Cryptocurrency exchange Bitget suspended withdrawals on 24 September 2026 after its security systems detected unauthorised transfers out of part of its hot wallet infrastructure at 18:31 UTC. In a security notice posted on her own X account, Bitget chief executive Gracy Chen initially put the estimated value of the affected funds at approximately US$351.6 million. A day later, Bitget revised that figure to approximately US$387.5 million, saying the first estimate had left out affected assets on Zcash and TRON and that the increase does not reflect any further unauthorised transfers.
Gracy said the exchange's cold wallets were untouched and that the damage stopped at part of the two online tiers, the hot and warm wallets, in a custody set-up that Bitget splits into three levels. Minutes after her first notice, the exchange's official account published its own statement, describing the transfers as involving a limited number of hot wallets. Both posts said deposits and trading continue normally, and customer account balances remain accurate.
Latest Timeline
- 26 September 2026, 04:10 UTC (12:10 SGT): Gracy said Bitget is taking a different approach from how Bybit handled similar incidents last year, citing this incident's spread across multiple blockchains and cryptocurrencies, and that she will host a live AMA at 07:30 UTC on 28 September, 30 minutes before withdrawals begin to resume.
- 26 September 2026, 03:57 UTC (11:57 SGT): Bitget's official account said withdrawals will resume in orderly phases. Its current schedule starts with BTC on the Bitcoin network on 28 September, followed by ETH (on Ethereum, BSC, Arbitrum, Base and Optimism) on 29 September, USDT (on Ethereum, BSC, Solana and TRON) on 30 September, and other tokens, fiat and P2P on 2 October, each at 08:00 UTC (16:00 SGT). It said the vulnerability had been identified and remediated, that withdrawals would resume once additional security checks were complete, and that users did not need to take any action.
- 25 September 2026, 14:53 UTC (22:53 SGT): Replying to a user on X, Gracy said an address raised by the user was a warm wallet wrongly tagged as cold. She repeated that cold wallets remain fully secure and that the breach was confined to a portion of the hot and warm wallet layers.
- 25 September 2026, 14:47 UTC (22:47 SGT): Bitget's official account and Gracy clarified that what Bitget will announce by 26 September, 04:00 UTC (12:00 SGT) is the confirmed status and timing of withdrawals.
- 25 September 2026, 14:03 UTC (22:03 SGT): In a thread on its official account, Bitget revised the loss to approximately US$387.5 million, up from US$351.6 million, after adding assets on Zcash and TRON, and published the main attacker-controlled receiving addresses. It also launched a Recovery Bounty Program paying 5% of funds successfully frozen, and 5% of funds successfully recovered, to eligible parties whose voluntary efforts directly bring that about, alongside a live tracing dashboard. A support centre update said it has identified the attack path and remediated the underlying vulnerability. Gracy repeated the figures in her 24 hour update at 14:11 UTC.
- 25 September 2026, 07:10 UTC (15:10 SGT): Bitget's official account said it is working with independent third party experts Mandiant and SlowMist on a full investigation. It said the self-custodial Bitget Wallet, which runs on separate infrastructure, was not affected.
- 25 September 2026, 05:43 UTC (13:43 SGT): Gracy summarised her livestream, naming affected assets and seven affected chains, with XRP the largest single chain loss, and saying a few blockchain foundations had frozen the attacker's addresses. She said that, based on IP behavioural patterns and on-chain signatures, the attack is consistent with techniques used by North Korea linked hacker groups, and that authorities have been notified.
- 25 September 2026, 03:10 UTC (11:10 SGT): Bitget's official account said its Protection Fund holds 5,500 BTC, approximately US$464 million at current prices, with all fund wallet addresses public and verifiable on-chain. It said losses from the hot wallet incident, once assessed, will be borne by the fund, that Bitget will replenish it, and that it will announce details and coverage terms separately. Separately, Bitget postponed the KCGI 2026 finale livestream it had scheduled for 25 September, citing its review of recent security matters.
- 25 September 2026, 00:43 UTC (08:43 SGT): In a written update on X, Gracy said Bitget's security team had made initial progress in tracing the source of the attack, which she said came through a compromised critical backend system within its wallet infrastructure. She said private key compromise has been ruled out, loss containment is confirmed, and no further unauthorised transfers are possible. The specific intrusion method is still under investigation. On withdrawals, she said she will announce a timeline once one is confirmed. Bitget posted a Chinese-language version a minute earlier.
- 24 September 2026, 23:30 UTC (25 September, 07:30 SGT): Bitget posted a withdrawal suspension notice in its support centre, confirming that withdrawals remain unavailable while deposits and trading continue, and repeating its commitment to hourly updates and an incident report within a day.
