NewsCryptoBitget Hit by $387.5 Million Wallet Breach, Temporarily Suspends Withdrawals

Bitget Hit by $387.5 Million Wallet Breach, Temporarily Suspends Withdrawals

Author: LiveBitcoinNews·

Key Takeaways

  • •Bitget detected unauthorized transfers from some hot and warm wallets at 18:31 UTC on September 24, 2026, and activated emergency response protocols within minutes.
  • •The estimated loss was revised from about $351.6 million to roughly $387.5 million through additional transaction classification, affecting assets across Ethereum and EVM chains, the XRP Ledger, Zcash and TRON.
  • •Bitget's cold wallets and its separate self-custodial Bitget Wallet service were unaffected, and the exchange said its User Protection Fund could cover the reported loss.
  • •A new Recovery Bounty Program offers eligible participants 5% of funds frozen and 5% of funds recovered through qualifying voluntary efforts, while actions under court orders or law-enforcement processes do not qualify.
  • •Withdrawals remain suspended pending completion of the security review, with a restoration status update planned by September 26, and Mandiant and SlowMist are supporting fund tracing.
Bitget Hit by $387.5 Million Wallet Breach, Temporarily Suspends Withdrawals

Crypto exchange Bitget has suffered a major security breach involving hundreds of millions of dollars in digital assets. Unauthorized transfers from parts of the exchange's wallet infrastructure began on September 24, 2026, prompting an emergency response and a temporary suspension of withdrawals. The company has confirmed approximately $387.5 million in affected assets and launched a recovery bounty aimed at freezing and returning the stolen funds. Deposits and trading remain operational while security teams investigate the incident.

Bitget Detects Unauthorized Wallet Transfers

Bitget detected unauthorized transfers from parts of its hot and warm wallet infrastructure on September 24. Security teams activated emergency procedures within minutes and began identifying suspicious addresses, according to the company.

Bitget said its cold wallets were unaffected by the breach, and that user account balances and assets remain accurate and protected. Hot and warm wallets sit at the connected layers of an exchange's custody setup, handling day-to-day transaction flow, while cold wallets keep reserves offline. The firm initially placed the affected funds at roughly $351.6 million and stated that its User Protection Fund could cover the reported loss.

Bitget's Gracy Chen shared the company's security notice on X:

[SECURITY NOTICE] Bitget Hot Wallet Incident — September 24, 2026

At 18:31 UTC on September 24, 2026, Bitget's security systems detected unauthorized transfers from some of our hot wallets. Our security team activated emergency response protocols immediately. What we have…

— Gracy Chen @Bitget (@GracyBitget) September 24, 2026

Further investigation later raised the amount transferred to attacker-controlled addresses to approximately $387.5 million. Bitget said the revision resulted from additional transaction classification rather than from new unauthorized transfers, with additional assets identified on Zcash and TRON accounting for part of the difference.

Affected networks include Ethereum and several EVM chains, the XRP Ledger, Zcash and TRON. Assets involved include XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX and TRX.

Bitget Launches Recovery Bounty Program

Recovery efforts have already frozen some affected assets with help from industry partners, according to Bitget. The firm has also introduced a Recovery Bounty Program for eligible parties who directly help freeze or recover affected funds. Eligible participants may receive 5% of funds successfully frozen through their voluntary actions, and another 5% may apply to funds successfully recovered through qualifying efforts.

Bounty-style recovery programs have become a recurring industry tool after exchange security incidents, enlisting outside exchanges, token issuers and on-chain investigators to flag and freeze stolen funds as they move across public blockchains.

Actions carried out under court orders, law-enforcement requests or other legal processes do not qualify for bounty payments.get will make final decisions regarding eligibility and payment amounts. The exchange will also use Bybit's LazarusBounty initiative as a key channel for its fund-tracing and recovery efforts.

Withdrawals Remain Suspended

Withdrawal services remain unavailable while technical teams conduct security checks and prepare systems for reopening. In a September 24 withdrawal notice, Bitget said services would return once its security review is completed, and the exchange plans to announce the status and timing of withdrawal restoration by September 26. Withdrawal pauses of this kind are a standard containment measure after exchange security incidents, designed to stop further outflows while internal systems are verified.

Meanwhile, Bitget Wallet said its separate self-custodial service was not affected by the exchange incident, and that its systems and users' self-custodied assets remain operational. Independent cybersecurity firms Mandiant and SlowMist are assisting Bitget with the investigation and fund-tracing work. Mandiant is an established cybersecurity firm and SlowMist specializes in blockchain security and on-chain forensics.

Fund tracing and the wider investigation remain active, meaning the confirmed loss figure could change as more transactions are classified. The near-term markers to watch include the September 26 update on withdrawal restoration and progress on asset freezes under the Recovery Bounty Program.