Security Incident Brief
⚠ VERIFIED SECURITY INCIDENT

Bitget Confirms
Wallet Security Incident

The platform confirmed unauthorized transfers from some hot and warm wallets. For on-chain asset holders, the priority is to separate facts from rumors, control risk, and beware of follow-up scams.

Illustration of affected hot and warm wallet layers separated from an isolated cold-storage vault
Editorial illustration — hot and warm wallet layers remain operationally different from isolated cold storage.
MAIN REPORT · COINDESK

Bitget says $351.6 million was affected in wallet-system breach

4 MIN READ
Reported Sep 24–25, 2026Read the original report ↗

CoinDesk reported that Bitget lost approximately $351.6 million after attackers reached part of the exchange’s wallet infrastructure. According to CEO Gracy Chen, the incident affected hot and warm wallet layers, while the exchange’s offline cold wallets remained isolated.

The first public estimates were lower. Independent blockchain researchers initially identified unusual movements of roughly $178 million to $183 million across several chains. The larger figure was disclosed after Bitget assessed the broader exposure, illustrating how early on-chain estimates can change as an exchange completes internal accounting.

Backend compromise, not stolen private keys

In a follow-up account reported by CoinDesk, Chen said attackers compromised a critical backend system, fabricated transaction data and caused Bitget’s authorization process to approve transfers. She said a direct private-key compromise had been ruled out. That distinction matters because stolen signing keys can enable repeated transfers until credentials are rotated, while a compromised approval system points to a different containment and remediation process.

Bitget temporarily paused withdrawals while deposits and trading remained available. The company said its protection fund—reported at more than $464 million—would cover the loss and that account balances remained accurate. Those statements are assurances from the exchange and should be evaluated alongside withdrawal restoration, proof-of-reserves information and the promised technical incident report.

What remained under review

The exchange later said the underlying vulnerability had been identified and remediated, and that no further unauthorized transfers were possible. Even so, users still needed clarity on the full intrusion path, the amount recovered or frozen, the restoration of withdrawals and the final changes made to security controls.

CoinDesk’s report combines Bitget’s statements with independent on-chain observations. Figures and conclusions may evolve as investigators publish additional evidence.

SOURCE EXCERPTS

Comments, claims & updates

3 SOURCES

The quoted figures reflect different moments in a developing incident. Later official findings should take precedence over early estimates.

LATEST VERIFIED STATUSCONTAINED

Attack path identified; underlying vulnerability remediated

Bitget says no further unauthorized transfers are possible. Cold wallets remained isolated, while restoration and recovery work continued across the affected hot and warm wallet layers.

Amount assessed by Bitget$351.6MLoss coverage and recovery remain subject to final verification

Known Facts & Open Questions

SWIPE TO VIEW
CONFIRMEDCONFIRMED

Unauthorized transfers occurred

At 02:31 Beijing time on Sep 25, unauthorized transfers were detected from several hot and warm wallets.

CONFIRMEDCONFIRMED

Withdrawals temporarily paused

The platform says deposits and trading remain available; withdrawals will resume after security checks.

ONGOINGVERIFYING

Recovery and final accounting

The final recovered amount, complete technical report, and long-term control changes still require independent verification.

BITGET OFFICIAL STATEMENT
“We will not speculate on the attack method before the investigation reaches a conclusion.”
— Bitget Security Notice, Sep 25, 2026

Incident Timeline

UTC+8

Security systems detected abnormal transfersEmergency response initiated

Suspicious addresses flagged and reportedLaw enforcement and on-chain security firms engaged

Attack path identified and vulnerability remediatedRecovery, validation and final reporting continue

⚠ SECONDARY RISK ALERTPHISHING

Phishing scams often appear immediately after a security incident

Beware of DMs, group messages, or fake sites urging “emergency asset migration,” “compensation registration,” or “account verification.”

Never share seed phrases or private keysNever transfer to a so-called safe addressDo not install remote-control softwareDo not open compensation links in DMs

What do you check first after a security incident?

This page summarizes Bitget’s official security notice. Claims about cold-wallet safety and protection-fund coverage should be evaluated alongside the final incident report and subsequent execution.

View Bitget official notice ↗