Bitget Hit by $388M Security Incident: Attackers Exploit Third-Party Vulnerability
Bitget, a popular cryptocurrency exchange, was hit by a security incident on September 24, 2026. At approximately 18:31 UTC, unauthorized transfers involving certain assets were made across multiple blockchains from a portion of Bitget's hot and warm wallet infrastructure.
The attacker may have exploited a vulnerability in a third-party security product to obtain high-level internal credentials, allowing them to send fraudulent withdrawal commands to the wallet system. The attack bypassed existing risk controls, resulting in abnormal transfers.
Bitget's security team identified the root cause of the incident and isolated the affected systems. They remediated the underlying vulnerability and revoked internal login credentials. Withdrawal services were shut down and re-enabled gradually as the exchange secured its infrastructure.
The investigation found that 12 wallet addresses associated with hot or warm wallets were involved in the unauthorized transfers, amounting to approximately $388 million. Affected assets included XRP, ETH, USDT, ZEC, ATOM, USDC, USD0, XAUt, BNB, AVAX, TRX, ALGO, and TIA across 11 blockchains.