Bitget Hack Losses Reach $351.6 Million as CEO Rules Out Private Key Compromise
Key Takeaways
- •Attackers exploited a backend wallet system to replicate transaction data and trigger the authorization process for moving funds, and Bitget ruled out any compromise of its private keys.
- •Lookonchain's on-chain analysis found XRP and Ethereum were the hardest-hit assets, with 102.93 million XRP worth $157.48 million and 31,890 ETH valued at $85.75 million among the affected holdings.
- •Bitget's monitoring flagged the unauthorized transfers at 18:31 UTC on Sept. 24, and the company says losses are contained, its cold wallets remain secure, and no further unauthorized transfers are possible.
- •Withdrawals are paused while deposits and regular trading continue, and Bitget's User Protection Fund, holding more than $464 million, is positioned to cover investor losses.
- •CEO Gracy Chen said identified IP addresses show VPN usage patterns matching a DPRK-linked group, making North Korean involvement very likely, though no timeline has been given for reopening withdrawals or releasing the full technical report.

Bitget said a security breach on Sept. 24, 2026, affected roughly $351.6 million in digital assets held on the exchange. Chief Executive Officer Gracy Chen said attackers compromised a backend wallet system rather than obtaining the platform's private keys. The company suspended withdrawals while keeping deposits and regular trading operational.
The exchange detected the unauthorized transfers at 18:31 UTC and activated its emergency procedures within minutes. According to Bitget, the breach reached parts of its hot and warm wallet infrastructure, while its cold wallets, which store assets offline, remained unaffected. Chen later said the company had contained the incident and blocked further unauthorized transfers.
Attackers Targeted Backend Wallet Infrastructure
Crypto hack incidents have been on the rise in 2026, with industry losses totaling $1.32 billion in the first half of the year, according to The Market Periodical's earlier reporting, and Bitget is the latest major exchange to be hit. According to Chen, the attackers compromised a major backend system within Bitget's wallet infrastructure, then used that access to replicate transaction data and trigger the authorization process needed to move funds out of the exchange.
“Private key compromise has been ruled out,” Chen said. Because the private keys themselves were not compromised, the theft was stopped at about $351 million, preventing the attackers from signing new transfers and draining additional funds from the platform.
“Loss containment is confirmed. No further unauthorized transfers are possible. The specific method of system intrusion remains under active investigation. A full technical report will follow once confirmed,” Chen said.
Bitget's systems flagged the unauthorized transfers from its hot wallets at 18:31 UTC on Sept. 24. The hot wallet layer stays online and connected to the internet around the clock. Chen said the attacker managed to reach the warm-wallet layer, which acts as a buffer between fully hot wallets (online) and fully cold wallets (offline) — a tiered structure common across the industry, designed to limit how much remains exposed online at any given time. She confirmed that Bitget's offline vault, its cold wallets, “remain fully secure.”
XRP and ETH Lead the List of Affected Assets
On-chain analysis by the blockchain analytics platform Lookonchain, shared in a post on X, identified Ripple's XRP and Ethereum (ETH) as the two most heavily affected assets on the Bitget platform. The stolen funds included 102.93 million XRP worth $157.48 million and 31,890 ETH valued at $85.75 million, according to Lookonchain.
Lookonchain also listed 34.75 million USDT (about $34.75 million), 21.05 million USDC (about $21.05 million), 19.67 million USD, and 3,000 XAUt (about $12.82 million) among the affected holdings. The incident further involved 12,719 BNB worth $9.88 million, 821,012 AVAX valued at $8.38 million, and 20.59 million TRX worth $7.07 million.
Bitget Points to $464 Million Protection Fund
In a message posted on X, Chen said Bitget's User Protection Fund holds more than $464 million, an amount she said is sufficient to cover investors' losses. “User funds are safe,” she wrote. “Your account balances are accurate and your assets are protected.”
Withdrawals are paused for the time being, while deposits and regular trading remain open. Chen said withdrawals would be reopened and that the team would be capable of handling any bank run. She noted that Bitget's retail trading volume is comparable to Bybit's, and argued that the exchange could absorb a loss of more than $300 million, similar to Bybit's ability to absorb its $1.5 billion loss.
Chen also said the team had identified IP addresses with VPN usage patterns matching those associated with a specific DPRK-linked group, making a North Korean connection “very likely.” North Korean-linked hacking groups have been implicated by investigators and researchers in some of the largest cryptocurrency exchange thefts in recent years.
Bitget has committed reopening withdrawals and publishing a full technical report on the intrusion method, but has not provided a timeline for either. The investigation remains ongoing, and loss estimates or attribution may shift as new evidence emerges. This article is for informational purposes only.