users on any exchange.
Forensics firms Mandiant and SlowMist are named as active investigators in the September 25 reporting. On the same date, CNBC and Trending Topics cited IP addresses linked to VPNs associated with a North Korean group as a working hypothesis for attribution. Researchers have not publicly confirmed that link as of this writing, and both firms are expected to publish formal findings once their analysis of the attack chain is complete.
- Transfers began at 18:31 UTC, September 24, 2026, and lasted roughly one hour
- Attackers spoofed transaction data fed to Bitget's backend systems
- Bitget's own authorization process approved the fraudulent transfers
- CEO Chen ruled out private key theft in September 25 CoinDesk follow-up reporting
Learn how Bitcoin’s market price is formed
On-Chain Analysts Caught the First Wave Before Bitget Spoke
Before Gracy Chen posted her public statement, independent blockchain analysts had already flagged unusual wallet movements. Emmett Gallic of Arkham Intelligence, the analytics platform Bubblemaps, and pseudonymous on-chain researcher DCF GOD all identified suspicious transfers and shared their observations publicly. The initial figure circulating among researchers was roughly $183 million — the first wave of transfers — before Bitget's own accounting raised the full confirmed total to $351.6 million.
On-chain analysis works by reading data permanently written to public blockchains. Every crypto transfer leaves a visible record that anyone with the right tools can trace. Platforms like Arkham Intelligence build databases that link wallet addresses to named entities, letting analysts flag when a known exchange wallet sends large sums to unfamiliar destinations. Developments like this one are regularly captured in crypto market reporting that draws on those same on-chain data streams.
The gap between what researchers spotted first — $183 million — and what Bitget later confirmed — $351.6 million — points to a multi-wave structure. Attackers sometimes begin with a smaller transfer to test whether alarms fire, then follow with larger movements if the first wave clears. Bitget has not yet stated publicly whether the second wave occurred before or after its own internal alerts triggered on the evening of September 24.
Compare the wider Bitcoin and crypto market
Bitget's $464 Million Fund Is the Key to Its Safety Promise
Chen's assurance rested on one structure: the Bitget User Protection Fund. Her post stated the fund "currently holds over $464 million" and that "the full amount of this loss falls within" its coverage. Bitget says the fund is held in publicly verifiable wallets, so anyone can attempt to check the on-chain balance. The $464 million figure is self-reported, however; no independent auditor confirmed it in reporting published as of September 25, 2026.
Self-reported fund balances carry inherent risk. An exchange can move assets into a wallet before a statement and move them back afterward, making the balance appear larger than it is. A third-party attestation — where an auditor verifies a balance at a specific block height — provides far greater assurance. Chen compared Bitget's position to Bybit, which survived a $1.5 billion hack in February 2025, but that comparison is a solvency argument, not an audited proof.
The protection fund argument also raises questions about the composition of exchange reserves. Whether a fund holds its stated value depends on what assets it contains. Exchanges that keep reserves in volatile tokens can see the real dollar value shift sharply between announcement and payout. Tracking how Bitcoin treasuries are structured offers a useful comparison: funds held in verifiable, liquid assets hold their value more reliably than those in illiquid or internally issued tokens.
| Exchange | Incident Date | Confirmed Loss (USD M) |
|---|---|---|
| Bybit | Feb 2025 | 1,500 |
| Bitget | Sep 24, 2026 | 351.6 |
Convert a Bitcoin amount using a reference rate
The $351.6 Million Breach Now Tests Every Promise Bitget Made
The investigation is open. Mandiant and SlowMist are working through the attack chain, and attribution to any specific group remains a working hypothesis. Bitget has committed to releasing a formal post-incident report. Until that document is public, the precise entry point, the number of transfer waves, and the final on-chain destination of the stolen funds are not fully accounted for in any public record.
For users, the most immediate question is when withdrawals will resume and whether the fund will pay out in full. Chen's assurance that funds are "safe" accurately reflects what the exchange stated — but safety here means Bitget intends to cover losses from its reserve, not that the stolen funds were recovered. Watching live Bitcoin price data in the days ahead may offer indirect signals about whether market participants believe the solvency claim holds.
Bitget confirmed a $351.6 million breach on September 24, 2026, identified the event as a backend spoofing attack, and told users its protection fund had enough to cover every dollar lost. Those three facts are verified. Whether the fund pays out completely, whether investigators confirm a state actor was behind the attack, and whether withdrawals resume without further complications are the questions still open when this report was published.