# Bitget Confirms Over $350 Million Crypto Theft in Major Hot Wallet Breach
**The exchange confirmed the attack on September 24, 2026, after on-chain analysts first raised the alarm.**
## What Happened?
Cryptocurrency exchange Bitget confirmed that more than $350 million in digital assets were stolen from its wallets in a coordinated exploit that unfolded on September 24, 2026. The company’s CEO, Gracy Chen, acknowledged the breach and reassured customers that funds held in cold storage — offline wallets not connected to the internet — remained untouched and fully secure.
Chen said the losses are entirely covered by Bitget’s User Protection Fund, which currently sits at over $464 million, a figure that has grown significantly since the exchange first established a $300 million fund in 2023.
## How the Attack Unfolded
The first red flag emerged when on-chain monitoring tools detected roughly $183 million in assets — spanning ETH, USDT, USDC, AVAX, BNB, and other tokens — flowing out of wallets publicly linked to Bitget and converging into a single newly created address within approximately one hour. The movement was spotted by blockchain analytics firms and independent researchers tracking suspicious exchange-related transfers.
The most striking detail was a single fresh wallet purchasing 7,111 ETH on the Arbitrum network in just six minutes. That wallet used $19.67 million in USDT0 — a cross-chain variant of Tether’s stablecoin — and routed the trade through decentralized exchange aggregators UniswapX and 1inch Fusion. The buyer willingly paid a premium of roughly 5% above the market price, a telltale sign of urgency typically associated with rapid fund extraction by a threat actor.
After the initial spike of activity, outflows from Bitget-labeled wallets ceased for at least twenty minutes, a pattern consistent with the exchange pausing withdrawals to contain the damage. Additional wallets tagged as belonging to Bitget continued sending ETH, AVAX, BNB, USDC, USDT, and XAUT — a token representing physical gold — to the same destination address, according to an on-chain researcher who first publicized the anomaly.
## Why Hot Wallets Are a Constant Target
Centralized exchanges like Bitget hold the majority of customer deposits in wallets they control. A small portion — known as hot wallets — stays online to facilitate fast withdrawals and everyday trading, while the bulk is moved to cold wallets kept offline for security. When hackers target an exchange, hot wallets are almost always the entry point, because they sit on internet-connected servers that present a larger attack surface.
Unlike traditional bank deposits backed by government insurance, cryptocurrency held on an exchange carries no such safety net. This is why the phrase “not your keys, not your coins” has become a foundational principle in the industry — users who keep their assets in self-custody retain full control, while those who leave funds on an exchange are relying entirely on the platform’s security posture.
## A Pattern Repeating Across the Industry
The Bitget incident is far from an isolated event. In February 2025, rival exchange Bybit suffered a $1.4 billion loss after attackers compromised a routine cold-wallet transfer by spoofing a signing interface — what remains the largest cryptocurrency theft ever recorded. Across the broader ecosystem, hackers and exploits drained a combined $2.72 billion from exchanges and decentralized protocols over the past year alone.
Despite growing investment in security infrastructure, including multi-signature requirements, real-time monitoring, and insurance reserves, attackers continue to find vulnerabilities that allow them to move large sums quickly and convert stolen assets into harder-to-trace digital assets.
## FAQ
**What are hot wallets and cold wallets?**
Hot wallets are cryptocurrency wallets connected to the internet, used by exchanges to process daily transactions and withdrawals quickly. Cold wallets are kept offline, disconnected from any network, and hold the majority of an exchange’s reserves in a more secure environment.
**What is a User Protection Fund?**
A User Protection Fund is a reserve pool maintained by a cryptocurrency exchange to compensate customers in the event of hacks, theft, or other unexpected losses. Bitget’s fund grew from an initial $300 million in 2023 to over $464 million by 2026.
**What tokens were stolen in the Bitget hack?**
On-chain data shows that ETH, USDT, USDC, AVAX, BNB, and XAUT (a gold-backed token) were among the assets moved from Bitget-labeled wallets during the incident.
**How do decentralized exchange aggregators like UniswapX and 1inch Fusion work?**
These platforms search multiple decentralized exchanges simultaneously to find the best prices for token swaps, executing trades directly on the blockchain without a middleman. They are often used by attackers because they allow rapid, permissionless conversion of stolen assets.
**Is my crypto safe on an exchange?**
While reputable exchanges invest heavily in security, no platform is immune to breaches. The safest approach for long-term holdings is to transfer assets to a self-custody wallet where you control the private keys.
**Has Bitget confirmed the hack?**
Yes. CEO Gracy Chen confirmed the unauthorized transfer from hot wallets and stated that the full loss will be covered by the company’s User Protection Fund.
## Conclusion
The Bitget hack underscores the persistent risks that centralized cryptocurrency exchanges face, even as the industry matures and security practices evolve. With over $350 million siphoned through hot wallets in a matter of minutes, the incident serves as a stark reminder that the convenience of custodial services comes with inherent trust requirements. As on-chain forensics become faster and more transparent, attackers are forced to move with increasing speed — reflected in the inflated fees paid to execute rapid swaps. For users, the event reinforces the importance of understanding where their assets are held and considering self-custody options for long-term storage.
Thank you for reading



