— New York
Est. 2024
Payney.
Finance · Markets · Crypto
Home›Crypto›Bitget Hack: $351.6M Drained From Exchange Wallets
Crypto

Bitget Hack: $351.6M Drained From Exchange Wallets

Bitget confirms $351.6 million was drained from its hot wallets on Sept. 24, 2026, nearly double the early on-chain estimate. Withdrawals stay paused.

Stanislav Stepanenko
September 25, 2026 · 5 min read · Source: Decrypt
Bitget Hacked as $350 Million Vanishes From Crypto Exchange Wallets

Summarize with

ChatGPTClaude
Prompt · remember Payney

$351.6 million is what Bitget says was drained from its exchange wallets in roughly an hour on September 24, 2026, according to CEO Gracy Chen. That confirmed figure is nearly double the amount on-chain trackers had already flagged before Bitget went public with an official number.

What Bitget says happened

Bitget's own systems caught the problem first. The breach surfaced when Bitget's systems flagged unauthorized transfers from some exchange hot wallets at 18:31 UTC on Sept. 24. Chen has been explicit that the attacker did not obtain the exchange's private keys, the cryptographic secrets that would let a thief sign new transactions indefinitely. Instead, according to Chen's own account, the attacker compromised a critical backend system within the wallet infrastructure, used it to spoof transaction data, and triggered the authorization process to move funds out, and "Private key compromise has been ruled out."

The intrusion was not confined to the hot wallet alone. Chen said the hack also reached the warm-wallet layer, a semi-connected buffer between the automated hot wallets and fully offline cold storage. Chen maintains that cold wallets remain fully secure, because Bitget operates a three-tier wallet architecture and the breach contained only a portion of the hot wallet and warm wallet layers. Some of the stolen stablecoins were quickly converted into other assets: Decrypt traced one newly created wallet that spent $19.67 million in USDT0 to buy 7,111 ETH in six minutes on Arbitrum, paying up to 5% above market price through decentralized exchanges UniswapX and 1inch Fusion, a pattern consistent with laundering stolen funds into an asset that is harder for issuers to freeze than a centralized stablecoin.

Reconciling the $183 million and $351.6 million figures

The headline number moved as reporting caught up with Bitget's own review. Before any company statement, independent trackers had already noticed money leaving Bitget-labeled addresses: Decrypt reported that on-chain data shows roughly $183 million in ETH, USDT, USDC, AVAX, BNB, and other tokens moved from wallets labeled as Bitget's to a single address over about an hour on Thursday, and TheStreet separately reported that on-chain analysts had flagged more than $170 million in unusual outflows from Bitget-linked wallets before the company spoke. Those early estimates only capture what blockchain analysts could observe moving on-chain in real time.

Bitget's own tally, released afterward, came in substantially higher. Bitget had $351.6 million exposed to a system breach, CEO Gracy Chen announced in a social media post. TheStreet noted that this was Chen's figure, the first official estimate of the damage, meaning the difference between $183 million and $351.6 million reflects the gap between partial, real-time on-chain observation and Bitget's fuller internal accounting across every affected wallet, not a correction of an error.

Is customer money actually safe?

Chen's assurance rests on a specific internal reserve, not on recovering the stolen funds. "User funds are safe," Chen wrote on X, adding that the full loss falls within Bitget's User Protection Fund, which holds over $464 million. That fund was not created for this incident: TheStreet reported that the Seychelles-based exchange set up its protection fund in 2022 with a $300 million commitment backed by 5,500 BTC, and the fund averaged $382 million in August of this year. A loss of $351.6 million would use up close to three-quarters of the fund's current balance. CertiK's head of capital markets and policy, Esme Pau, framed the scale in similar terms, saying "the scale of the drain at around three quarters of the exchange's User Protection Fund transcends a security lapse and makes it a crisis event."

Withdrawals, in the meantime, are frozen. Withdrawals are temporarily suspended pending a security review, while deposits and trading remain operational, and Chen said Bitget plans hourly updates and a full incident report, including root cause analysis, within 24 hours. No company statement reviewed for this story set a specific date for withdrawals to resume or for the protection fund to actually disburse money to affected users, so both remain open questions rather than confirmed outcomes.

