29 SEP 2026 — Cryptocurrency exchange Bitget put the loss from its 24 September hot-wallet theft at about US$388 million after revising the first estimate upward from US$351.6 million. It says customer balances will not absorb the loss; the exchange's reserve fund will cover it.
The chief executive has pointed to North Korean hackers. The company's own incident page says it will not speculate on who did it until the investigation is finished.
What happened
Bitget's security systems detected unauthorised transfers from some of its hot wallets at 18:31 UTC on 24 September, the exchange's first notice says. Hot wallets are connected to the internet so the exchange can process withdrawals quickly. Cold wallets hold most assets offline.
The attacker "exploited a vulnerability in a third-party security product to potentially obtain high-level internal credentials", Bitget's updated account of 27 September says, and then sent fraudulent withdrawal commands that bypassed its risk controls. The loss came from 12 wallet addresses across its hot and warm tiers. Bitget says its cold wallets were not touched.
What was taken
SecurityWeek reports the stolen assets included ether, XRP, BNB, AVAX and the stablecoins USDT and USDC, with XRP the largest single loss.
Who pays
Bitget says customer balances are unaffected and that the loss falls within its User Protection Fund. The fund stood at more than US$464 million in the first notice. If the revised figure holds, that leaves a margin of roughly US$76 million.
Deposits and trading continued. Withdrawals were suspended and are being restored in stages. Bitcoin withdrawals resume from 08:00 UTC on 28 September, ether on the 29th, USDT on the 30th, and other tokens, fiat and peer-to-peer services on 2 October.
Who did it
Chief executive Gracy Chen said on X that the method was "highly consistent with known patterns of North Korean hacker organizations", citing network behaviour and blockchain analysis, SecurityWeek reports. No group was named.
The company's updated incident page takes a more cautious line: Bitget "will not speculate on attribution while the independent forensic investigation remains ongoing". Google's Mandiant and the blockchain security firm SlowMist are investigating.
The two positions are not contradictory. Similarity to known attack patterns is a lead. A forensic report is evidence. Until that report is finished, the CEO's statement is an early read from an interested party.
Recovery and the bounty
Some of the stolen assets have been frozen through co-operation across the industry, Bitget says. Some blockchain foundations also froze addresses linked to the attacker. The exchange is offering a recovery bounty of 5% of any amount frozen or returned.
The break-in account is the part other exchanges will want in detail: a flaw in a third-party security product led to internal credentials. Bitget has not named the product.