← All stories
● Covered by 7 sources · 11 reportsMedium impact7 negative4 neutral

Bitget crypto exchange reports $351.6 million stolen from hot and warm wallets

🔄 Updated 6h ago — new reporting from CNBC Technology
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Bitget lost $351.6 million from hot and warm wallets.
  • The User Protection Fund, holding $464 million, will cover losses.
  • Withdrawals are temporarily suspended during investigation.
  • North Korean hackers are suspected based on attack patterns.
  • Attack occurred at 18:31 UTC on September 24, 2026.
  • Bitget's cold wallets and most platform assets are secure.
  • Customer account balances are accurate; deposits and trading operate normally.
  • Bitget enlisted Mandiant and SlowMist for investigation.
  • Bitget Wallet was not affected by the incident.
  • Impacted assets include ETH, XRP, BNB, AVAX, USDT, USDC.
  • Affected chains include Ethereum, XRP Ledger, Arbitrum, Avalanche.
  • The attack is the largest crypto heist of the year.
  • Bitget CEO Gracy Chen stated the attack methods are highly consistent with North Korean hacker organizations.
  • The incident has been reported to relevant authorities.
  • Bitget was founded in 2018.
  • XRP accounts for the largest loss on a single chain.
  • The initial estimate of losses amounts to $387.5 million.
  • Bitget's security team initially detected unauthorized transfers and activated emergency protocols.
  • Law enforcement and other crypto platforms were notified about the incident.
  • Bitget resumed Bitcoin withdrawals.
  • Bitget addressed the security vulnerability exploited in the incident.
  • ETH withdrawals will resume on September 29 at 8:00 UTC.
  • USDT withdrawals will resume on September 30 at 8:00 UTC.
  • Other tokens/Fiat/P2P assets withdrawals will resume starting October 2 at 8:00 UTC.
  • Bitget CEO Gracy Chen spoke on an X livestream about the hack.
  • Hackers exploited a backend wallet system by forging transfer approvals.
  • Suspicious IP addresses tied to VPN infrastructure were used by hackers.
  • Early independent on-chain analysis estimated stolen value at $170 million to $183 million.
  • The BSC network was among the affected chains.
  • Attacker exploited a zero-day vulnerability in a third-party security product.
  • Attacker gained internal credentials through the vulnerability.
  • Attacker sent fraudulent withdrawal commands that bypassed Bitget's risk controls.
  • Bitget CEO Gracy Chen described the attack in an interview with The Block and comments to Cointelegraph.
  • Attackers dropped web shells on one appliance and malware on the production wallet job server.
  • Attackers used a custom withdrawal tool to steal cryptocurrency.
  • Malicious activity was first identified on August 31.
  • Attackers ran a hidden script under a service process to read a database password.
  • Similar hidden-script activity was observed on two other nodes on September 23 and September 25.
  • Bitget confirmed the zero-day vulnerability findings from SlowMist.
  • Bitget recovered a customized tool used by the attacker.
  • Bitget notified the relevant third-party vendor.
  • Bitget disabled the affected functionality.
  • Only $1.1 million of stolen funds have been frozen.
  • Bitget's protection fund was drawn down to below $200 million after the hack.
  • The protection fund was restored to over $300 million.
  • Bitget's latest Proof of Reserves is based on a September 29 snapshot.

Bitget Suffers Significant Breach

Cryptocurrency exchange Bitget disclosed a security breach resulting in the theft of $351.6 million from its hot and warm wallets. The incident was detected on Thursday evening when security systems flagged unauthorized transfers.

Bitget has temporarily halted all withdrawals to facilitate an investigation. The company is collaborating with law enforcement, on-chain security institutions, and cybersecurity experts from Mandiant and SlowMist.

Unaffected Assets and User Protection

Bitget confirmed that its self-custodial Bitget Wallet was not impacted, as it operates on separate infrastructure. The majority of platform assets and cold wallets remain secure.

The company stated that its User Protection Fund, which currently holds approximately $464 million, will cover all losses incurred by the incident. Customer account balances and trading operations are unaffected.

Attack Vector and Suspected Perpetrators

Bitget CEO Gracy Chen indicated that the attack involved multiple blockchain networks, including Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base, affecting assets like ETH, XRP, BNB, AVAX, USDT, and USDC. XRP experienced the largest single-chain loss.

The attack method, involving compromise of a critical backend wallet-service system to spoof transaction data and trigger authorization, is consistent with known patterns of North Korean hacker organizations. Some hacker wallet addresses have reportedly been frozen.

