The crypto exchange Bitget suffered a major hack on Thursday, September 24, 2026 at 18:31 UTC (or Friday, September 25, 2026 at 01:31 WIB).
Coinvesting
Here are the details of the data and the incident chronology of the hack:
Bitget Hacking Incident Data
Total Losses: Approximately US$351.6 million, or equivalent to Rp6.31 trillion.
Stolen Assets: Consisted of various tokens, including 31.666 ETH, 34.75 million USDT, 19.66 million USDT0, as well as some USDC, XAUt, BNB, and AVAX tokens.
Affected Network(s): These illegal funds were spread across six blockchain networks, with the largest share on the Ethereum network (68.6%) and Arbitrum (10.7%).
Perpetrator Method: The hackers transferred funds from part of the platform’s hot wallet and warm wallet. After draining the funds, the perpetrator immediately swapped those stablecoin assets for ETH using DEX aggregators such as Uniswap and 1inch.
Impact and Handling Steps
Fund Withdrawals Suspended: Bitget immediately temporarily halted withdrawal services for the investigation process. However, deposit and trading services were reported to remain operational.
User Funds Security: Bitget CEO Gracy Chen assured on platform X that users’ account balances were recorded accurately and that customers’ assets remain protected.
Suspected Perpetrator: Based on transaction patterns, management suspects the involvement of a group of hackers from North Korea, although this allegation is still in its early investigation stage. Bitget also stated that this incident was not caused by an insider (inside job) or a leak of private keys.
