On September 24, 2026, crypto exchange Bitget suffered the largest crypto hack of the year. Attackers drained about $388 million from the exchange’s hot and warm wallets before the platform could stop them.
Four days later, Bitget restarted Bitcoin withdrawals. In the first hour alone, users pulled 4,098 BTC off the exchange. Here is what happened, what the exchange is doing now, and what you should do to keep your own funds safe.
Key takeaways
- $388 million stolen from Bitget’s hot and warm wallets on September 24, the biggest reported crypto theft of 2026.
- Bitcoin withdrawals resumed September 28 at 08:00 UTC. Users withdrew 4,098 BTC in the first hour.
- ETH withdrawals return September 29, USDT on September 30, and all other assets plus fiat and P2P by October 2.
- Bitget says private keys and cold wallets were never touched, and a 5,500 BTC protection fund will cover the loss.
- North Korea’s Lazarus group is the leading suspect, but attribution is not proven.
What happened in the $388 million Bitget hack
Bitget detected abnormal transfers at about 6:31 p.m. UTC on September 24. The money moved fast. Roughly $185 million left the exchange within a single minute.
The exchange’s systems caught the anomaly and blocked all user withdrawals. Deposits and trading kept running. After days of tracing, the confirmed loss stands at about $388 million.
A minute-by-minute look at the attack
Bitget’s incident timeline, shared publicly by CEO Gracy Chen, shows how quickly it all happened. The first two transfers were tiny probes: 0.84 ETH from an Ethereum hot wallet and 93 TRX from a TRON hot wallet. They were small enough to slip under risk-control thresholds and triggered no alert.
- Key takeaways
- What happened in the $388 million Bitget hack
- Bitcoin withdrawals are back: the full recovery timeline
- Are Bitget user funds safe?
- Who was behind the Bitget hack?
- What Bitget users should do right now
- Watch: the Bitget hack explained in plain English
- Watch: Bitget CEO Gracy Chen walks through the attack
- How to protect your crypto from the next exchange hack
- Mistakes to avoid after a hack
- Bitget hack: frequently asked questions
- How much was stolen from Bitget?
- Have Bitget withdrawals resumed?
- Were Bitget’s private keys stolen?
- Will Bitget customers lose their money?
- Was North Korea behind the Bitget hack?
- Should I keep my funds on Bitget?
- How do I move my Bitcoin to self-custody?
- The bottom line
- 02:58 to 04:09 UTC+8 (Sept 25): the attacker fired 17 large transfers worth roughly $360 million across Ethereum, XRP, BNB Smart Chain, Base, Arbitrum, Optimism and Avalanche. A second wave touched ALGO, TIA, ATOM and the privacy coin Zcash.
- 03:05 UTC+8: Bitget’s reconciliation system spotted the anomaly and automatically blocked all user withdrawals.
- 03:14 UTC+8: a top-level emergency response began. Before the wallets were fully frozen, a second round of seven transfers added roughly $28 million.
The total drained from hot and warm wallets: about $388 million. The attacker then deleted traces after each transfer. No malware was used.
What the attackers stole
The biggest pieces of the theft came from a few large holdings. Here is the breakdown reported so far:
| Asset | Amount stolen | Can the issuer freeze it? |
|---|---|---|
| XRP | 102.93M XRP (about $157.5M) | No |
| Ether (ETH) | 31,890 ETH (about $85.8M) | No |
| USDT (Tether) | About $34.75M | Yes |
| USDC (Circle) | About $21.05M | Yes |
| USDT0 (cross-chain USDT) | About $19.67M | Yes, in principle |
| Others | BNB, AVAX, TRX, ZEC, 3,000 XAUt gold tokens | Mostly no |
The number grew from the first estimate of $351.6 million. Investigators later found stolen assets on the Zcash and TRON networks that the first count missed. Bitget says this is better accounting, not a second theft.
How did the attackers get in?
