Bitget says its cold wallets stayed secure. Its private keys were not stolen. Yet attackers still managed to move approximately $351.6 million.
That is the part of the Bitget hack that deserves more attention than the number alone.
The September 24 breach is already one of the largest reported crypto exchange security incidents of 2026. Bitget temporarily suspended withdrawals after detecting unauthorized transfers from portions of its hot and warm wallet infrastructure, while deposits and trading remained operational.
But according to Bitget CEO Gracy Chen, this was not the classic story of hackers obtaining private keys and simply emptying wallets.
The attackers allegedly penetrated a critical backend system connected to Bitget’s wallet infrastructure, manipulated transaction data, and caused the exchange’s own authorization machinery to approve transfers that should never have been approved.
The vault keys, in other words, may have remained secure while the system deciding who was allowed to open the door failed.
That distinction turns the Bitget hack into something more important than another exchange-loss headline.
It raises a much broader question:
How safe is a crypto exchange when its cryptography works but the infrastructure surrounding that cryptography can still be deceived?
What Happened in the Bitget Hack?
Bitget said its security systems detected unauthorized transfers at 18:31 UTC on September 24, 2026.
The exchange activated emergency procedures and later estimated that approximately $351.6 million in digital assets had been affected.
According to Bitget’s official security notice, the breach was limited to portions of its hot and warm wallet infrastructure.
Bitget said its cold wallets were not compromised.
The exchange responded by:
- temporarily suspending withdrawals;
- flagging addresses associated with the unauthorized transfers;
- contacting law enforcement;
- bringing in blockchain-security and cybersecurity specialists;
- keeping deposits and trading operational; and
- beginning a broader security review before reopening withdrawals.
Bitget has said the loss is contained and that no further unauthorized transfers should be possible from the compromised path.
However, the precise method used by the attacker to enter the backend system remained under investigation when this article was prepared.
Why Was This Not a Normal Private-Key Hack?
Private keys are normally the center of a crypto theft story.
If an attacker obtains the private key controlling a wallet, the attacker can generally authorize blockchain transactions from that wallet.
Bitget says that is not what happened here.
Chen said the investigation had ruled out a compromise of the relevant wallet private keys.
Instead, an attacker allegedly gained access to a backend component within Bitget’s wallet infrastructure and used that access to create or manipulate transaction information.
Those instructions then passed through Bitget’s authorization process.
This distinction matters because it exposes a different security layer.
| Security Layer | What It Protects | What Can Still Go Wrong |
|---|---|---|
| Private Keys | Authorization of blockchain transactions | Keys can be stolen, exposed, copied, or misused |
| Hot and Warm Wallet Systems | Operational movement of exchange assets | Connected infrastructure can be attacked |
| Backend Systems | Transaction creation and processing | False or manipulated instructions may enter workflows |
| Authorization Controls | Determines which transfers should proceed | A compromised system may make fraudulent transfers look legitimate |
| Monitoring Systems | Detects unusual activity | Detection may occur only after transactions begin moving |
This is why The Crypto Encounter has repeatedly argued that cold storage alone does not make an exchange safe.
Cold storage can reduce exposure to online private-key theft.
It cannot automatically protect every server, authorization process, employee workflow, database, transaction engine, API, wallet-management service, or security-control layer surrounding those keys.
How Could Hackers Move $351.6 Million Without Stealing the Keys?
The easiest way to understand the alleged attack is to separate signing authority from the information being presented for authorization.
Imagine a bank vault whose key remains secure.
Now imagine that an attacker compromises the system that tells the bank’s payment department which transfers have been approved.
The attacker does not need to steal the physical vault key if the bank’s own machinery can be persuaded to send money to the wrong destination.
Crypto exchange wallet infrastructure can contain a similar chain of systems.
A withdrawal or treasury transfer may involve:
- a transaction request;
- risk and compliance checks;
- internal authorization;
- transaction construction;
- signing infrastructure;
- broadcasting to the blockchain; and
- post-transaction monitoring.
If malicious transaction data enters that chain and successfully clears the internal approval process, cryptographic signing can still work exactly as designed.
The problem is that it may be signing the wrong transaction.
This is a crucial difference between technical security and system safety, something The Crypto Encounter examines in Crypto Can Be Secure Without Being Safe.
A blockchain can correctly process a transaction that should never have been authorized in the first place.
What Was Stolen From Bitget?
The attack affected assets across several blockchain networks.
