A test transaction of 0.84 ETH at 18:31 UTC was the first sign . Three hours later, Bitget confirmed it had lost roughly a third of a billion dollars and shut the exit doors on every customer.
What Happened: Bitget Confirms $351.6M Stolen, Freezes All Withdrawals
Bitget, one of the largest centralized crypto exchanges, confirmed on September 24, 2026 that attackers drained approximately $351.6 million from its hot and warm wallet infrastructure and suspended all customer withdrawals pending a security review . By confirmed dollar loss, it is possibly the single largest crypto exchange hack of 2026 .
Quick Answer: Bitget confirmed attackers stole about $351.6 million from its hot and warm wallets on September 24, 2026, and froze withdrawals for every customer. That confirmed figure is nearly double the roughly $192 million on-chain trackers had independently calculated before disclosure — an unusual direction for such a gap.
The disclosure timeline is tight but not instant. Bitget's systems detected unauthorized transfers at 18:31 UTC; CEO and founder Gracy Chen published the formal security notice on X at roughly 21:30 UTC, about three hours later .
"Our security team activated emergency response protocols immediately," said Gracy Chen, CEO and founder of Bitget, in the exchange's security notice (source: TFTC, 2026-09).
What the attackers took spanned at least seven tokens across multiple chains:
- Assets drained: ETH, BNB, AVAX, USDT, USDT0, USDC, and the gold-backed XAUT .
- Concentration: In Bubblemaps' pre-confirmation tracking, Ethereum accounted for 44.4% of the roughly $192 million it had traced, spread across 15 separate transfers from hot and warm wallets .
- Service status: withdrawals halted platform-wide — including for users whose balances were never touched — while deposits and spot and derivatives trading stayed live .
Chen said cold wallets remain fully secure and that the breach touched only part of the hot and warm layers of Bitget's three-tier wallet architecture. No independent forensic confirmation of that claim has been published, and the exchange declined to name an attack vector until its investigation closes .
Why the Confirmed Number Is Nearly Double What Trackers First Found
The confirmed loss is roughly twice what independent on-chain trackers measured in real time. Blockchain security researchers — including an Arkham analyst, PeckShield, and Hacken — put early outflows at about $174–183 million consolidated into a single address within the first hour , and Bubblemaps independently calculated around $192 million drained across networks before Bitget spoke .
Bitget's own $351.6 million figure is therefore 1.8–2.0x the highest pre-confirmation external estimate . That direction is the unusual part. Exchanges historically under-report losses, not over-report them, so a self-disclosed number well above what trackers could see is a gap analysts have flagged rather than resolved.
| Source | Loss estimate | Timing / scope |
|---|---|---|
| Security researchers (Arkham, PeckShield, Hacken) | ~$174–183M | First hour, single consolidated address |
| Bubblemaps | ~$192M | Cross-network, pre-statement; 15 transfers, Ethereum 44.4% of tracked value |
| Bitget (official) | $351.6M | Hot and warm wallet infrastructure |
Part of the visibility gap is explained by how fast the attacker moved. A freshly created wallet swapped roughly $19.67 million of USDT0 into 7,111 ETH in about six minutes on Arbitrum, routing through UniswapX and 1inch Fusion and accepting up to 5% above market price .
Paying a 5% premium is not sloppy execution — it is the cost of outrunning a freeze. Tether and Circle can blacklist addresses holding their stablecoins, so the practical read for traders is:
- Issuer-freezable assets (USDT, USDT0, USDC) must be converted before an issuer acts, which forces slippage-tolerant routing.
- Non-freezable assets like ETH are the destination, which is why Ethereum dominated the stolen value mix.
- Aggregator routing across chains fragments outflows, so single-address trackers undercount totals early.
The exploiter address was identified as 0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee, with funds later dispersed to 0x469Ac1406dE92f82C0563477240a3627057425DC . Until Bitget publishes a transfer-level breakdown, the $160M-plus difference between tracked and declared losses stays unexplained .
Why It Matters: A Platform-Wide Freeze Turns One Wallet Breach Into Counterparty Risk for Everyone
A hot-wallet breach became an exchange-wide solvency question the moment Bitget suspended withdrawals for every user, not just those whose balances were touched . Deposits and spot and derivatives trading kept running, so users can still add funds and take positions — they simply cannot exit the venue . That asymmetry is the practical definition of counterparty risk.
Three things remain unverified, and each one widens the gap between the company's account and what outsiders can check:
- Cold-wallet integrity. CEO Gracy Chen says cold wallets "remain fully secure" under a three-tier architecture, with the breach confined to part of the hot and warm layers . No independent forensic confirmation of that claim has been published .
- Attack vector. Still undisclosed. Chen said the company will not speculate until the investigation concludes . Without it, no one can rule out a repeat.
- Restoration date. Withdrawals return "as soon as the security review is complete" — an open-ended condition, not a timestamp .