According to Bitget, the attacker exploited a vulnerability in a third-party security product used by the exchange. That flaw gave them genuine high-level internal credentials, a level of access normally reserved for the exchange’s own staff.
With those credentials, they wrote fake withdrawal commands directly into the wallet backend. The commands looked real enough to pass pre-execution risk checks, so Bitget’s own approval process signed the transfers with the real keys. It was not a vault break-in. It was forged paperwork, and the vault opened on its own. This is the same class of third-party software risk highlighted by recent crypto security incidents: the weakest link is often a vendor’s code, not the exchange’s own keys.
No private keys were stolen, and cold wallets were never touched. Bitget says the vulnerability is patched, insider involvement is preliminarily ruled out, and no further unauthorized transfers have been detected.
Bitcoin withdrawals are back: the full recovery timeline
Bitget began restoring withdrawals on September 28 at 8:00 a.m. UTC, starting with Bitcoin. The exchange is turning services back on network by network, running extra security checks on each one before it goes live.
The demand was immediate. By 9:00 a.m. UTC, Bitget had processed 9,585 Bitcoin withdrawals totaling about 4,098 BTC. CEO Gracy Chen addressed users and questions in a live AMA session the same day.
| Asset | Networks | Resumes |
|---|---|---|
| BTC | Bitcoin, BNB Smart Chain | Sept 28, 08:00 UTC |
| ETH | Ethereum, BSC, Arbitrum, Base, Optimism | Sept 29, 08:00 UTC |
| USDT | Ethereum, BSC, Solana, Tron | Sept 30, 08:00 UTC |
| All other assets, fiat, P2P | All | Oct 2 |
Are Bitget user funds safe?
Bitget says yes. The exchange states that customer account balances were not affected. Private keys were never compromised, and cold wallets stayed offline and untouched.
The exchange says its User Protection Fund will cover the full loss. The fund holds 5,500 BTC and was worth more than $464 million at the time of the attack. Bitget also says it will refill the fund to at least $300 million within a week, in publicly visible wallets so anyone can verify it.
There is also a recovery bounty: 5% of any frozen or returned funds goes to people whose direct help leads to a freeze or recovery. Some assets are already frozen through industry cooperation. Circle and Tether froze about $318,000 in stablecoins linked to the attacker’s addresses. NEAR Intents says its SHIELD system caught more than $50 million in attempted Bitget-linked flows and blocked most of them.
Independent firms Mandiant and SlowMist are running the forensic investigation. Bitget expects to publish a full security report this week.
A note of caution: most of the facts above come from Bitget’s own statements, and the independent investigation is still open. Exchange hacks are sadly not new in crypto; the WOO X hack, in which $14 million was stolen from users, is a recent reminder. Treat this story as developing until the independent forensic report lands.
Who was behind the Bitget hack?
The honest answer: nobody knows for sure yet. North Korea’s Lazarus group is the leading suspect, but that is not proven.
Blockchain investigator ZachXBT traced the stolen funds across bridges and mixers. He says Chinese illicit actors are laundering the money on behalf of the suspected North Korean attackers. In an unusual twist, he published evidence that some of these operators were openly asking for help with stalled swaps in public Discord and Telegram channels.
“BREAKING: Chinese illicit actors laundering funds from the $387M Bitget exploit on behalf of the alleged DPRK attackers are openly asking for support with orders in public Discord servers and Telegram channels of services they use.”
ZachXBT (@zachxbt) on X, September 28, 2026
CEO Gracy Chen said IP patterns and on-chain signatures are consistent with techniques used by DPRK-linked hacking groups. Blockchain intelligence firm Elliptic assesses the attack as highly likely to be North Korea linked. Bitget itself says the formal attribution process is still ongoing, and the exchange has described the attackers only as a sophisticated, state-backed group.
“Our security team has made initial progress in tracing the source. The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out.”
Gracy Chen (@GracyBitget), CEO of Bitget, on X, September 25, 2026
What Bitget users should do right now
If you hold funds on Bitget, do not wait for the full story. Take these steps today:
- Do a small test withdrawal first. Move a tiny amount and confirm it arrives before sending the rest.