On-chain tracker Lookonchain estimated that the stolen assets included more than 102.9 million XRP, 31,890 ETH, tens of millions of dollars in USDT and USDC, BNB, AVAX, TRX, USDT0 and Tether Gold.
The valuations changed with market prices while investigators were tracing the transactions, which explains why external estimates have sometimes differed slightly from Bitget’s official $351.6 million figure.
The largest identified individual component was XRP.
| Asset | Reported Amount | Approximate Value at Tracking Snapshot |
|---|---|---|
| XRP | 102.93 million XRP | About $157.5 million |
| ETH | 31,890 ETH | About $85.8 million |
| USDT | About 34.75 million USDT | About $34.75 million |
| USDC | About 21.06 million USDC | About $21.06 million |
| USDT0 | About 19.67 million | About $19.67 million |
Those figures should be treated as on-chain estimates rather than Bitget’s final forensic accounting.
Lookonchain also reported that much of the stolen value on Ethereum-compatible networks was converted into approximately 67,982 ETH, worth around $183 million at the time it was tracked.
That conversion behavior matters because attackers often try to consolidate multiple assets into more liquid cryptocurrencies before beginning more complicated laundering routes.
Why Is the Stolen XRP So Important?
The XRP portion creates an unusual recovery problem.
More than 102.9 million XRP was traced to attacker-controlled addresses.
Unlike certain issued tokens, native XRP cannot simply be frozen at the blockchain level.
The official XRP Ledger documentation states that freeze functionality applies to issued tokens, not native XRP.
That does not mean the stolen XRP is impossible to track or recover.
If the attacker tries to send XRP through a centralized exchange, that exchange can potentially identify and restrict the relevant account.
Bridges and other centralized infrastructure may also become intervention points.
But there is no protocol-level switch that allows Bitget, Ripple or another organization to simply freeze native XRP sitting in an independent blockchain address.
This is one of the tensions created by decentralized assets.
The same property that protects legitimate holders from arbitrary protocol-level seizure can complicate theft recovery.
Are Bitget User Funds Safe?
Bitget says customer account balances remain intact and that users will not absorb the reported loss.
That is an important commitment.
It should also be interpreted precisely.
At the time this article was prepared, withdrawals remained suspended under the latest official information available.
So there are two different questions:
| Question | Current Answer |
|---|---|
| Does Bitget say customer balances are protected? | Yes |
| Can customers currently withdraw normally? | Not under the latest public incident notice |
This distinction is exactly why an exchange balance is not the same as direct control of crypto.
A balance can remain visible and economically recognized while practical access is temporarily restricted.
That does not mean the balance has disappeared.
It does mean another institution controls the route between the number displayed in the account and the blockchain transfer needed to move the asset elsewhere.
What Does Bitget’s $464 Million Protection Fund Actually Mean?
Bitget says the full $351.6 million loss falls within its User Protection Fund, which the exchange valued at more than $464 million when announcing the incident.
At those stated valuations, the fund was approximately 1.32 times the size of the reported loss.
That represents roughly $112 million more than the estimated value affected by the hack.
But there is an important detail.
Bitget’s Protection Fund is supported by 5,500 BTC.
That means its dollar value is not fixed.
When Bitcoin rises, the fund becomes more valuable in dollar terms.
When Bitcoin falls, its dollar valuation declines.
The Protection Fund therefore should not be confused with a conventional fixed-dollar government deposit guarantee.
Nor is a protection fund the same thing as proving that every operational security layer worked correctly.
The exchange’s response may protect customers financially after an incident while the breach itself still exposes weaknesses that need to be fixed.
This is also why regulated does not mean risk-free. Regulation, reserves, insurance arrangements and protection funds can reduce certain consequences without making an institution impossible to hack or disrupt.
Why Are Bitget Withdrawals Still Suspended?
Pausing withdrawals after an exchange breach can be frustrating for users, but it also serves an obvious security purpose.
If an exchange has not fully identified how an attacker entered its systems, reopening withdrawals too quickly could expose additional assets.
Bitget has said multiple teams are reviewing and hardening its systems before withdrawal services return.
The exchange has avoided giving a reopening time that it cannot guarantee.
That is preferable to announcing a deadline before investigators know whether all affected infrastructure has been secured.
But the suspension also demonstrates the custody trade-off described in The Crypto Encounter’s analysis of the hidden cost of crypto exchange convenience.
