Bitget has confirmed a $387.5 million crypto heist involving unauthorized transfers from its hot and warm wallets. The cryptocurrency exchange says the underlying vulnerability has been identified and remediated, the incident is contained, and Bitcoin withdrawals resumed on September 28, 2026.
What happened in the Bitget crypto heist
Bitget detected unauthorized transfers from a limited number of hot wallets at 18:31 UTC on September 24. The exchange initially estimated that approximately $351.6 million in assets had been affected and temporarily suspended withdrawals while its security team investigated the incident.
On September 25, Bitget raised the confirmed total to approximately $387.5 million after additional on-chain tracing and transaction classification. The company said the revised amount included assets on Zcash and TRON that were not part of the initial estimate. Bitget stated that the increase did not represent new unauthorized transfers.
The confirmed affected assets include XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX, and TRX across Ethereum and several EVM networks, XRP Ledger, Zcash, and TRON.
What Bitget has confirmed
Bitget says its security team identified the attack path and the method used to bypass existing security controls. The company has not publicly disclosed the full technical details of the exploited vulnerability, but it says the flaw has been remediated and no further unauthorized transfers are possible.
The exchange says its cold wallets remained secure and the breach was limited to part of its hot and warm wallet infrastructure. Bitget also says customer account balances remain accurate and that its User Protection Fund will cover the financial impact of the platform incident.
Independent cybersecurity firms Mandiant and SlowMist are supporting the investigation, according to Bitget. The exchange has also launched a recovery bounty program and says some affected assets have already been frozen through coordination with industry partners.
Bitcoin withdrawals restored after security checks
Bitget began restoring withdrawals in phases after additional validation of its withdrawal infrastructure. Bitcoin withdrawals were scheduled to resume at 08:00 UTC on September 28 and have now been restored, according to current reporting.
The published restoration schedule calls for ETH withdrawals on supported networks to resume September 29 at 08:00 UTC, followed by USDT withdrawals on September 30 at 08:00 UTC. Bitget plans to begin restoring other tokens, fiat withdrawals, and peer-to-peer services on October 2.
Trading and deposits remained available during the withdrawal pause. Bitget says users do not need to take action before services return and should rely on the platform and its official channels for availability updates.
What remains unverified
Bitget CEO Gracy Chen attributed the attack to North Korean hackers based on on-chain analysis and observed IP behavior. That attribution has not been independently confirmed by a government agency in the public disclosures reviewed for this report.
The investigation remains ongoing, and Bitget says its figures may change as more transactions are classified and traced. The company has not released a complete technical post-incident report, so the precise vulnerability and the full sequence of the intrusion are not yet public.
Who is affected
The confirmed financial loss affected Bitget’s platform wallet infrastructure rather than customer cold wallets. Bitget maintains that users’ account balances are unaffected and protected by its fund, but customers temporarily lost access to withdrawals while the exchange completed security checks.
Businesses that use Bitget for treasury activity, payments, or cryptocurrency trading should review operational dependencies created by the withdrawal suspension. Even when balances are reimbursed, a platform outage can interrupt access to working capital and delay time-sensitive transfers.
Why the incident matters
The scale of the confirmed loss makes this one of the most significant cryptocurrency security incidents of 2026. It also demonstrates the concentration of risk in exchange-controlled hot wallets, which must remain connected to systems capable of rapidly authorizing transfers.
For customers, the incident is a reminder that an account balance shown by an exchange is not the same as direct control over assets in a private wallet. Businesses should balance liquidity needs against custody risk and avoid keeping more operating funds on any single platform than necessary.
Practical defensive actions
- Use only official Bitget channels: Attackers frequently exploit major incidents with fake recovery notices, support accounts, and withdrawal links. Navigate directly to the official app or website.
- Reject unsolicited recovery offers: Do not share seed phrases, private keys, authentication codes, or remote-access control with anyone claiming they can accelerate withdrawals or recover funds.
- Review account activity: Check recent logins, API-key use, withdrawal addresses, and security notifications for activity that does not match authorized use.
- Strengthen authentication: Use a unique password, phishing-resistant multi-factor authentication where supported, and withdrawal address allowlists.
- Review API credentials: Businesses using trading bots or integrations should confirm that API keys have the minimum required permissions and rotate credentials if suspicious activity is found.
- Reduce custody concentration: Consider separating long-term holdings from exchange operating balances and using multiple approved custody options for business continuity.
- Document exposure: Organizations should record balances, pending transactions, access interruptions, and any related financial impact while the investigation continues.