Bitget Suffers $351M Breach, Expects User Fund to Cover Loss
Bitget, a cryptocurrency exchange, has been hit by a significant breach that resulted in the loss of $351.6 million in assets. The incident occurred on September 24, 2026, when Bitget's security systems detected unauthorized transfers from several hot wallets. According to Gracy Chen, CEO of Bitget, investigators have ruled out a leak of private keys used by the exchange's cold, warm, and hot wallets.
The attackers are believed to have entered Bitget's systems and transferred funds directly, without using customer withdrawal requests. The exact entry point is still under review, but Bitget has identified part of the attack route as a compromise of a core backend wallet service. Chen noted that measures have been taken to prevent further outflows, but withdrawals remain suspended while the exchange works on strengthening security controls and repairing systems.
The stolen assets include 102.93 million XRP worth $157.48 million, according to estimates from Lookonchain. Bitget's internal estimate puts the loss at approximately $351.6 million, with customer account balances remaining accurate. The exchange's User Protection Fund, valued at more than $464 million, is expected to cover the estimated loss.
The incident has raised concerns about the potential involvement of a North Korean hacking group, although Chen stopped short of confirming attribution. Bitget has promised to release a full incident report containing its root-cause analysis and corrective actions within 24 hours.