Bitget disclosed that unauthorized transfers were detected from several of its hot wallets at 18:31 UTC on 24 September 2026. Within an hour, on-chain analysts had identified roughly $183 million moving out of wallets linked to the platform. By the time the exchange released an official statement, the total outflow had risen to $351.6 million, and the figure was later updated to $387.5 million.

Scale of the loss

The stolen assets spanned multiple blockchains and included stablecoins, Ethereum, and a substantial XRP holding. The XRP component alone comprised about 103 million tokens, valued at roughly $157 million at current market rates. The remainder consisted of a mix of USDT, ETH and other crypto, bringing the overall loss to the highest recorded for a single exchange in 2026.

Method of attack

According to Bitget’s CEO, Gracy Chen, the perpetrators did not obtain private keys to the exchange’s cold, hot, or warm wallets. Instead, they infiltrated a backend system that manages wallet operations and fabricated transaction data. This forged data convinced Bitget’s internal approval mechanism to sign off on withdrawals that appeared legitimate. In effect, the attackers submitted counterfeit withdrawal requests that bypassed the usual verification steps.

A pseudonymous researcher, known as DCF GOD, highlighted a newly created wallet that moved $19.67 million in USDT to purchase 7,111 ETH across decentralized exchanges UniswapX and 1inch Fusion, paying a 5% premium. Subsequent investigations traced additional transfers across at least five blockchains to addresses controlled by the attackers.

Response and protection fund

Bitget halted all withdrawals shortly after the breach was identified, while trading and deposits continued. The exchange’s User Protection Fund, which now holds more than $464 million, will fully reimburse the loss, ensuring that user account balances remain unaffected. The fund was originally established in 2023 with $300 million to address similar incidents.

Bitget has engaged forensic partners, including Mandiant and SlowMist, to complete a root-cause analysis. The exchange plans to release a comprehensive incident report once remediation is finalized, and it expects to reopen withdrawals after a further safety review.

Suspected perpetrators

While the identity of the attackers has not been publicly confirmed, Chen noted that certain IP addresses and on-chain signatures resemble patterns previously linked to North Korean state-affiliated hacking groups, such as Lazarus. These groups have been attributed to large-scale crypto thefts, including the $1.4 billion Bybit hack in February 2025. Chainalysis estimates that North Korean actors amassed over $2 billion in crypto proceeds in 2025 alone.

Why it matters

The breach underscores the vulnerability of even well-funded exchanges to sophisticated backend attacks that do not rely on private-key theft. Bitget’s ability to cover the loss through its protection fund protects users but also highlights the growing importance of such reserves in the industry. Moreover, the suspected involvement of a nation-state actor raises broader concerns about geopolitical motivations behind cryptocurrency theft and the challenges law-enforcement faces in attributing and responding to cross-border cyber-crimes.