Bitget reports $400 million theft, withdrawals paused
Bitget reports $400 million theft, withdrawals paused
Bitget announced an unauthorized transfer of nearly $400 million, paused withdrawals and initiated an investigation into the incident.
How the breach occurred
On 24.09.2026 at 18:31 UTC the exchange detected unexpected outbound transfers from its hot wallet infrastructure. The company states that its cold wallets were not compromised and that the attacker induced Bitget’s internal systems to sign fraudulent withdrawal requests, which were then executed.
Attribution and investigation
Bitget’s CEO, Gracy Chen, reported that IP behavior and on-chain indicators resemble techniques previously associated with North Korean hacking groups. Independent blockchain analyst Elliptic also assesses a high probability of a DPRK link, while Bitget has engaged cybersecurity firms Mandiant and SlowMist to assist the investigation.
Funds and customer balances
According to the exchange, user account balances remain intact and the losses will be covered by the platform’s User Protection Fund, which exceeded $464 million prior to the incident. Bitget said withdrawals will be resumed in phases to restore normal access.
- 28.09.2026 — BTC withdrawals
- 29.09.2026 — ETH withdrawals
- 30.09.2026 — USDT withdrawals
- 02.10.2026 — remaining tokens, fiat and P2P
Operational status
Bitget reports that trading and deposits continue to operate while the vulnerability has been closed and forensic work is underway. The exchange committed to updating users as the review proceeds and recovery steps are completed.
Related posts