Updates

🕒 2026-10-02 · new reporting from CNBC Technology
  • Only $1.1 million of stolen funds have been frozen.
  • Bitget's protection fund was drawn down to below $200 million after the hack.
  • The protection fund was restored to over $300 million.
  • Bitget's latest Proof of Reserves is based on a September 29 snapshot.
🕒 2026-10-01 · new reporting from The Hacker News
  • Bitget confirmed the zero-day vulnerability findings from SlowMist.
  • Bitget recovered a customized tool used by the attacker.
  • Bitget notified the relevant third-party vendor.
  • Bitget disabled the affected functionality.
🕒 2026-09-30 · new reporting from BleepingComputer
  • Attackers dropped web shells on one appliance and malware on the production wallet job server.
  • Attackers used a custom withdrawal tool to steal cryptocurrency.
  • Malicious activity was first identified on August 31.
  • Attackers ran a hidden script under a service process to read a database password.
  • Similar hidden-script activity was observed on two other nodes on September 23 and September 25.
🕒 2026-09-28 · new reporting from The Hacker News
  • Attacker exploited a zero-day vulnerability in a third-party security product.
  • Attacker gained internal credentials through the vulnerability.
  • Attacker sent fraudulent withdrawal commands that bypassed Bitget's risk controls.
  • Bitget CEO Gracy Chen described the attack in an interview with The Block and comments to Cointelegraph.
🕒 2026-09-28 · new reporting from Tom's Hardware
  • Bitget CEO Gracy Chen spoke on an X livestream about the hack.
  • Hackers exploited a backend wallet system by forging transfer approvals.
  • Suspicious IP addresses tied to VPN infrastructure were used by hackers.
  • Early independent on-chain analysis estimated stolen value at $170 million to $183 million.
  • The BSC network was among the affected chains.
🕒 2026-09-28 · new reporting from BleepingComputer
  • Bitget resumed Bitcoin withdrawals.
  • Bitget addressed the security vulnerability exploited in the incident.
  • ETH withdrawals will resume on September 29 at 8:00 UTC.
  • USDT withdrawals will resume on September 30 at 8:00 UTC.
  • Other tokens/Fiat/P2P assets withdrawals will resume starting October 2 at 8:00 UTC.
🕒 2026-09-25 · new reporting from TechCrunch, SecurityWeek, The Record
  • The attack is the largest crypto heist of the year.
  • Bitget CEO Gracy Chen stated the attack methods are highly consistent with North Korean hacker organizations.
  • The incident has been reported to relevant authorities.
  • Bitget was founded in 2018.
  • XRP accounts for the largest loss on a single chain.
  • The initial estimate of losses amounts to $387.5 million.
  • Bitget's security team initially detected unauthorized transfers and activated emergency protocols.
  • Law enforcement and other crypto platforms were notified about the incident.
🕒 2026-09-25 · new reporting from The Hacker News
  • Attack occurred at 18:31 UTC on September 24, 2026.
  • Bitget's cold wallets and most platform assets are secure.
  • Customer account balances are accurate; deposits and trading operate normally.
  • Bitget enlisted Mandiant and SlowMist for investigation.
  • Bitget Wallet was not affected by the incident.
  • Impacted assets include ETH, XRP, BNB, AVAX, USDT, USDC.
  • Affected chains include Ethereum, XRP Ledger, Arbitrum, Avalanche.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Bitget CEO Gracy Chen stated that the exchange does not expect to recover a significant portion of the $388 million stolen in a recent cyberattack, with only $1.1 million frozen so far. The exchange used its own capital to replenish its protection fund, ensuring user account balances were not affected by the theft.

Cryptocurrency exchange Bitget confirmed that a zero-day vulnerability in third-party security products was exploited in the recent $387.5 million theft. Attackers used this flaw to gain internal credentials and initiate unauthorized withdrawals across 11 blockchains. This incident highlights the supply chain risks associated with integrating third-party services in critical financial infrastructure.

Cryptocurrency exchange Bitget suffered a $387.5 million theft after attackers exploited a zero-day vulnerability in third-party security products. The breach allowed attackers to access Bitget's wallet environment and deploy malicious tools for cryptocurrency theft across multiple blockchains.

Cryptocurrency exchange Bitget announced that an attacker stole approximately $388 million by exploiting a zero-day vulnerability in a third-party security product used by the exchange. The attacker gained internal credentials, allowing them to send fraudulent withdrawal commands that bypassed Bitget's risk controls, impacting its hot and warm wallets.

Crypto exchange Bitget suffered a $387 million hack, with CEO Gracy Chen attributing the attack to North Korean state-sponsored actors based on suspicious IP addresses. The hackers exploited a backend wallet system, forging transfer approvals to steal various cryptocurrencies, though cold wallets and private keys remained secure. Bitget will cover all losses from its User Protection Fund and has implemented a staggered withdrawal schedule.

Cryptocurrency exchange Bitget has resumed Bitcoin withdrawals following a $387.5 million security breach last week, attributed to suspected North Korean hackers. The exchange states it has addressed the vulnerability and will progressively restore withdrawals for other assets, assuring user funds are unaffected and covered by its Protection Fund.

Crypto exchange Bitget suffered a breach resulting in the theft of $387.5 million, with CEO Gracy Chen attributing the attack to North Korean hackers. The company is using its $464 million User Protection Fund to cover losses and has suspended withdrawals while working with security firms and law enforcement.

Cryptocurrency exchange Bitget reported a theft of approximately $351.6 million in digital assets, attributing the attack methods to known North Korean threat actors. The incident involved unauthorized transfers from hot wallets, prompting an investigation with external security firms and notification to authorities.

Cryptocurrency exchange Bitget experienced a cyberattack resulting in the theft of over $351 million from its hot wallets, with North Korean hackers suspected as the perpetrators. This incident marks the largest crypto heist of the year and highlights ongoing security vulnerabilities in the digital currency sector.

Cryptocurrency exchange Bitget announced that suspected North Korean threat actors stole $351.6 million from its hot and warm wallets. The attack compromised a critical backend system, leading to unauthorized transfers of various cryptocurrencies across multiple chains.

Cryptocurrency exchange Bitget announced that hackers stole $351.6 million from its hot and warm wallets. The company has suspended withdrawals and is investigating the incident, stating its User Protection Fund will cover all losses.