Centralized exchanges make trading easier because they manage infrastructure for customers.
The other side of that convenience is that the exchange can halt access when its systems enter emergency mode.
Was Bitget Wallet Also Hacked?
Bitget says its separate self-custodial Bitget Wallet product was not affected.
The company has said Bitget Wallet operates on infrastructure separate from Bitget Exchange.
That distinction matters because the names can easily cause confusion.
A centralized exchange account and a self-custodial wallet may appear inside products carrying the same brand, but their security models are different.
In self-custody, the user normally controls the keys.
On a centralized exchange, the platform manages custody and transaction infrastructure.
Neither model eliminates risk. They move responsibility to different places.
Our analysis of what actually sits behind a crypto app balance explains why the interface alone cannot tell users which risks they are taking.
Is North Korea Behind the Bitget Hack?
Possibly, but it has not been established as fact.
Chen said investigators had identified IP addresses whose VPN usage patterns resembled infrastructure associated with a North Korean hacking group.
She also said parts of the behavior looked similar to previous attacks attributed to North Korean operators.
Some blockchain investigators have pointed to additional transaction patterns that they believe could support that hypothesis.
However, attribution remains preliminary.
Bitget has not publicly established the attackers’ identities through a completed forensic report, and similarities in VPN infrastructure or laundering behavior are not sufficient on their own to prove who controlled the operation.
That caution is especially important because “North Korean hackers” can quickly become the headline before the forensic evidence is complete.
There is nevertheless a strong historical reason investigators are examining the possibility.
Chainalysis estimated that North Korean-linked hackers stole approximately $2.02 billion in cryptocurrency during 2025.
The enormous $1.5 billion Bybit breach accounted for a substantial portion of that total.
If a DPRK-linked group is eventually confirmed behind Bitget, it would continue a pattern in which attackers increasingly target the operational infrastructure and human systems surrounding large crypto businesses rather than trying to break blockchain cryptography itself.
Why Does the Bitget Hack Matter Even if Customers Get Repaid?
Because reimbursement solves one problem.
It does not erase the security lesson.
If Bitget covers the entire loss, customers may ultimately avoid losing the affected value.
But $351.6 million still left infrastructure that was supposed to prevent unauthorized transfers.
That raises questions about:
- backend system isolation;
- transaction validation;
- authorization architecture;
- internal trust assumptions;
- hot wallet exposure;
- real-time anomaly detection;
- transaction-size limits;
- multi-party approval systems; and
- the amount of value accessible through operational wallets.
The important question is not merely whether an exchange can absorb a hack.
It is whether the security architecture can prevent the next one.
That is why crypto exchange risk extends beyond custody alone.
Operational controls, liquidity, infrastructure, regulation and withdrawal mechanisms all become part of the user’s risk exposure once assets enter a centralized platform.
What Should Bitget Users Do Now?
The first priority is verification.
Major hacks create an ideal environment for secondary scams.
Attackers know users are anxious about withdrawals and asset recovery. That makes fake support messages, fraudulent recovery links, Telegram impersonators, phishing emails and “move your funds to this safe wallet” scams especially dangerous after a widely reported exchange incident.
Users should obtain updates directly from Bitget’s official website and verified communication channels rather than links sent through unsolicited messages.
Never provide:
- a wallet recovery phrase;
- a private key;
- two-factor authentication codes;
- remote access to a device; or
- crypto to an address supposedly required to “unlock” or “protect” an exchange balance.
The Crypto Encounter’s crypto safety checklist provides a broader framework for handling wallet, exchange and phishing risks.
Users should also expect impersonation attempts to become more convincing as AI tools improve. Our investigation into why AI scam bots do not sleep explains how automated fraud can exploit exactly this kind of high-anxiety event.
What Should Crypto Exchanges Learn From the Bitget Hack?
One lesson is already clear.
“Our private keys were not compromised” is important, but it cannot be the end of the security conversation.
An exchange security model has to protect the complete path from transaction creation to blockchain settlement.
That means asking whether:
- transaction data can be altered before signing;
- authorization systems independently verify destinations and amounts;
- large transfers require separate approval channels;
- hot wallet exposure is tightly capped;
- backend systems are segmented;
- privileged access is continuously monitored;
- signing systems verify intent rather than blindly trust upstream data; and
- unusual transfer patterns can stop transactions before substantial value leaves the platform.
The difference is subtle but fundamental.
A secure key tells you who signed.
