Bitget confirmed on September 24, 2026 that roughly $351.6 million had been stolen from its hot and warm wallets, prompting the exchange to freeze withdrawals while deposits and trading continue as normal. The exchange said the loss will be covered in full by its User Protection Fund, which it says holds more than $464 million.

According to Bitget CEO Gracy Chen, writing on X, the exchange's security systems detected the unauthorized transfers at 18:31 UTC on September 24. "At 18:31 UTC on September 24, 2026, Bitget's security systems detected unauthorized transfers from some of our hot wallets. [...] Estimated funds affected: approximately $351.6 million," Chen wrote.

Chen sought to reassure users that cold storage was untouched. "Cold wallets remain fully secure. [...] User funds are safe. The entirety of this loss falls within the scope of Bitget's User Protection Fund, which currently holds more than $464 million," she said.

On-chain trackers diverge on the total

Blockchain security firm SlowMist traced approximately $357 million linked to the incident, spread across 11 EVM addresses, seven XRP Ledger addresses and one Tron address. Lookonchain separately estimated that about 102.9 million XRP, worth roughly $157.5 million, had been taken. Unchained's initial tally, built on a 13-address Arkham tracker, put the figure lower at approximately $183.8 million across six networks, including about 48,800 ETH, USDT, USDC, 821,012 AVAX, BNB and 3,000 XAUT.

Decrypt reported that the attacker moved quickly to convert holdings, swapping $19.67 million from USDT0 into 7,111 ETH within six minutes via UniswapX and 1inch Fusion, paying roughly a 5% premium over market price. Funds were also routed across chains using the Stargate and cBridge bridges. Arkham has grouped roughly 68,466 ETH, worth about $184 million, across 25 addresses under an entity labelled "Bitget Hacker."

North Korea attribution

Chen said preliminary investigation findings pointed to IP addresses associated with VPN services tied to a North Korean hacking group, and Hackread reported she had named the Lazarus Group specifically. On-chain investigator Specter noted that the route taken by the stolen XRP matched that used in the July hack of AFX, a $24 million theft attributed to TraderTraitor, a unit affiliated with Lazarus.

Chen described the attack mechanism as a compromise of backend wallet infrastructure rather than a leak of private keys. "Attackers compromised a backend wallet infrastructure service, falsified transaction data, and triggered the withdrawal authorization process themselves," she said, adding that Bitget would not speculate further until its investigation concluded. "A full incident report, including root cause analysis and remedial measures, will be published within 24 hours. We will not speculate on the attack vector before the investigation concludes," she said, with the report expected before 21:30 UTC on Friday, September 25.

Chen closed her statement with a pledge to keep the exchange operating. "Bitget has weathered several market cycles. We will not run away. Every dollar and every decision will be accounted for, in full transparency," she wrote.

The incident invites comparison with the February 2025 Bybit hack, in which $1.5 billion was stolen and later attributed by the FBI to North Korea. Binance's own protection fund, SAFU, currently holds $1 billion, roughly double the size of Bitget's fund even after the latest loss.