- 24 September 2026, 22:27 UTC (25 September, 06:27 SGT): Gracy went live on X to address the incident, after Bitget's official account announced the broadcast at 22:18 UTC.
- 24 September 2026, 21:39 UTC (25 September, 05:39 SGT): Bitget published the security notice in its support centre, with the same wording as Gracy's post on X.
Bitget's headline reassurance is that the loss is covered. Gracy's first notice, issued when the estimate stood at US$351.6 million, tied that claim to the size of the exchange's User Protection Fund.
"User funds are safe. The full amount of this loss falls within the coverage of Bitget's User Protection Fund, which currently holds over $464 million," by Gracy Chen of Bitget
What Bitget has confirmed so far
Gracy said responders began working on the incident within minutes, marked and reported the addresses linked to the transfers, and involved law enforcement agencies and blockchain analytics specialists. Bitget has since named Mandiant and SlowMist as the independent firms working on the investigation. The halt on withdrawals is framed as precautionary and will last until the exchange has finished its security checks. Shortly before the 04:00 UTC deadline it set for 26 September, Bitget published a phased restart schedule, beginning with bitcoin on 28 September and ending with other tokens, fiat and P2P on 2 October, and said withdrawals will resume once those checks are completed.
The initial statements declined to speculate on the attack vector. Gracy's written update at 00:43 UTC on 25 September went further, setting out a preliminary account of how the funds left the exchange.
"The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out. Private key compromise has been ruled out," by Gracy Chen of Bitget
In the same post, she said loss containment is confirmed and that no further unauthorised transfers are possible. Bitget's later support centre update said its security team has identified the attack path, including how the attacker bypassed existing security controls, and that the underlying vulnerability has been remediated. It has not yet published those details.
Why the wallet layers matter
Centralised exchanges typically split custody across tiers. Hot wallets stay connected so that customer withdrawals can be processed quickly, warm wallets act as a buffer that tops them up, and cold wallets hold the bulk of assets offline.
Gracy's preliminary account adds a further point. If the keys were not exposed but a compromised backend system pushed transfers through Bitget's own approval process, the weakness would sit in the controls around transaction approval rather than in key custody.
How crypto firms secure the assets they hold on behalf of clients is not a niche question for supervisors. The European Securities and Markets Authority (ESMA) has already put custody resilience at crypto-asset service providers under review, testing it against the operational resilience expectations of the Digital Operational Resilience Act (DORA) and the Markets in Crypto-Assets Regulation (MiCA). Incidents at this scale tend to sharpen that focus.
The protection fund test
Bitget says the fund holds 5,500 BTC, which it valued at approximately US$464 million on 25 September. At that figure, the revised loss would take up roughly 84% of the fund, leaving a margin of about US$76.5 million, though the dollar value of a bitcoin-denominated fund moves with the price. Bitget says it will replenish the fund, and Gracy has said the exchange holds over US$1 billion in its own assets on top of it.
A protection fund is only as reassuring as the transparency around how it is held and deployed. Assurances that user funds are safe are also becoming a familiar opening line in crypto incident disclosures. MANTRA used similar framing when it halted its chain in August, saying only two managed wallets were hit, while The Sandbox disabled bridging and isolated unbacked tokens after its own cross chain exploit. In each case, the first statement set the frame and the follow up disclosures determined how it was judged.
What compliance and risk teams should do now
For institutions and trading firms with balances on Bitget, the immediate, practical issue is access to funds. Under Bitget's schedule, no withdrawals restart before 28 September and other tokens, fiat and P2P remain unavailable until 2 October. Treasury and risk teams should map their balances against those dates, reassess any settlement obligations that assume funds can be moved off the exchange sooner, and document their exposure until their assets are released.
For other exchanges, payment firms and virtual asset service providers, the practical exposure sits with incoming funds. Bitget has now published the main attacker-controlled receiving addresses for EVM networks, the XRP Ledger, Zcash and TRON, along with a live tracing dashboard and an address feed that it says will be updated as funds move, and it is asking exchanges, stablecoin issuers, bridges and custodians to monitor them. Compliance teams should make sure those addresses flow quickly into their transaction monitoring and screening tools, and be ready to hold and escalate deposits that trace back to them rather than process them automatically.
Gracy closed her first notice with a commitment that sets the bar the exchange will now be measured against.
"Bitget has navigated multiple market cycles. We will not run from this. Every dollar and every decision will be accounted for, transparently and in full," by Gracy Chen of Bitget
Read Gracy Chen's full security notice on X and Bitget's latest incident update.
