BitGet Confirms $351.6 Million Stolen in Biggest Crypto Hack of 2026 So Far
Key Takeaways
- •Bitget disclosed that approximately $351.6 million in digital assets was stolen from its hot wallets, making it the largest cryptocurrency hack of 2026 so far.
- •CEO Gracy Chen stated the breach was confined to hot and warm wallet infrastructure, with the company's cold wallets and customer account balances unaffected.
- •The attackers compromised a critical backend system, spoofed transaction data, and misused the exchange's own authorization process to move funds rather than stealing private keys.
- •Bitget's User Protection Fund, which holds more than $464 million, is sufficient to cover the full reported loss, according to the CEO.
- •Withdrawals remain suspended until the security review concludes, and Bitget has flagged the involved addresses while notifying law enforcement and blockchain security firms.

Cryptocurrency exchange BitGet said approximately $351.6 million in digital assets was stolen in a security breach that ranks as the biggest hack of 2026 so far, while stressing that its cold wallets and customer funds remained secure.
The exchange said it detected unauthorized transfers from some of its hot wallets and suspended withdrawals as a precaution while it investigates the incident. Deposits and trading remained operational. Withdrawal suspensions are a common contingency measure during exchange security investigations, intended to prevent further outflows while forensic work is underway.
Bitget CEO Gracy Chen said the breach was confined to portions of the exchange's hot and warm wallet infrastructure and that the company's cold wallets were not affected. Hot wallets are internet-connected accounts used to process day-to-day deposits and withdrawals, while warm wallets act as an intermediate layer between them and offline cold storage.
The exchange's User Protection Fund, which holds more than $464 million, covers the full amount of the reported loss, Chen said. "User funds are safe," she said, adding that customer account balances remained accurate and that assets were protected. Protection funds of this kind are maintained by some exchanges as a designated backstop for user losses, and their size relative to a given incident is a key measure of whether affected users are made whole.
The exchange later said the incident did not involve a compromise of private keys. Instead, according to Chen, attackers compromised a critical backend system within Bitget's wallet infrastructure, spoofed transaction data, and triggered the exchange's own authorization process to move funds. That vector matters because it bypasses the cold-storage perimeter entirely: rather than stealing the keys guarding offline reserves, the attackers co-opted the systems that authorize movements from operational wallets — the same layer through which routine user withdrawals flow.
Bitget said its security team activated emergency response procedures within minutes of detecting the unauthorized transfers. The company has identified and flagged the addresses involved in the transactions and notified law enforcement and blockchain security firms. Address flagging is a standard early step in cases like this, enabling exchanges, analytics providers and investigators to trace movements of stolen assets across blockchains and monitor for attempts to move them onward.
Withdrawals will remain suspended until the security review is completed, the exchange said, adding that it will publish a full incident report covering the root cause and corrective measures. Bitget said further unauthorized transfers had been contained and that it would provide updates as its investigation progresses. The findings of that report, the timeline for restoring withdrawals, and the results of tracking the flagged addresses are the immediate markers to watch as the story develops.
The breach adds to a series of large cryptocurrency security incidents in 2026, underscoring the risks exchanges face even when the private keys controlling their offline reserves are not compromised.