Bitget pauses withdrawals after $387.5M hack, CEO assures funds safe

Photo: Tima Miroshnichenko / Pexels

Bitget pauses withdrawals after $387.5M hack, CEO assures funds safe

The exchange's User Protection Fund, holding over $464 million, is designed to absorb losses without touching user balances.

Bitget detected unauthorized transfers from its hot and warm wallets at 18:31 UTC on September 24, 2026, and moved quickly to suspend all withdrawals. The initial damage estimate came in at $351.6 million, later revised upward to $387.5 million once investigators traced additional stolen assets on the Zcash and Tron networks.

CEO Gracy Chen moved to calm users within hours, pointing to the exchange’s User Protection Fund as the firewall between the hack and customer balances. The fund currently holds over $464 million, enough to absorb the revised loss figure with room to spare.

How the attackers got in

The breach did not involve stolen private keys. Attackers instead exploited a vulnerability in Bitget’s backend wallet infrastructure, which gave them the ability to spoof transaction authorization data and move funds without triggering the usual authentication checks. Cold wallets were left untouched.

Advertisement

Chen linked the attack to North Korean hacking groups, citing IP behavior patterns and on-chain analysis. Cybersecurity firm Mandiant and blockchain analytics firm SlowMist have both joined the investigation alongside law enforcement. Bitget said the unauthorized outflows have been contained and committed to releasing a full incident report.

What users are actually looking at

Trading and deposits at Bitget continued without interruption throughout the incident. User balances were not affected, and the exchange has been explicit that the User Protection Fund exists specifically for scenarios like this one.

Bitget’s native BGB token dropped roughly 3.3% immediately after news of the hack broke.

The broader security picture

At $387.5 million, this is the largest single exchange hack of 2026. The attack method, spoofing backend transaction authorization rather than targeting private keys directly, points to a maturing threat landscape where backend systems represent a softer target than private key infrastructure.

Mandiant’s involvement is notable. SlowMist, which specializes in blockchain security, brings complementary expertise in tracing stolen crypto funds across chains. The fact that additional stolen assets were discovered on Zcash and Tron networks after the initial estimate suggests the on-chain investigation is still developing.

Disclosure: This article was edited by John Chen. For more information on how we create and review content, see our Editorial Policy.
Bitget pauses withdrawals after $387.5M hack, CEO assures funds safe
Bitget pauses withdrawals after $387.5M hack, CEO assures funds safe

The exchange's User Protection Fund, holding over $464 million, is designed to absorb losses without touching user balances.

Share

Add us on Google

Photo: Tima Miroshnichenko / Pexels

Bitget detected unauthorized transfers from its hot and warm wallets at 18:31 UTC on September 24, 2026, and moved quickly to suspend all withdrawals. The initial damage estimate came in at $351.6 million, later revised upward to $387.5 million once investigators traced additional stolen assets on the Zcash and Tron networks.

CEO Gracy Chen moved to calm users within hours, pointing to the exchange’s User Protection Fund as the firewall between the hack and customer balances. The fund currently holds over $464 million, enough to absorb the revised loss figure with room to spare.

How the attackers got in

The breach did not involve stolen private keys. Attackers instead exploited a vulnerability in Bitget’s backend wallet infrastructure, which gave them the ability to spoof transaction authorization data and move funds without triggering the usual authentication checks. Cold wallets were left untouched.

Advertisement

Chen linked the attack to North Korean hacking groups, citing IP behavior patterns and on-chain analysis. Cybersecurity firm Mandiant and blockchain analytics firm SlowMist have both joined the investigation alongside law enforcement. Bitget said the unauthorized outflows have been contained and committed to releasing a full incident report.

What users are actually looking at

Trading and deposits at Bitget continued without interruption throughout the incident. User balances were not affected, and the exchange has been explicit that the User Protection Fund exists specifically for scenarios like this one.

Bitget’s native BGB token dropped roughly 3.3% immediately after news of the hack broke.

The broader security picture

At $387.5 million, this is the largest single exchange hack of 2026. The attack method, spoofing backend transaction authorization rather than targeting private keys directly, points to a maturing threat landscape where backend systems represent a softer target than private key infrastructure.

Mandiant’s involvement is notable. SlowMist, which specializes in blockchain security, brings complementary expertise in tracing stolen crypto funds across chains. The fact that additional stolen assets were discovered on Zcash and Tron networks after the initial estimate suggests the on-chain investigation is still developing.

Disclosure: This article was edited by John Chen. For more information on how we create and review content, see our Editorial Policy.