Bitget Confirms $351.6 Million Hot Wallet Hack, Suspends Withdrawals
Key Takeaways
- •Bitget suspended customer withdrawals after attackers stole approximately $351.6 million from its internet-connected hot wallets, with the intrusion detected at 18:31 UTC on September 24, 2026.
- •Blockchain records show roughly $133.4 million in assets moved from Bitget-labeled wallets across Ethereum and Arbitrum, alongside 3,000 Tether Gold tokens worth $12.8 million, with the remainder transferring on other chains.
- •The attacker converted the freezable stolen tokens—USDT, USDC and Tether Gold—into ether through Uniswap within minutes, accepting premiums of up to 5% over spot to outrun potential issuer freezes.
- •CEO Gracy Chen stated that cold storage was never breached, the loss falls within the exchange's $464 million User Protection Fund, and a complete incident report will be released within 24 hours.
- •The breach is the largest exchange loss since Bybit's roughly $1.5 billion hack in February 2025, and fake tokens mimicking the attacker's transfers have already appeared to deceive address trackers.

Bitget Confirms $351.6 Million Hot Wallet Hack, Suspends Withdrawals
Bitget suspended customer withdrawals on Thursday night after confirming that attackers drained roughly $351.6 million from its hot wallets. Chief Executive Gracy Chen published the notice at 21:30 UTC. "At 18:31 UTC on September 24, 2026, Bitget's security systems detected unauthorized transfers from some of our hot wallets," she wrote. "Our security team activated emergency response protocols immediately."
On-chain records corroborate the 18:31 timestamp. What they also show, in minute-by-minute detail, is everything that happened afterward.
Three Hours Between Detection and Containment
At 18:31:11 UTC, a wallet labeled "Bitget 6" on Etherscan, Arbiscan and BscScan sent 0.84 ether to an address created that same day — the small test transfer that typically precedes a large exfiltration, and the first on-chain movement of the breach. It landed in the same minute Bitget says its systems flagged the intrusion.
The main outflows followed quickly. At 18:58:59, the same wallet sent 34,751,168 USDT. At 19:01:20, on Arbitrum, it sent 19,668,851 USDT0. At 19:01:23, it moved 12,852,046 USDC, and at 19:01:35, 7,130.86 ether. A second wallet, labeled "Bitget 35," added 15,362 ether across three transfers. A further 223.2 ether left at 21:23:11 — two hours and 52 minutes after the detection timestamp in Bitget's own notice, and seven minutes before that notice was published.
In total, $133.4 million left Bitget-labeled wallets across Ethereum and Arbitrum alone, alongside 3,000 Tether Gold tokens worth $12.8 million from a third address. The remainder of the $351.6 million moved across other chains.
None of this indicates a slow response in any conventional sense. Hot wallets are the internet-connected balances an exchange keeps online to service withdrawals; cold storage sits offline. An exchange operates hot wallets across a dozen networks, and shutting each one down without stranding customer withdrawals is not a single switch. Chen said cold storage was never touched. Still, the gap between detection and containment here is measured in hours — and it is where the money went.
The Attacker Converted Everything That Could Be Frozen
The asset selection points to deliberate planning. Tether can freeze USDT. Circle can freeze USDC. Tether can freeze its gold token. Ether cannot be frozen by anyone.
Within six minutes of receiving the tokens, the attacker pushed all three into 0x7c96279E, a router contract that dispersed them across Uniswap V3 pools and the Uniswap V4 PoolManager and returned ether. DCF GOD, a pseudonymous analyst with 105,000 followers who flagged the Arbitrum leg before Bitget said anything publicly, noted that the buyer was "paying up to +5% over spot" and drove one to $2,870 against a spot price near $2,688. "which makes no sense if someone was just trying to buy eth," he wrote. It makes sense if the seller is racing an issuer's freeze function.
What remains is ether, sitting in three wallets that had never transacted before: 10,000 ETH at 20:13, 10,000 at 20:19, and 4,590 more at 21:41:11. That final tranche moved ten minutes after Chen's notice went up, and a minute after Bitget's own account told customers it had "identified and flagged the relevant transfer addresses."
What Bitget Says
"User funds are safe," Chen wrote. "The full amount of this loss falls within the coverage of Bitget's User Protection Fund, which currently holds over $464 million." She described a three-tier wallet architecture in which "the breach contained only a portion of the hot wallet and warm wallet layers," said deposits and trading were running normally, and promised a full incident report within 24 hours. "We will not speculate on the attack vector until the investigation is complete."
That last commitment carries weight for every other exchange operator. Breaches of this shape rarely involve breaking cryptography. "Those are off-chain hacks that led to on-chain loss of funds," said Ido Sofer, founder and CEO of key management firm Sodot, on the On The Margin podcast, describing the pattern behind the Bybit theft and its successors. "Developer credentials, deployment keys, API keys that are being stolen. And that provided access to moving funds on chain." His blunter version: "There will be hacks. The question is, is it gonna be in your company or not?"
A $464 million fund set against a $351.6 million loss is a thin but real cushion. Bitget has also published proof-of-reserves attestations — periodic snapshots of holdings intended to demonstrate that customer assets are fully backed — for 45 consecutive months, most recently reporting a 122% reserve ratio for August. The real test of all of it is whether withdrawals reopen.
A Second Scam Is Already Running
One warning for anyone tracking the addresses: within hours, spoofed tokens began mimicking the attacker's transfers. Fake contracts named "ETH," "USDC" and "USDT" — some spelled with invisible Unicode characters — broadcast the same amounts to lookalike addresses that differ from the real ones only in the middle. Fourteen had appeared against this one wallet by 22:00. Anyone copying an address out of a block explorer right now risks picking up a poisoned one.
The incident is the largest exchange loss since the Bybit breach, which drained roughly $1.5 billion in February 2025 in an attack widely attributed to North Korea's Lazarus Group. It follows the $130 million Coldcard theft that reopened the argument over who should hold bitcoin's keys, and the $137 million November spree that rebuilt DeFi's yield layer. As with the fresh wallets that made $1.2 million on Polymarket before the Iran airstrikes, the chain recorded everything in public while everyone argued about what it meant.
"Bitget has navigated multiple market cycles. We will not run from this," Chen wrote. The incident report is due within a day, and 24,590 ether sits in three wallets waiting to move.