The sector backdrop sharpens the point. September 2026 crypto losses now exceed $684 million once Bitget is added, surpassing April's $646.9 million as the year's costliest month on a gross-loss basis . The $320 million Liquid Network breach earlier in the month contributed most of the rest, though those attackers claimed white-hat intent . Bitget's case has no such caveat.
Does the $464M User Protection Fund Actually Cover the Hole?
Bitget's stated backstop is larger than the loss, but only on paper. CEO Gracy Chen said the exchange's User Protection Fund holds more than $464 million and that "the full amount of this loss falls within the coverage of Bitget's User Protection Fund," with user account balances unchanged . Against the confirmed $351.6 million, that is a self-reported coverage ratio of roughly 132% .
Read the other way, the loss consumes about 76% of the fund's declared value . That leaves roughly $112 million of headroom — thin if the forensic accounting revises outflows upward again, as it already did once.
"Every dollar and every decision will be accounted for, transparently and in full," — Gracy Chen, CEO at Bitget (source: Gracy Chen on X, 2026-09)
The pledge is not yet verifiable. The fund's composition has never been independently audited, and TFTC flagged three questions Bitget has not answered:
- What is in it. Whether the $464 million is stablecoins, BGB, or illiquid holdings that would need to be sold into a falling market.
- Is it liquid. A fund that cannot be converted within days does not resolve a withdrawal freeze.
- Is it segregated. Whether the assets are genuinely ring-fenced from operating capital, or accounted for as part of it.
Bitget has also not said whether the fund will be deployed immediately or held back while it attempts to freeze and recover the stolen assets . Those are different promises: one makes users whole now, the other makes them wait on a recovery effort with no stated deadline.
What to Watch Next: The Two Checkpoints That Will Confirm or Break the Story
Two concrete checkpoints will settle whether Bitget's account holds. The first is the full incident report Bitget pledged to publish within 24 hours of disclosure, including root-cause analysis and corrective measures . The second is the withdrawal-restoration date, which the exchange has tied only to the completion of an open-ended security review .
What traders should track, in order of information value:
- The 24-hour report — does it name an attack vector, or repeat that the company "will not speculate" ?
- Withdrawal resumption — full, or tiered by asset and user segment.
- Law-enforcement acknowledgement — no agency had publicly confirmed Bitget's report at the time of writing .
- Third-party proof of reserves covering the protection fund's composition.
Price action says the market has already scoped the problem. BGB fell roughly 5% at the peak of the selloff before paring to between -2.49% and -2.9% , while Bitcoin slipped 0.29% and Ethereum 0.2% over 24 hours . That is a solvency question priced to one venue, not contagion.
The takeaway is binary and short-dated: either the incident report lands with a named vector and withdrawals reopen, or the disclosure gap widens — and a widening gap, not the $351.6 million itself, is what would reprice counterparty risk on Bitget.
Frequently asked questions
How much did Bitget lose in the September 2026 hack?
Bitget confirmed roughly $351.6 million drained from its hot and warm wallet layers on September 24, 2026, a figure most outlets round to $352 million . The stolen balance spanned at least seven assets across multiple chains — ETH, BNB, AVAX, USDT, USDT0, USDC and the gold-backed XAUT . Bubblemaps' pre-confirmation tracking of the roughly $192 million it could see had already found 15 separate transfers, with Ethereum accounting for 44.4% of that traced value .
Why did initial reports estimate a much smaller loss than Bitget confirmed?
Early numbers came from real-time on-chain tracking, not a completed wallet reconciliation. Blockchain security researchers — including an Arkham analyst, PeckShield, and Hacken — put outflows at roughly $174–183 million to a single address within the first hour , and Bubblemaps independently calculated about $192 million across networks . Bitget's internal figure arrived afterward and is nearly double the highest external estimate — a discrepancy that runs opposite to the usual direction, since exchanges have historically disclosed less than trackers found, not more.
Are Bitget withdrawals still frozen?
Yes, as of the latest available reporting. Bitget suspended withdrawals for every user, including accounts whose balances were untouched, and said they "will be restored as soon as the security review is complete" . Deposits and spot and derivatives trading continued to operate throughout . No restoration date has been published.
Is my money safe if I have funds on Bitget?
Bitget says yes; that claim is not yet independently verified. CEO Gracy Chen stated cold wallets "remain fully secure" under a three-tier wallet architecture and that the loss falls fully within a User Protection Fund holding more than $464 million . What remains unconfirmed is what assets make up that fund, whether they are liquid, and whether they are genuinely segregated from operating capital. Until withdrawals reopen, balances shown in an account are a statement, not a settlement.
Is this the biggest crypto hack of 2026?
By confirmed dollar value, yes — the $351.6 million loss exceeds every other reported 2026 incident, including the roughly $320 million Liquid Network breach earlier in September, whose attackers claimed white-hat intent . Adding Bitget pushes September's reported crypto losses above $684 million, making it the costliest month of the year on a gross-loss basis and surpassing April's $646.9 million .
Enjoyed this article? Subscribe to get new stories by email whenever they're published.