BLOCKINSIDERLoading
Live
Block InsiderBLOCKINSIDER
NEWS
MARKETS
ORIGINALS
EMERGING TECH
RWA & DEFI
LEARN
TOOLS
ABOUT
Advertise with Block InsiderGet in touch
HomeSecurity & HacksBitget Turns to its $464M Safety Net After $351.6M Breach
Security & Hacks

Bitget Turns to its $464M Safety Net After $351.6M Breach

Bitget’s latest update turns a massive crypto hack into a broader security story, with seven networks affected, reserves under scrutiny and investigators probing an alleged backend authorization breach.

25 September 2026
Security & HacksMarkets
On this page
  • Key Insights
  • The Crypto Hack Involved Multiple Network Breach
  • Bitget’s $464M Fund Is Not the Whole Balance Sheet
  • The Investigation Has Moved Beyond the Wallets
  • Bitget Joins a Larger Security Wave
Bitget Turns to its $464M Safety Net After $351.6M Breach
Arnold Kirimi
Arnold Kirimi
Crypto Journalist
VIEW PROFILE
Share

Key Insights

  • Bitget’s $351.6M crypto hack spans seven networks, with XRP bearing the biggest single-chain hit as investigators trace the unauthorized transfers.
  • A $464M+ Protection Fund sits above the losses, while Bitget says it also holds more than $1B in company assets and keeps user funds 1:1 backed.
  • The investigation has shifted from a wallet theft to an alleged backend authorization compromise, with Bitget pointing to techniques associated with DPRK-linked hackers.

A crypto hack at Bitget is escalating as new details emerge from a multi-chain security incident involving a “hot wallet” with roughly $351.6 million in assets affected.

The exchange is now relying on a $464 million-plus protection fund as investigators follow where the money went.

The exchange reported the breach, which it described as occurring in a “hot wallet” after its security systems detected “unauthorized transfers” at 18:31 UTC on September 24, 2026.

Withdrawals were suspended, though deposits and trading were briefly allowed to continue. The most recent update provides more insight into the scope of the damage,.

Bitget CEO Gracy Chen noted that the crypto hack resulted in the conversion of stablecoins and ETH, as well as XRP, BNB, AVAX and several other altcoins.

The chains affected by the crypto hack included Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC and Base. XRP accounted for the largest single-chain loss.

The Crypto Hack Involved Multiple Network Breach

The breadth of the incident is best captured in the list of networks it impacted, which speaks to the overall scale of the crypto hack.

Bitget said all cold wallets across the affected networks were confirmed secure. That is important because the exchange uses separate wallet layers, with the original incident described as involving portions of its hot and warm wallet infrastructure.

Chen also clarified that Bitget Wallet was not part of the breach. The wallet product operates on infrastructure separate from Bitget Exchange, meaning the incident did not extend to those funds.

View tweet

The exchange has contacted foundations across the affected networks. Chen said some had already frozen addresses associated with the hacker.

That introduces another recovery mechanism beyond Bitget's own controls. Once suspicious addresses are identified, blockchain networks, exchanges and other ecosystem participants can potentially restrict movement of the assets.

Bitget’s $464M Fund Is Not the Whole Balance Sheet

The financial response is another part of the updated picture.

Bitget previously said its User Protection Fund held more than $464 million and was large enough to cover the full $351.6 million affected in the incident.

Chen has now disclosed more. Bitget holds more than $1 billion in its own assets in addition to the Protection Fund, while user funds are covered on a 1:1 basis.

That means the protection fund is not being presented as the company's only financial resource. The exchange is pointing to both the dedicated reserve and its wider balance sheet as evidence that it can absorb the reported loss. The crypto hack, however, remains an operational problem until withdrawals return.

Bitget said it is targeting a full restoration as soon as possible but declined to provide a specific window before one is confirmed. The exchange has said it will not commit to a timeline it cannot deliver.

The Investigation Has Moved Beyond the Wallets

In its initial statement, Bitget declined to speculate on the attack vector while the investigation continued. A later update cited by Gulf News attributed the incident to a compromise of a critical backend system inside the wallet infrastructure.

According to that account, the attacker spoofed transaction data and used the compromised system to trigger Bitget's authorization process.

The report said Bitget had ruled out a private-key compromise and determined that the unauthorized transfers had been contained.

View tweet

Chen's newer assessment also linked the attack's IP behavior and on-chain signatures to techniques associated with DPRK-linked hacker groups.

That remains an attribution from Bitget, rather than a final independent determination. The exchange said it had notified authorities and was cooperating with them internationally.

For a crypto hack of this scale, attribution matters because it changes the question from a simple wallet failure to a broader investigation into how access to transaction infrastructure was obtained.

Bitget Joins a Larger Security Wave

The incident also lands alongside several different security and legal cases in crypto.

On August 20, Block Insider reported that a hijacked Tornado Cash domain had been used in a phishing attack that cost one user 1,010 ETH. The case involved a fake frontend capturing withdrawal credentials rather than a direct exchange breach.

Bybit has taken the legal route after its $1.5 billion Ethereum theft. Block Insider reported that the exchange sued North Korea and the Lazarus Group and obtained a U.S. court order freezing identified stolen assets. Bybit said $48.4 million had been recovered and another $30.5 million frozen.

A separate dispute involves Binance affiliates and RedotPay. The affiliates are seeking $472.8 million, alleging that more than 470,000 users were diverted in breach of a commercial agreement. RedotPay has denied the allegations, and the case has yet to produce a final ruling.

How does this read?
Share

Comments · 0

Sign in to comment. Accounts coming soon.

No comments yet

Be the first to share your take when accounts launch.

Related reading

SECURITY & HACKS

1,000+ ETH Stolen Through Fake Tornado Cash Site After US Sanction

@aaryamann-shrivastava36d ago
SECURITY & HACKS

Crypto Investigator Flags Alleged $5M Scam Ring

@rizwan-ansari46d ago
CRYPTO

Whale Adds $400 Million in HYPE Ahead of Binance Listing

@chandan-gupta13h ago
Advertise with Block InsiderReach a crypto audience that is already reading.Get in touch
More from this desk
  • Block Adds Bitcoin Lightning to x402 for AI Agent Payments15h ago
  • Grayscale’s AI Compute ETF GCPU Targets Bitcoin Miners1d ago
  • Zcash Leads Rare Group of Altcoins Outperforming Bitcoin1d ago
  • UK Bank Trials Push Tokenization Into Mainstream Finance2d ago
Advertise with Block InsiderReach a crypto audience that is already reading.Get in touch
Block InsiderBLOCKINSIDER© 2026 Block Insider.
AboutThe InsidersAdvertiseSponsoredCareersTermsPrivacy