Bitget's $351.6M Hot Wallet Breach Covered by Its Bitcoin (BTC) Fund

Bitget revised its hack losses to $387.5M, covered by a $464M fund holding 5,500 BTC. CEO Gracy Chen cites a backend breach, not leaked private keys.

(01:07 PM UTC)
4 min read
AI SummaryAI
  • Bitget detected unauthorized hot wallet transfers worth $351.6M on September 24, 2026.
  • Bitget suspended crypto withdrawals as a precaution while its security review continues.
  • Revised hack loss estimate reached $387.5M after counting Zcash and TRON transfers.
  • CEO Gracy Chen said private keys were not leaked; backend systems were compromised.
k7rq2fdm

Hot Wallet Breach Triggers Withdrawal Freeze

Bitget detected unauthorized transfers out of a portion of its hot wallets at 18:31 UTC on September 24, 2026, and the exchange's official security notice put the estimated impact at approximately $351.6 million. Per the exchange's own incident announcement, the damage extended from the hot wallet tier into parts of the warm wallet layer, while cold wallets — where keys are held fully offline — were untouched. Bitget runs a three-tier wallet architecture that separates always-online hot wallets, intermediate warm wallets and offline cold storage, so a single compromised system cannot expose the platform's full reserves at once.

Emergency response teams identified and flagged the attacker addresses, and the exchange contacted law enforcement along with on-chain security firms. While the review runs, crypto withdrawals have been suspended under a separate withdrawal suspension notice; deposits are processing with delays, and Bitget Onchain transactions are temporarily disabled pending a security review. Spot trading has so far continued uninterrupted.

The exchange insists customer balances remain accurate and fully covered, and two facts anchor that claim. First, cold storage was not affected. Second, the user protection fund stood above $464 million when the incident hit — larger than the $351.6 million estimated loss. The fund, created in 2022, is composed of 5,500 BTC and is managed under a policy of keeping its valuation above $300 million; its August 2026 monthly average valuation was $382 million. That makes it function closer to a self-funded DeFi insurance backstop than a statutory deposit guarantee: coverage exists, but the dollar value of a BTC-denominated fund fluctuates with Bitcoin's price, and claims are adjudicated case by case. Bitget had also published its September proof of reserves on September 17, showing a 135% aggregate reserve ratio across 19 assets — a separate mechanism from the fund. As of September 25, no timetable for restoring withdrawals had been published.

Loss Revised to $387.5M

The loss figure itself then moved. On September 25, Bitget revised the affected amount from roughly $351.6 million to approximately $387.5 million. The exchange stated the increase came from supplementary accounting of transfers across Zcash and TRON — not a new theft — and that some stolen assets had already been frozen with help from industry partners. Blockchain analytics firm Elliptic assessed the same day that the attack was “highly likely” connected to North Korea, citing overlaps between the routed funds and laundering addresses used in earlier DPRK-linked thefts. That remains an analytical attribution; Bitget's full technical incident report has not yet been released.

Chief executive Gracy Chen addressed the attack vector in public statements on September 25: private keys were not leaked, but a critical backend system inside the wallet infrastructure was compromised. Attackers, she explained, fabricated transaction data to trick the exchange's internal approval process into authorizing outbound transfers — smuggling fake instructions through the legitimate signing workflow rather than stealing the vault key outright. She said additional unauthorized transfers had been stopped, while the precise method of intrusion into the backend remains under investigation.

The laundering question is where the Bybit precedent matters. After Bybit lost roughly $1.5 billion in February 2025 — an attack the FBI attributed to North Korea — security researchers documented how more than $1 billion of the haul was laundered between February and June 2025 through chain-hopping, token swaps and mixers, with about $200 million routed through the no-KYC service eXch. Some traceable funds reached Tron, were converted to USDT, and were cashed out via over-the-counter desks handling on-chain payments. Because native Bitcoin and the Ethereum network have no central issuer able to freeze balances, recovery typically requires a compliant platform, an issuer with freeze capability, or law enforcement seizure — the US Department of Justice, for instance, seized over 15 million USDT tied to earlier DPRK platform thefts. Readers tracking the market in real time can follow live spot and futures prices on Bitget.

Post-Mortem Is the Real Test

Our reading of the record: the on-chain evidence is already the strongest lever here. Attacker addresses have been flagged publicly, the drained sums are verifiable on-chain, and partial freezes have been executed through industry coordination — none of that waits on Bitget's report. The post-mortem, though, is what validates the root cause: the CEO's interim account points to a backend compromise via spoofed approvals, not a key leak, and the promised full incident report must confirm exactly how the approval workflow was tricked and what remediation follows. Bitget's $464 million BTC-denominated fund absorbing a $387.5 million hole — minus whatever stays frozen — is the number that will decide whether this remains a contained incident.

COINOTAG News Desk

COINOTAG News Desk

COINOTAG's editorial and research desk.

How our News Desk works
AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.