Bitget Exchange Experiences $388 Million Security Breach Due to Third-Party Vulnerability

Why it matters
This breach underscores vulnerabilities in centralized cryptocurrency exchanges, potentially shaking user trust and market stability.
What happened (in 30 seconds)
- Bitget suffered a breach on September 24, 2026, losing approximately $388 million from its hot and warm wallets.
- Withdrawals were suspended immediately, with a phased resumption starting on September 28, 2026.
- Forensic investigations suggest involvement of North Korean-linked actors, consistent with previous state-sponsored cyber thefts.
The context you actually need
- State-sponsored threats: This incident aligns with a multi-year trend of large-scale cryptocurrency thefts attributed to state-sponsored groups, particularly North Korea.
- User Protection Fund: Bitget had a dedicated User Protection Fund valued at over $464 million, which is absorbing the losses to maintain user balances.
- Market response: Following the breach, customer outflows reached approximately $463 million within the first 24 hours of reopening, indicating diminished user confidence.
What's really happening
On September 24, 2026, at approximately 18:31 UTC, Bitget experienced a significant security breach that exploited a zero-day vulnerability in a third-party security application. This vulnerability allowed attackers to spoof internal credentials and initiate unauthorized fund transfers from Bitget's hot and warm wallets, totaling around $388 million. The attackers began with small test transfers, which escalated to larger unauthorized movements, effectively bypassing the exchange's risk controls without compromising private keys.
In response, Bitget immediately suspended all withdrawals while allowing trading and deposits to continue. The exchange engaged cybersecurity firms Mandiant and SlowMist to conduct forensic investigations and notified law enforcement. The vulnerability was remediated, and no further unauthorized activity was detected post-incident. A phased withdrawal resumption began on September 28, starting with Bitcoin, followed by Ethereum and USDT, with a target for full restoration by October 2.
Despite the breach, Bitget's CEO Gracy Chen confirmed that the exchange's cold wallets and private keys remained uncompromised. The User Protection Fund was activated to cover the losses, ensuring that user balances would remain intact. However, the incident has raised alarms about the security of centralized exchanges, particularly in light of ongoing state-sponsored cyber threats. The forensic assessments pointing to potential North Korean involvement align with a broader pattern of sophisticated supply-chain and credential-based attacks that have extracted billions in digital assets over the years.
The aftermath of the breach has seen significant customer outflows, with approximately $463 million withdrawn within the first 24 hours of the phased reopening. This reflects a notable erosion of user confidence in Bitget and centralized exchanges as a whole. The incident highlights the critical need for enhanced security measures and transparency in the cryptocurrency space, as users become increasingly wary of the risks associated with centralized platforms.
Who feels it first (and how)
- Retail traders: Individuals trading on Bitget may experience liquidity issues and reduced confidence in the platform.
- Institutional investors: Firms holding assets on centralized exchanges may reconsider their security protocols and asset management strategies.
- Crypto market participants: General sentiment in the cryptocurrency market may shift, affecting trading volumes and asset prices across exchanges.
What to watch next
- Withdrawal trends: Monitor the volume of withdrawals from Bitget and other centralized exchanges to gauge user confidence and liquidity shifts.
- Regulatory responses: Watch for any potential regulatory actions or guidelines that may emerge in response to the breach, particularly regarding cybersecurity standards.
- Market sentiment: Observe changes in market sentiment and trading volumes in the wake of the breach, as user trust in centralized exchanges may fluctuate.
Bitget's User Protection Fund is covering the losses from the breach.
User confidence in centralized exchanges will continue to be shaken, leading to increased withdrawals and liquidity challenges.
The full extent of regulatory responses and their impact on the cryptocurrency market remains uncertain.
Frequently Asked Questions
- Why it matters?
- This breach underscores vulnerabilities in centralized cryptocurrency exchanges, potentially shaking user trust and market stability.
- What happened (in 30 seconds)?
- Bitget suffered a breach on September 24, 2026, losing approximately $388 million from its hot and warm wallets. Withdrawals were suspended immediately, with a phased resumption starting on September 28, 2026. Forensic investigations suggest involvement of North Korean-linked actors, consistent with previous state-sponsored cyber thefts.
