Bitget's security systems flagged unauthorised transfers from a limited number of hot wallets at 18:31 UTC on 24 September. In its own public statement the Singapore-based exchange put the loss at US$351.6 million from hot and warm wallets; chief executive Gracy Chen later told a town hall that the initial estimate was US$387.5 million, and blockchain security firms had initially seen more than US$175 million leave before larger tranches followed. Cold wallets and the overwhelming majority of platform assets were unaffected, customer balances remain accurate, and withdrawals are suspended pending a security review. Chen said the attacker compromised a critical backend system inside the wallet infrastructure, used it to spoof transaction data and triggered the authorisation process to move funds out, with the intrusion method still under investigation; assets taken include ETH, XRP, BNB, AVAX, USDT and USDC across Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC and Base. Mandiant and SlowMist are investigating, some chains have frozen attacker addresses, a US$464 million User Protection Fund will cover losses, and a recovery bounty pays platforms 5% to freeze attacker funds and 5% on recovery. Chen cited IP behaviour, on-chain signatures and behavioural patterns as consistent with North Korean groups.
| Attribute | Detail |
|---|---|
| Sector | Financial Services |
| Date | 2026-09-26 |
| Source | The Record |
| Reliability | Tier 2 |