Excerpt
- Bitget says approximately $351.6 million was affected in a September 24 security incident after an attacker compromised a critical backend wallet system.
- The exchange says private keys were not compromised, user balances remain intact, and withdrawals remain suspended while Mandiant and SlowMist investigate.
Bitget says approximately $351.6 million was affected in a September 24 security incident after an attacker compromised a critical backend system within its wallet infrastructure. Withdrawals remain suspended as the exchange works with Mandiant, SlowMist and law enforcement to investigate the breach.
The incident was detected at 18:31 UTC on September 24, according to Bitget CEO Gracy Chen. The exchange says the attacker used the compromised backend system to spoof transaction information and trigger its authorization-signing process, allowing funds to be transferred out without compromising the underlying private keys.
[SECURITY NOTICE] Bitget Hot Wallet Incident — September 24, 2026
At 18:31 UTC on September 24, 2026, Bitget's security systems detected unauthorized transfers from some of our hot wallets. Our security team activated emergency response protocols immediately.
What we have…
— Gracy Chen @Bitget (@GracyBitget) September 24, 2026
What Happened
Bitget initially described the incident as unauthorized transfers from a portion of its hot-wallet infrastructure. The company later said the affected assets included ETH, XRP, BNB, AVAX, USDT, USDC and other tokens across Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC and Base.
Bitget says its cold wallets remain secure and unaffected and that the incident has been contained, with no further unauthorized outflows possible. The exchange also said its separate self-custodial Bitget Wallet operates on independent infrastructure and was not affected.
The attack’s reported mechanism is significant because Bitget says the attacker did not obtain private keys. Instead, the compromised backend system allegedly manipulated transaction information before invoking the exchange’s existing authorization process.
What Bitget Says
Bitget says user balances remain intact and that the approximately $351.6 million loss is fully covered by its User Protection Fund, which the company says holds more than $464 million.
The exchange has temporarily suspended withdrawals while deposits and trading continue operating. Bitget has not committed to a specific withdrawal-restoration deadline, saying it will announce a timeline once technical teams confirm that systems are safe to reopen.
Bitget has also said some blockchain foundations have frozen addresses associated with the attacker as the company pursues recovery efforts.
The exchange’s preliminary analysis has linked the attack to techniques it says are highly consistent with North Korean hacker organisations, based on IP behaviour and on-chain analysis. That remains a preliminary attribution from Bitget rather than a final independently established conclusion. Other reporting has noted similar preliminary indicators.
Earlier 7 hours ago, I hosted a live stream with everyone that lasted over three hours. Here’s a summary of the points I covered in the live:
① Bitget security incident update — 1 hours in. We’re sharing specific facts, not just reassurances.
② Affected assets include ETH,… https://t.co/kkVr4YbKZq
— Gracy Chen @Bitget (@GracyBitget) September 25, 2026
What Happens Next
Bitget says multiple technical teams are working on remediation and security hardening while preparations for restoring withdrawals continue.
The company has engaged Mandiant and SlowMist to conduct a comprehensive investigation into the incident. Bitget says the specific method used to gain initial access to the backend system remains under investigation and that a full technical report will follow once the findings are confirmed.
The exchange has also notified law enforcement and on-chain security firms.
Separately, Bybit CEO Ben Zhou said Bybit is standing by to assist Bitget, noting that Bitget previously helped Bybit following its own hack. Zhou said Bybit is also updating LazarusBounty.com to assist with tracing the movement of the stolen funds.
Bybit team is standby to help in any ways that we can. Bitget helped us when we had the hack.
we are updating https://t.co/qbieK9k1lK to help Bitget to capture and trace the stolen fund movement. https://t.co/5hkfhUCaLt— Ben Zhou (@benbybit) September 25, 2026
For Bitget users, the immediate issue remains withdrawal access. The exchange says it will restore withdrawals as soon as its security review confirms that doing so is safe.