- What's really happening?
- On September 24, 2026, at approximately 18:31 UTC, Bitget experienced a significant security breach that exploited a zero-day vulnerability in a third-party security application. This vulnerability allowed attackers to spoof internal credentials and initiate unauthorized fund transfers from Bitget's hot and warm wallets, totaling around $388 million. The attackers began with small test transfers, which escalated to larger unauthorized movements, effectively bypassing the exchange's risk controls
- Who feels it first (and how)?
- Retail traders: Individuals trading on Bitget may experience liquidity issues and reduced confidence in the platform. Institutional investors: Firms holding assets on centralized exchanges may reconsider their security protocols and asset management strategies. Crypto market participants: General sentiment in the cryptocurrency market may shift, affecting trading volumes and asset prices across exchanges.
- What to watch next?
- Withdrawal trends: Monitor the volume of withdrawals from Bitget and other centralized exchanges to gauge user confidence and liquidity shifts. Regulatory responses: Watch for any potential regulatory actions or guidelines that may emerge in response to the breach, particularly regarding cybersecurity standards. Market sentiment: Observe changes in market sentiment and trading volumes in the wake of the breach, as user trust in centralized exchanges may fluctuate.
Research, news, and analysis on blockchain startups, DeFi, and regulations.
"Crypto Briefing provides research, news, and analysis on blockchain startups, DeFi, and crypto regulations with investor-focused coverage."
— A47 Editor
Bitget CEO Gracy Chen expresses skepticism on recovering $387.5M in stolen funds
Bitget CEO Gracy Chen expressed skepticism regarding the recovery of approximately $387.5 million in stolen funds following a significant security breach. The incident highlights vulnerabilities in the cryptocurrency sector, particularly concerning t...
Research, news, and analysis on blockchain startups, DeFi, and regulations.
"Crypto Briefing provides research, news, and analysis on blockchain startups, DeFi, and crypto regulations with investor-focused coverage."
— A47 Editor
Bitget reopens withdrawals after major security breach drains roughly $388 million
Bitget has reopened withdrawals following a significant security breach that resulted in unauthorized transfers totaling approximately $388 million. The breach, which affected both hot and warm wallets, prompted the exchange to temporarily suspend wi...
Covers blockchain, cryptocurrency news, project analysis, and market insights.
"Cointelegraph is a leading crypto-focused media outlet known for timely news, analysis, and educational content related to blockchain and digital assets."
— A47 Editor
Bitget CEO ‘not very optimistic’ on recovering funds from $388M breach
Bitget, a cryptocurrency exchange, has reported a significant security breach resulting in unauthorized transfers totaling approximately $388 million. CEO Gracy Chen expressed skepticism about the recovery of these funds, citing the 2025 Bybit hack a...
Real-time updates, analysis, and reports on the blockchain and cryptocurrency sectors.
"Crypto News delivers real-time updates, analysis, and reports on the blockchain and cryptocurrency sectors."
— A47 Editor
Bitget’s hack exposes a double standard on stolen funds
Bitget, a cryptocurrency exchange, recently suffered a significant security breach resulting in unauthorized transfers totaling approximately $388 million. The exchange has paused withdrawals as investigations reveal a backend breach, prompting Bitge...
English-language digital publication covering business, politics, technology, and current affairs.
"The Arabian Post mixes original and syndicated-style coverage with a broad regional and global business-news orientation."
— A47 Editor
THORChain rejects Bitget request to block hacker wallets
THORChain has declined a request from Bitget's CEO Gracy Chen to block addresses associated with a recent $387.5 million security breach, asserting that its permissionless network cannot selectively censor transactions. The stolen assets were reporte...
Covers Bitcoin plus altcoin news, market updates, and educational resources.
"Bitcoin.com provides news, market data, and guides focused on Bitcoin and the wider crypto industry."
— A47 Editor
Thorchain Faces Heat as Bitget Hack Revives Bybit Controversy
Thorchain is facing scrutiny following a significant security breach at Bitget, where hackers drained approximately $352 million. This incident has reignited controversy surrounding Bybit, as concerns about the security protocols of cryptocurrency ex...