Security & Hacks
Bitget Turns to its $464M Safety Net After $351.6M Breach
Bitget’s latest update turns a massive crypto hack into a broader security story, with seven networks affected, reserves under scrutiny and investigators probing an alleged backend authorization breach.

Key Insights
- Bitget’s $351.6M crypto hack spans seven networks, with XRP bearing the biggest single-chain hit as investigators trace the unauthorized transfers.
- A $464M+ Protection Fund sits above the losses, while Bitget says it also holds more than $1B in company assets and keeps user funds 1:1 backed.
- The investigation has shifted from a wallet theft to an alleged backend authorization compromise, with Bitget pointing to techniques associated with DPRK-linked hackers.
A crypto hack at Bitget is escalating as new details emerge from a multi-chain security incident involving a “hot wallet” with roughly $351.6 million in assets affected.
The exchange is now relying on a $464 million-plus protection fund as investigators follow where the money went.
The exchange reported the breach, which it described as occurring in a “hot wallet” after its security systems detected “unauthorized transfers” at 18:31 UTC on September 24, 2026.
Withdrawals were suspended, though deposits and trading were briefly allowed to continue. The most recent update provides more insight into the scope of the damage,.
Bitget CEO Gracy Chen noted that the crypto hack resulted in the conversion of stablecoins and ETH, as well as XRP, BNB, AVAX and several other altcoins.
The chains affected by the crypto hack included Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC and Base. XRP accounted for the largest single-chain loss.
The Crypto Hack Involved Multiple Network Breach
The breadth of the incident is best captured in the list of networks it impacted, which speaks to the overall scale of the crypto hack.
Bitget said all cold wallets across the affected networks were confirmed secure. That is important because the exchange uses separate wallet layers, with the original incident described as involving portions of its hot and warm wallet infrastructure.
Chen also clarified that Bitget Wallet was not part of the breach. The wallet product operates on infrastructure separate from Bitget Exchange, meaning the incident did not extend to those funds.
The exchange has contacted foundations across the affected networks. Chen said some had already frozen addresses associated with the hacker.
That introduces another recovery mechanism beyond Bitget's own controls. Once suspicious addresses are identified, blockchain networks, exchanges and other ecosystem participants can potentially restrict movement of the assets.
Bitget’s $464M Fund Is Not the Whole Balance Sheet
The financial response is another part of the updated picture.
Bitget previously said its User Protection Fund held more than $464 million and was large enough to cover the full $351.6 million affected in the incident.
Chen has now disclosed more. Bitget holds more than $1 billion in its own assets in addition to the Protection Fund, while user funds are covered on a 1:1 basis.
That means the protection fund is not being presented as the company's only financial resource. The exchange is pointing to both the dedicated reserve and its wider balance sheet as evidence that it can absorb the reported loss. The crypto hack, however, remains an operational problem until withdrawals return.
Bitget said it is targeting a full restoration as soon as possible but declined to provide a specific window before one is confirmed. The exchange has said it will not commit to a timeline it cannot deliver.
The Investigation Has Moved Beyond the Wallets
In its initial statement, Bitget declined to speculate on the attack vector while the investigation continued. A later update cited by Gulf News attributed the incident to a compromise of a critical backend system inside the wallet infrastructure.
According to that account, the attacker spoofed transaction data and used the compromised system to trigger Bitget's authorization process.
The report said Bitget had ruled out a private-key compromise and determined that the unauthorized transfers had been contained.
Chen's newer assessment also linked the attack's IP behavior and on-chain signatures to techniques associated with DPRK-linked hacker groups.
That remains an attribution from Bitget, rather than a final independent determination. The exchange said it had notified authorities and was cooperating with them internationally.
For a crypto hack of this scale, attribution matters because it changes the question from a simple wallet failure to a broader investigation into how access to transaction infrastructure was obtained.
Bitget Joins a Larger Security Wave
The incident also lands alongside several different security and legal cases in crypto.
On August 20, Block Insider reported that a hijacked Tornado Cash domain had been used in a phishing attack that cost one user 1,010 ETH. The case involved a fake frontend capturing withdrawal credentials rather than a direct exchange breach.
Bybit has taken the legal route after its $1.5 billion Ethereum theft. Block Insider reported that the exchange sued North Korea and the Lazarus Group and obtained a U.S. court order freezing identified stolen assets. Bybit said $48.4 million had been recovered and another $30.5 million frozen.
A separate dispute involves Binance affiliates and RedotPay. The affiliates are seeking $472.8 million, alleging that more than 470,000 users were diverted in breach of a commercial agreement. RedotPay has denied the allegations, and the case has yet to produce a final ruling.
How does this read?
Comments · 0
Sign in to comment. Accounts coming soon.
No comments yet
Be the first to share your take when accounts launch.