A secure system also has to determine whether the transaction should have existed at all.
The Crypto Encounter View: The Vault Can Stay Locked While the Payment System Fails
The cryptocurrency industry has spent years teaching users one security lesson above almost every other:
Protect the private keys.
That advice remains correct.
But the Bitget incident shows why it is incomplete for centralized institutions.
A large crypto exchange is not simply a collection of wallets.
It is a financial operating system.
Assets move through servers, databases, approval engines, risk controls, employee permissions, APIs, wallet-management systems and blockchain signing infrastructure.
The cryptographic keys can remain untouched while another part of that machine produces a catastrophic result.
That is why the most important sentence in the Bitget story may not be “$351.6 million was stolen.”
It may be:
The private keys were not compromised.
If Bitget’s preliminary findings are confirmed, attackers found a way around the vault rather than through it.
That is a harder security problem because it cannot be solved simply by moving more assets into cold storage.
It requires exchanges to protect the logic that decides when money is allowed to move.
And for users, it reinforces the lesson behind judging crypto platforms by what happens behind the interface, not merely by what the balance screen looks like when everything is working normally.
Frequently Asked Questions About the Bitget Hack
How Much Was Stolen in the Bitget Hack?
Bitget estimates that approximately $351.6 million in digital assets was affected by unauthorized transfers on September 24, 2026. External on-chain estimates have varied slightly because asset prices and tracked addresses changed during the investigation.
Were Bitget’s Private Keys Stolen?
Bitget says no. CEO Gracy Chen said investigators had ruled out private-key compromise. The preliminary explanation is that attackers compromised a backend system, spoofed transaction data and triggered Bitget’s authorization process.
Were Bitget’s Cold Wallets Hacked?
Bitget says its cold wallets remained secure. The breach affected portions of the exchange’s hot and warm wallet infrastructure.
Are Bitget Withdrawals Working Again?
Under the latest official incident information available when this article was prepared, withdrawals remained temporarily suspended while Bitget conducted additional security checks. Deposits and trading remained operational.
Will Bitget Users Lose Money From the Hack?
Bitget says users will not bear the loss and that its User Protection Fund is sufficient to cover the approximately $351.6 million affected. The exchange valued the fund at more than $464 million when it announced the incident.
What Is the Bitget Protection Fund?
The Bitget Protection Fund is an additional reserve established to help protect users during extreme incidents. Bitget says it is supported by 5,500 BTC. Because the fund is Bitcoin-denominated, its U.S. dollar valuation changes with the price of Bitcoin.
Was XRP Stolen in the Bitget Hack?
Yes. On-chain analysts tracked approximately 102.9 million XRP linked to the incident, worth roughly $157 million at the relevant market snapshot.
Can the Stolen XRP Be Frozen?
Native XRP cannot be frozen directly on the XRP Ledger. However, centralized exchanges can freeze accounts or assets held within their own systems if stolen XRP reaches them, creating potential intervention points.
Was North Korea Responsible for the Bitget Hack?
That has not been confirmed. Bitget’s CEO said preliminary technical indicators, including certain IP and VPN patterns, showed similarities to previous North Korean-linked operations. Attribution remains under investigation.
Was the Lazarus Group Behind the Attack?
Some researchers and publishers have discussed a possible Lazarus or DPRK-linked connection, but Bitget has not publicly confirmed that Lazarus Group carried out the attack. The identity of the attacker should therefore remain described as suspected or under investigation.
Was Bitget Wallet Affected?
Bitget says its self-custodial Bitget Wallet product was not affected because it operates on infrastructure separate from Bitget Exchange.
Should Users Trust an Exchange Because It Uses Cold Storage?
Cold storage is an important security measure, but it protects only part of the system. Exchange users remain exposed to operational, backend, authorization, liquidity, custody and withdrawal risks that cold storage alone cannot eliminate.
What Should Bitget Users Watch Next?
The most important developments are the restoration of withdrawals, Bitget’s detailed technical incident report, confirmation of the intrusion method, information about recovered assets, any final attacker attribution, and evidence of the security changes implemented before normal withdrawal operations resume.
Disclaimer
This article is for informational and educational purposes only. It does not constitute financial, investment, legal, cybersecurity or trading advice. Information about the Bitget incident continues to develop, and forensic conclusions, recovered amounts, attacker attribution and service status may change as the investigation progresses. Readers should verify current information through official Bitget communications and other reliable primary sources before taking action.