Bitget has confirmed unauthorised transfers affecting roughly $351.6 million across part of its hot and warm wallet infrastructure. Withdrawals were paused while the exchange carried out a security review. Customer balances remain accurate according to Bitget, but the incident is a sharp reminder that an exchange balance and assets held under your own keys carry different risks.
The short version
- Bitget detected abnormal transfers at 18:31 UTC on 24 September 2026.
- The exchange's preliminary estimate puts affected assets at approximately $351.6 million.
- Bitget says its cold wallets were not affected.
- Deposits and trading remained available, while withdrawals were temporarily paused.
- Bitget says its User Protection Fund, valued above $464 million, covers the reported loss.
- The attack vector has not yet been established publicly.
What happened at Bitget
At 18:31 UTC on 24 September, Bitget's monitoring systems identified transfers that the exchange says were not authorised. The company activated its incident response process, flagged destination addresses and contacted law-enforcement agencies and on-chain security firms.
Bitget's initial assessment places the value of affected assets at about $351.6 million. Early third-party estimates were lower because they covered only part of the visible activity. Later reconstructions included additional networks and XRP Ledger transfers, bringing outside estimates much closer to the exchange's figure.
The exchange says the incident was contained to part of its hot and warm wallet layers. Its cold wallets were not affected, account balances continued to display correctly, and deposits and trading remained operational. Withdrawals were suspended while the security review proceeded.
What is confirmed and what is still unknown
| Question | Current position |
|---|---|
| Were unauthorised transfers detected? | Yes. Bitget has confirmed them publicly. |
| How much was affected? | Approximately $351.6 million under Bitget's preliminary estimate. |
| Were cold wallets breached? | Bitget says no. |
| Are customer balances intact? | The exchange says balances are accurate and the protection fund covers the loss. |
| How did the attacker gain access? | No final technical finding has been published. |
| When will withdrawals fully resume? | Bitget says they will return after the security review, without a confirmed timetable at the time of writing. |
On-chain data can show where assets moved, but it cannot by itself explain how an attacker obtained authority to create or sign the transactions. Claims about the root cause should therefore be treated as unverified until Bitget publishes its technical report and independent evidence can be assessed.
Why withdrawals were paused
A withdrawal halt is a containment measure. Once abnormal transfers appear, an exchange needs to isolate affected wallets, review signing permissions, rotate relevant keys and test replacement withdrawal paths before reopening them. The pause does not mean every customer account was compromised.
It does, however, expose a practical feature of exchange custody: access depends on the platform. A balance can remain visible and fully credited while the owner is temporarily unable to move it. That is counterparty and availability risk, separate from crypto market volatility.
What the protection fund does and does not prove
Bitget says its User Protection Fund is worth more than $464 million, exceeding the current $351.6 million loss estimate. That provides a potential financial buffer and may reduce the risk of customers bearing the loss directly.
The fund is not a substitute for a full post-incident account. Users still need clarity on the final loss, how the fund will be used, when withdrawals will return, what failed and what controls have changed. Coverage matters, but so do transparent remediation and proof that the vulnerable path has been closed.
What Bitget users should do now
- Use official channels only. Open Bitget's website or app directly. Do not trust private messages offering a special withdrawal link.
- Never share passwords, 2FA codes or a seed phrase. Major incidents attract impersonators posing as support staff.
- Preserve account records. Save balances, deposit and withdrawal history, login alerts and any unfamiliar activity.
- Review account security. Use an authenticator app or security key, enable an anti-phishing code and remove unknown logged-in devices.
- Wait for verified updates. Some wallet movements can be part of containment or asset recovery. Do not treat every large transaction as a fresh theft without supporting evidence.
A common follow-on scam
- No legitimate support agent needs your seed phrase.
- Do not install remote-control software for someone claiming to restore withdrawals.
- Do not pay a release fee to “unlock” an exchange balance.
- Type the official website address yourself before checking any update.
The self-custody lesson
Exchanges are useful for buying, selling and converting assets. They do not have to hold an entire long-term portfolio. One practical approach is to keep only the amount needed for trading on an exchange and move longer-term savings to a hardware wallet that you set up yourself.
Self-custody does not eliminate risk; it changes who carries it. The owner must secure the seed phrase, verify transaction details on the device and maintain a recovery plan. Moving assets in a panic can be dangerous if the user has not tested the destination address, network and backup process first.
Hardware wallets for long-term holdings
These devices take different approaches to screens, connectivity and recovery. Choose the workflow you understand and can maintain, rather than selecting by coin count or price alone.
Frequently asked questions
How much was taken from Bitget?
Bitget's preliminary estimate is approximately $351.6 million. The final figure may change after the investigation and asset reconciliation are complete.
Did customers lose their balances?
Bitget says account balances remain accurate and its protection fund covers the reported loss. Users should still follow the official incident report and withdrawal status.
Why can trading continue while withdrawals are paused?
Withdrawals require the exchange's wallet and signing infrastructure. Internal trading can operate separately, allowing Bitget to stop outbound transfers while reviewing the affected systems.
Should everyone withdraw as soon as the service returns?
There is no universal answer. Decide how much capital genuinely needs to remain available for trading. If you choose self-custody, secure the backup and test a small transfer before moving a larger balance.
Would a hardware wallet prevent this type of incident?
A hardware wallet removes reliance on an exchange for custody of those assets. It does not protect against a leaked seed phrase, a wrong network or an unsafe transaction approval.
Conclusion
The confirmed facts are serious: Bitget reported unauthorised transfers worth about $351.6 million and paused withdrawals. The exchange says the incident affected only part of its hot and warm wallet layers, cold wallets stayed secure and its protection fund can absorb the loss. The technical cause remains unresolved publicly.
For users, the immediate priorities are avoiding impersonation scams, following verified updates and reviewing how much long-term capital should remain on any single exchange. Diversifying custody and learning self-custody carefully are more useful than making rushed decisions in response to a headline.
Updated 25 September 2026. This article is provided for security education and does not constitute investment advice or an assurance of any service provider's financial position.
Sources checked: Bitget's official security notice, Forbes and Cointelegraph's incident reporting.






Share:
Hardware Wallet Brands Around the World: Compare 15 Brands Before You Buy