Business 4 min read

Bitget Lost About $388 Million From Its Hot Wallets and Says Its Reserve Fund Will Pay

The exchange traces the break-in to a flaw in a third-party security product. Its CEO pointed to North Korea; its incident page will not speculate.

Eva Chin
Business & Chinese Culture Correspondent
Published 29 Sep 2026, 6:32 AM (SGT)
Share:
Rows of gold and silver coins stamped with cryptocurrency symbols Rows of gold and silver coins stamped with cryptocurrency symbols Photo by DS stories on Pexels
Advertisement

29 SEP 2026 — Cryptocurrency exchange Bitget put the loss from its 24 September hot-wallet theft at about US$388 million after revising the first estimate upward from US$351.6 million. It says customer balances will not absorb the loss; the exchange's reserve fund will cover it.

The chief executive has pointed to North Korean hackers. The company's own incident page says it will not speculate on who did it until the investigation is finished.

What happened

Bitget's security systems detected unauthorised transfers from some of its hot wallets at 18:31 UTC on 24 September, the exchange's first notice says. Hot wallets are connected to the internet so the exchange can process withdrawals quickly. Cold wallets hold most assets offline.

The attacker "exploited a vulnerability in a third-party security product to potentially obtain high-level internal credentials", Bitget's updated account of 27 September says, and then sent fraudulent withdrawal commands that bypassed its risk controls. The loss came from 12 wallet addresses across its hot and warm tiers. Bitget says its cold wallets were not touched.

What was taken

SecurityWeek reports the stolen assets included ether, XRP, BNB, AVAX and the stablecoins USDT and USDC, with XRP the largest single loss.

~US$388mRevised loss, up from the first estimate of US$351.6m
12Wallet addresses drained, all in hot and warm tiers
US$464m+User Protection Fund, which Bitget says covers the loss
28 Sept – 2 OctStaged restart of withdrawals, bitcoin first

Who pays

Bitget says customer balances are unaffected and that the loss falls within its User Protection Fund. The fund stood at more than US$464 million in the first notice. If the revised figure holds, that leaves a margin of roughly US$76 million.

Deposits and trading continued. Withdrawals were suspended and are being restored in stages. Bitcoin withdrawals resume from 08:00 UTC on 28 September, ether on the 29th, USDT on the 30th, and other tokens, fiat and peer-to-peer services on 2 October.

Advertisement

Who did it

Chief executive Gracy Chen said on X that the method was "highly consistent with known patterns of North Korean hacker organizations", citing network behaviour and blockchain analysis, SecurityWeek reports. No group was named.

The company's updated incident page takes a more cautious line: Bitget "will not speculate on attribution while the independent forensic investigation remains ongoing". Google's Mandiant and the blockchain security firm SlowMist are investigating.

The two positions are not contradictory. Similarity to known attack patterns is a lead. A forensic report is evidence. Until that report is finished, the CEO's statement is an early read from an interested party.

Recovery and the bounty

Some of the stolen assets have been frozen through co-operation across the industry, Bitget says. Some blockchain foundations also froze addresses linked to the attacker. The exchange is offering a recovery bounty of 5% of any amount frozen or returned.

The break-in account is the part other exchanges will want in detail: a flaw in a third-party security product led to internal credentials. Bitget has not named the product.

Advertisement
Eva Chin
Business & Chinese Culture Correspondent

Eva Chin covers business and commerce in Southeast Asia for RECATOOLS, alongside Chinese cultural practice and education.

View author profile → · Editorial policy

Corrections policy

Advertisement