According to Beijing time: 02:31 on September 25, 2026, Bitget has once again experienced a major security incident.
On September 24, 2026, Bitget officially confirmed that unauthorized asset transfers occurred involving some hot wallets and warm wallets, initially involving approximately US$351.6 million. Cold wallets were not affected. The platform stated that its user protection fund of more than US$464 million is sufficient to cover this loss, and users’ account balances will not be deducted as a result.
This once again puts an old problem in front of users of all exchanges:
If an exchange is really hacked, what happens to users’ money?
I compiled some more representative exchange security incidents in recent years and in the history of the crypto industry. To make comparison easier, below we only look at four key metrics: time, stolen amount, attribution of the attack, and whether users ultimately got their money back.
It needs to be clarified that “the number of affected users” is actually one of the hardest data points to calculate. Most exchanges only disclose the loss amount and rarely disclose how many user accounts correspond to the assets involved. Therefore, anything without reliable data is labeled as “not disclosed.” 「Follow for more」

First, look at how much the entire industry was actually stolen
2025 was a year with extremely severe security incident losses in the crypto industry.
According to Chainalysis year-end statistics, the total value of crypto assets stolen in 2025 exceeded $3.4 billion.
Among these, North Korea-related hacker groups stole at least $2.02 billion, setting a new annual record; by the end of 2025, Chainalysis’ conservative estimate for North Korea’s cumulative stolen crypto assets has already reached $6.75 billion.
And what truly changed the overall industry security data in 2025 is Bybit.
1. Bybit: about $1.46 billion
Time: February 21, 2025
Amount: about $1.46 billion–$1.5 billion
Assets: 401,347$ETH , as well as assets like stETH, cmETH, mETH
Attribution: attacks related to North Korea’s TraderTraitor / Lazarus
Number of affected users: not disclosed
User handling outcome: users’ balances were covered 1:1, with losses borne by the platform
This is one of the largest single-incident crypto asset thefts in the history of the crypto industry so far.
Bybit disclosed its asset losses as:
401,347 ETH, about $1.12 billion;
90,375 stETH, about $253 million;
15,000 cmETH, about $44.13 million;
8,000 mETH, about $23 million.
Total is about $1.46 billion.
After the incident, the U.S. FBI officially confirmed that North Korea was responsible for this roughly $1.5 billion theft and referred to the related malicious activity as TraderTraitor.
But for ordinary users, there is only one most important outcome:
Bybit did not allocate the $1.46 billion hole to users.
The platform announced that customer assets would continue to be supported 1:1, with losses borne by the exchange itself; the platform continued operating.
So this is a very typical one:
The platform wallet was stolen, but the user assets on the books did not decrease.

2. Bitget: about $351.6 million
Time: September 24, 2026
Amount: about $351.6 million
Attribution: still under investigation; the market has suspicions related to Lazarus, but as of now the official has not finalized the attribution
Number of affected users: not disclosed
User handling outcome: the official stated that the protection fund was enough to cover all losses
This is currently the latest major CEX security incident.
Bitget officially confirmed that at 18:31 UTC on September 24, 2026, the system detected unauthorized asset transfers from some hot wallets.
Preliminary confirmation involved about $351.6 million.
But the cold wallet was not affected.
Bitget also said that at the time the user protection fund size was over $464 million, higher than the amount involved in this incident, so users’ assets could be covered. Users’ account balances stayed normal.
After the incident: withdrawals temporarily paused; deposits正常; trading normal; cold wallets normal.
Therefore, the handling logic currently is also:
Losses were borne by the exchange, not directly by making users bear the losses.
However, because the incident has just happened, the final attack method, the attacker’s identity, the percentage of funds recovered, and so on still need to wait for a complete investigation report.