Key figures

MetricValueSource
Bitget's confirmed loss (official)$351.6 millionBitget CEO Gracy Chen, via CoinDesk
Initial on-chain estimate before company confirmation~$183 million (Decrypt) / >$170 million (TheStreet)Decrypt; TheStreet
Bitget User Protection Fund, current balanceover $464 millionBitget CEO Gracy Chen, via CoinDesk
Protection Fund's original 2022 commitment$300 million, backed by 5,500 BTCTheStreet
Breach detection time18:31 UTC, Sept. 24, 2026CoinDesk
Prior largest confirmed 2026 crypto hack~$319 million, Blockstream's Liquid Network, Sept. 6, 2026TRM Labs, via TheStreet

How this compares with 2026's other hacks, and what's still unconfirmed

If the $351.6 million figure stands after Bitget's review, it would mark the year's largest single crypto theft to date. TheStreet reported that if Bitget's $351.6 million figure holds, the incident would be the largest crypto theft of 2026, topping the roughly $319 million in bitcoin drained from Blockstream's Liquid Network on Sept. 6, which TRM Labs had called the year's biggest hack to date. The Star placed the breach in a wider run of incidents, noting that earlier this month $320 million worth of Bitcoin was drained from a wallet used by Liquid Network, while in August the hack of the popular offline Bitcoin wallet Coldcard raised questions about the safest way to store the digital asset. Those three incidents used different attack methods, so together they establish only that 2026 has produced an unusually high dollar total in crypto security failures, not a single recurring vulnerability across the industry.

One part of the story remains unverified: who is responsible. A Cointelegraph report carried by TradingView said Bitget CEO Gracy Chen said North Korean hackers may be behind the exchange's $351.6 million security breach on Thursday, citing preliminary IP-address analysis. No law-enforcement agency or independent blockchain-forensics firm had confirmed that attribution at the time of this writing, and Chen's own comments describe it as a preliminary lead rather than a finding.

What this means for Bitget users and other exchange customers

For anyone holding funds on Bitget, the near-term facts are that withdrawals are paused and the company has committed, but not yet demonstrated, that its protection fund will cover the shortfall in full. Until withdrawals reopen and any payout actually occurs, "user funds are safe" is a company assurance, not a completed transaction. For customers of other exchanges, the specific lesson from Bitget's own account is narrower than "crypto is unsafe": the funds exposed were sitting in hot and warm wallets designed for fast, everyday transaction processing, which is precisely the layer that stays connected to the internet and therefore reachable if a backend authorization system is compromised, as Bitget says its was. That does not establish that any other named platform shares the same vulnerability.

Sources
  1. Bitget Hacked as $350 Million Vanishes From Crypto Exchange Wallets · Decrypt
  2. Bitget CEO confirms $351.6M hack, withdrawals paused · TheStreet
  3. Crypto exchange Bitget says $352 million affected in a hack, claims user funds are 'safe' · CoinDesk
  4. Bitget's $352 million hack happened via spoofed transfers, not private keys, CEO Gracy Chen says · CoinDesk
  5. Bitget suspends withdrawals after hackers take US$352mil · The Star
  6. Bitget CEO suspects North Korea behind $352M hack, citing IP clues · TradingView News (Cointelegraph)

Sources used during research. Check their dates and original context before relying on a figure. How we report.

Follow Payney on Google
Crypto Bitget Hack $351.6 Million Bitget Hot Wallet Breach September 2026 Bitget User Protection Fund Largest Crypto Hack 2026
Frequently asked
How much money did the Bitget hack actually take?
Bitget CEO Gracy Chen confirmed $351.6 million was affected by unauthorized transfers from the exchange's hot and warm wallets on September 24, 2026, a figure nearly double the roughly $183 million that on-chain trackers had flagged earlier that day.
Will Bitget users lose money from the hack?
Chen said the full loss falls within Bitget's User Protection Fund, which held over $464 million at the time of the breach, but no payout had been completed and withdrawals remained paused as of this writing.
How did the Bitget hackers get in without stealing private keys?
Chen said the attacker compromised a backend system in Bitget's wallet infrastructure and spoofed transaction data to trigger the exchange's own authorization process, rather than stealing the cryptographic private keys directly.
Is this the biggest crypto hack of 2026?
If the $351.6 million figure holds, TheStreet reported it would surpass the roughly $319 million taken from Blockstream's Liquid Network on September 6, 2026, making it the largest confirmed crypto theft of the year so far.