- Move long-term holdings to self-custody. Withdraw coins you are not actively trading into a non-custodial wallet where you control the private keys.
- Only use official URLs. Type the exchange address yourself or use the official app. Do not click links from emails, DMs or ads.
- Ignore “recovery help” messages. Scammers always appear after a big hack. Bitget support will never DM you first or ask for your seed phrase.
- Turn on two-factor authentication on every crypto account, and use a fresh, strong password.
- Follow official channels only for updates: Bitget’s verified X account and its official announcements page.
Watch: the Bitget hack explained in plain English
Watch: Bitget CEO Gracy Chen walks through the attack
How to protect your crypto from the next exchange hack
Exchange hacks are not new, and this will not be the last one. The safest habit is simple: keep only your trading money on exchanges. Keep the rest in a wallet you control.
Start with a hardware wallet or a trusted non-custodial wallet. If you are new to self-custody, these beginner-friendly Bitcoin wallets walk you through the setup in simple steps.
For larger amounts, split your holdings across more than one wallet instead of trusting a single platform. Also consider decentralized wallet options that give you full control of your private keys.
Finally, check whether your exchange publishes monthly proof of reserves, and never keep more on any exchange than you can afford to lose.
Mistakes to avoid after a hack
Panic is the hacker’s best friend. Avoid these common errors:
- Do not panic sell. A hack on one exchange does not change what Bitcoin itself is. Selling in fear locks in losses.
- Never share your seed phrase. No real support team will ever ask for it. Wallet drainer scams surge after every big hack, and one wrong click can empty your wallet.
- Do not click links from “support” accounts. Fake accounts copy exchange logos and offer fake refunds. They only want your login details.
- Do not reuse passwords. If you used the same password anywhere else, change it now.
- Do not assume the story is over. The forensic report is due this week. Keep watching official updates before making big moves.
Bitget hack: frequently asked questions
How much was stolen from Bitget?
Bitget currently estimates that about $387.5 million, roughly $388 million, was moved to attacker-controlled addresses on September 24. The figure was revised up from an initial $351.6 million estimate after more affected transactions were found.
Have Bitget withdrawals resumed?
Yes. Bitcoin withdrawals resumed on September 28 at 08:00 UTC on the Bitcoin and BNB Smart Chain networks. ETH withdrawals were scheduled for September 29, USDT for September 30, and all remaining assets, fiat withdrawals and P2P for October 2.
Were Bitget’s private keys stolen?
Bitget says no. Its investigation has so far ruled out private-key compromise, and cold wallets were not affected. The attacker used stolen internal credentials, not keys.
Will Bitget customers lose their money?
Bitget says customer account balances are unaffected and its User Protection Fund, holding 5,500 BTC, will cover the full loss. The independent investigation is still open, so users should still withdraw funds they are not actively trading.
Was North Korea behind the Bitget hack?
That is not proven. Elliptic assesses the attack as highly likely to be linked to North Korea, and Bitget’s CEO said the techniques match DPRK-linked groups. Bitget says formal attribution is still ongoing.
Should I keep my funds on Bitget?
Bitget says funds are safe, but the safest practice after any exchange hack is to withdraw what you do not need for trading into a wallet you control. Only keep active trading balances on the exchange.
How do I move my Bitcoin to self-custody?
Withdraw from the exchange to your own wallet address, starting with a small test amount. Use a hardware wallet or a trusted non-custodial wallet, and write down your recovery phrase on paper kept somewhere safe.
The bottom line
The Bitget hack is a harsh reminder: an exchange account is an IOU, not a vault. The exchange says users are covered and withdrawals are coming back online. But the safest move is one you can make yourself.
Withdraw what you do not need for trading, and hold it in a wallet you control. For the latest on this story, follow our Bitcoin news coverage as the forensic report lands this week.


