# A $387 Million Crypto Heist: Unraveling the Bitget Exchange Breach
**The largest cryptocurrency exchange breach of 2026 has left the industry shaken, as Bitget confirmed the loss of $387.5 million in digital assets following a sophisticated attack on September 24. The incident has raised urgent questions about exchange security, backend vulnerability, and the growing boldness of state-sponsored cybercriminals.**
—
## The Day Everything Unraveled
On the evening of September 24, Bitget’s internal security monitoring systems flagged suspicious activity at 18:31 UTC. The unauthorized transfers targeted portions of the exchange’s hot and warm wallets — the infrastructure responsible for facilitating day-to-day trading and customer withdrawals. Fortunately, the company’s offline cold wallets, which store the majority of user funds in isolation from internet-connected systems, remained untouched.
Despite detecting the anomaly within minutes, the severity of the breach was not fully understood immediately. The first public signs emerged less than two hours later, when a blockchain analyst flagged a wallet draining $19.67 million in stablecoins to purchase nearly 7,200 ETH in a six-minute window — paying up to 5% above market prices in a clear urgency to move assets before anyone could intervene.
By the time Bitget’s CEO Gracy Chen issued a formal security notice around 21:30 UTC, approximately $351.6 million had already been moved. The notice confirmed that all withdrawal operations would be suspended indefinitely as the company worked to contain the damage.
Over the following hours, the final tally climbed to $387.5 million after Bitget completed a full inventory of affected assets, which included Zcash and TRON tokens in addition to the more widely traded cryptocurrencies.
## How Attackers Turned Bitget’s Own Systems Against It
The most startling revelation came days after the breach, when Chen disclosed that the attackers had compromised a critical backend system — the unseen software infrastructure that manages wallet operations and transaction processing.
Rather than stealing private keys or breaching encrypted databases, the attackers injected false transaction data directly into Bitget’s authorization pipeline. The exchange’s own systems, designed to verify and approve legitimate transfers, were deceived into processing fraudulent withdrawals. This method effectively made the hack feel like a series of approved, routine transactions from Bitget’s perspective.
Chen confirmed that private-key theft was not the attack vector, though the company has not yet disclosed exactly how the backend was breached or which specific security controls failed to catch the manipulation.
## The Investigation Underway
Two of the world’s leading blockchain forensics firms — Mandiant and SlowMist — have been retained to investigate the breach. Their work is expected to trace the movement of stolen funds across blockchains and identify the identities behind the wallets used to receive the assets.
Chen has publicly suggested that North Korean threat actors may be responsible, citing patterns in IP addresses and on-chain behavior that resemble a well-documented February 2025 attack on the Bybit exchange. The FBI later attributed the Bybit theft to North Korean state-sponsored hackers, and investigators have noted eerie similarities between the two incidents.
Key parallels that have drawn scrutiny include the use of manipulated transaction approvals to bypass security checks, the rapid conversion of stolen assets into ether and other major cryptocurrencies, the fragmentation of funds across numerous receiving wallets, and the use of the THORChain cross-chain protocol to launder and move assets — a technique that experts believe was also used in the earlier Bybit incident.
However, investigators have cautioned that shared tactics alone do not conclusively identify the perpetrators, and a thorough forensic analysis is still underway.
## The Road Ahead for Bitget
In the days following the incident, Bitget announced that the vulnerability exploited in the breach had been patched. The company promised to release a detailed withdrawal plan by September 26 at 04:00 UTC, though it stopped short of confirming when — or even whether — withdrawals would resume.
The lingering uncertainty has been difficult for users, many of whom have been unable to access or move their funds for days. Meanwhile, industry observers and regulators are watching closely, raising calls for strengthened security standards across cryptocurrency exchanges.
—
## Frequently Asked Questions (FAQ)
**Q: What was the total amount stolen in the Bitget hack?**
A: Bitget ultimately confirmed that $387.5 million in digital assets were stolen from its exchange wallets during the attack on September 24, 2026. The figure was revised upward after the company accounted for Zcash and TRON tokens in addition to initially reported assets.
**Q: How did the attackers gain access to Bitget’s wallets?**
A: According to CEO Gracy Chen, the attackers compromised a critical backend system responsible for processing wallet transactions. They fed false transaction data into Bitget’s authorization process, causing the exchange’s own systems to approve fraudulent transfers. Private-key theft was ruled out as the attack method.
**Q: Were Bitget’s cold wallets affected?**
A: No. Bitget stated that its offline cold wallets, which are not connected to the internet and are considered the most secure storage method, remained completely unaffected by the breach.
**Q: Who is investigating the Bitget hack?**
A: Two leading blockchain security and forensics firms — Mandiant and SlowMist — are conducting a full investigation into the incident. They are tracing on-chain activity and analyzing the attack’s technical details.
**Q: Are North Korean hackers responsible for the attack?**
A: CEO Gracy Chen has publicly suggested that the attack bears characteristics consistent with North Korean threat actor groups, pointing to similarities with the February 2025 Bybit theft. However, investigators have emphasized that a definitive attribution has not yet been made, and further forensic work remains ongoing.
**Q: Has Bitget resumed withdrawals?**
A: No. Withdrawals remained suspended as of the latest available information. Bitget indicated a withdrawal plan would be announced by September 26 at 04:00 UTC, but did not commit to resuming withdrawals at that time.
**Q: What protections does Bitget offer affected users?**
A: Bitget has stated that its protection fund covers the full amount of the loss. The company is working to address the impact on users while security operations and investigations continue.
—
## Conclusion
The Bitget hack of September 2026 stands as one of the most significant security incidents in the cryptocurrency industry, not only for the sheer scale of the financial loss but also for the cleverness of the attack method. By compromising backend systems and turning an exchange’s own authorization processes into weapons, the attackers demonstrated a level of sophistication that challenges traditional exchange security models.
The investigation by Mandiant, SlowMist, and potentially government agencies will be critical in understanding exactly how the breach occurred, who is responsible, and how such exploits can be prevented in the future. For Bitget’s users, the situation remains uncertain, with withdrawal delays and a lengthy recovery process ahead.
The incident also serves as a broader reminder to the cryptocurrency industry: as exchanges handle billions in digital assets, the stakes of robust security infrastructure, rigorous auditing, and transparent incident response have never been higher.
Thank you for reading.



