T
iTokenly

Bitget (hot and warm wallet breach) hack — September 2026

Verified — 3 sourcesLast checked September 25, 2026

Incident facts

Date of incident
Target typeCentralised exchange
Loss$351,600,000Price at time of incident
MethodInfrastructure compromiseBitget says the attacker compromised a backend system inside its wallet infrastructure, used it to spoof transaction data and fed the forged transfers through the exchange's own authorisation process; it has ruled out a private-key compromise but has not yet said how the system was entered
ChainsMultiple chains, XRP Ledger, Ethereum, BNB Chain, Avalanche, Tron
Attributed toUnidentified. Bitget's chief executive said some IP addresses used in the attack closely matched VPN patterns associated with a North Korea-linked group, while stressing that the attackers' identity was not confirmedSuspected
OutcomeUnresolved

What happened

Bitget, a centralised exchange, lost about $351.6m from part of its hot and warm wallet infrastructure on 24 September 2026. Its systems flagged the unauthorised transfers at 18:31 UTC. Cold wallets were not touched. Bitget suspended withdrawals while keeping deposits and trading open, and says customer balances are unaffected because the loss falls within its User Protection Fund, which it puts at more than $464m, held as 5,500 BTC. Blockhead described it as the largest breach of a centralised exchange so far this year.

On 25 September chief executive Gracy Chen said the attacker had compromised a critical backend system in the wallet infrastructure, used it to spoof transaction data and triggered the exchange's own authorisation process to move the funds out. Private-key compromise has been ruled out, she said, and the loss is contained, with no further unauthorised transfers possible; how the system was entered is still under investigation. The distinction matters: the signing keys held, and the failure sat in the controls in front of them, which approved transfers fed to them by a system that should not have been trusted.

According to a breakdown by the on-chain tracker Lookonchain, reported by Blockhead, the stolen assets span nine tokens: 102.93 million XRP (about $157.5m), 31,890 ETH ($85.8m), roughly $75.5m in USDT, USDC and USDT0, 3,000 XAUt, 12,719 BNB, 821,012 AVAX and 20.59 million TRX. That comes to about $357m at 25 September prices, slightly above Bitget's own figure, which is the one recorded here. SlowMist tied the theft to eleven EVM addresses, seven XRP Ledger addresses and one Tron address, and reported the attacker converting EVM-chain assets into ETH.

No attribution has been published. In a livestream Chen said some IP addresses used in the attack closely matched VPN patterns associated with a North Korea-linked group, while stressing that this was not confirmed, and the on-chain investigator Specter linked the routing of the stolen XRP to funds from the July 2026 AFX Trade hack recorded elsewhere in this registry. Bitget has promised a full technical report and will not commit to a date for reopening withdrawals. The outcome is recorded as unresolved until withdrawals reopen and the protection-fund payout, which Bitget says will be made after assessment, is confirmed.

Law enforcement

Bitget says it has flagged the receiving addresses and notified law enforcement agencies and on-chain security firms

Sources

  1. CoinDeskSecondary · retrieved 2026-09-25
  2. BlockheadSecondary · retrieved 2026-09-25
  3. CryptoSlateSecondary · retrieved 2026-09-25

Changes to this entry

  • Recorded the morning after the incident, from Bitget's own figure of $351.6m; Lookonchain's asset breakdown at later prices, about $357m, is kept as the upper end. Provisional: Bitget has promised a full incident report, and the mechanism, the final figure and the outcome may all change when it appears.

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Bitget (hot and warm wallet breach) hack — September 2026", iTokenly, accessed 2026-09-25, https://itokenly.com/hacks/bitget-september-2026
https://itokenly.com/hacks/bitget-september-2026

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.