3. DMM Bitcoin: about $305 million
Around May 31, 2024
Amount: 4,502.9$BTC
Value at the time: about $305 million–$308 million
Attribution: attacks related to North Korea’s TraderTraitor/Lazarus
Number of affected users: not disclosed
User handling outcome: the parent company raised funds to top up assets, but the exchange ultimately exited the market
DMM Bitcoin was stolen: 4,502.9 BTC; based on the price at the time, it was worth more than $300 million.
Unlike Bybit, although DMM Bitcoin ultimately did not make customers directly bear the loss, this attack still had a serious impact on the company’s operations.
The parent company later raised funds to make up customers’ assets.
But: money can make up the gap, it doesn’t mean the exchange can continue operating.
DMM Bitcoin ultimately decided to stop operations and gradually transferred customer accounts and assets to SBI VC Trade.
This is a very important case.
Because it shows: if an exchange can afford to compensate users, that doesn’t necessarily mean the exchange itself will survive.

4. WazirX: about $230 million
Time: July 18, 2024
Amount: about $230 million–$235 million
Attribution: widely attributed to Lazarus-related attackers
Number of affected users: not disclosed exact figures
User handling outcome: restored in phases through a restructuring plan
WazirX was another completely different outcome.
After the attack, the platform did not directly use assets to quickly cover the entire shortfall like Bybit did, but instead entered a long legal restructuring process.
It wasn’t until October 24, 2025 that WazirX restarted trading.
Under the final restructuring plan, eligible users first receive an initial allocation of approximately **85%** of their Approved Claims.
The remaining part is handled via the Recovery Token (RT) mechanism.
In January 2026, WazirX confirmed that the Recovery Token distribution has been completed, but these Tokens could not be traded directly at that time; future buybacks still depend on the company’s profits and the status of later asset recoveries.
So WazirX cannot be simply understood as: “the platform has already compensated 100%.”
More precisely, it is: first recover about 85% of the value of claims, and the remainder is handled via Recovery Token while waiting for future buybacks and recoveries.

5. Phemex: about $70 million–$85 million
Time: January 23, 2025
Amount: about $70 million–$85 million
Attribution: external security researchers had suspected a link to North Korea, but it is not advisable to state it as an official confirmation directly
Number of affected users: not disclosed
User handling outcome: the platform covered the losses and restored withdrawals in phases
On January 23, 2025, Phemex discovered abnormal activity in its hot wallet.
The platform immediately paused some deposit and withdrawal functions and isolated the related systems.
A key point is this: the cold wallet was not affected by this attack.
Then the platform gradually restored withdrawals across different chains, and by February 2025 the withdrawal service was fully restored.
These kinds of incidents again show why exchanges should keep the vast majority of users’ assets in cold wallets:
Hot wallets handle daily liquidity, but the majority of real reserves should be isolated from the internet environment.

6. Binance: 7,000 BTC
Time: May 7, 2019
Amount: 7,000 BTC
Value at the time: about $40 million
Attribution: a combined attack such as phishing, malware, leakage of API Key and 2FA information
Number of affected users: not disclosed
User handling outcome: SAFU covered the losses; user balances were not deducted
This is the most famous exchange security incident in Binance’s history.
In the end, the attacker took 7,000 BTC in one go from Binance’s BTC hot wallet.
Based on the price at the time, about $40 million.
The attacked hot wallet accounted for about 2% of Binance’s total BTC holdings at the time. Binance’s official statement said the attacker obtained large amounts of users’ API Keys, 2FA verification codes, and other information through phishing, viruses, and other attack methods.
Subsequently, Binance paused deposits and withdrawals for about a week to conduct a security check.
In the end, the losses were covered by SAFU’s user security asset fund, with no direct deductions from ordinary users’ balances.
This incident also made the concept of “exchange insurance fund / user protection fund” truly widely recognized by many users.

7. BNB Chain cross-chain bridge: about 2 million BNB
Time: October 7, 2022
Amount: about 2 million$BNB
Nominal value: close to $570 million
Number of affected users: not applicable
User handling outcome: assets of retail exchange users were not directly stolen
This incident is often mistakenly written as:
“Binance exchange hacked for $570 million.”
Actually, it isn’t.
The attacked assets were the native cross-chain bridge between the BNB Beacon Chain and BNB Smart Chain:
BSC Token Hub.
The attacker generated an additional about 2 million BNB through vulnerabilities; at the then-current price it was close to $570 million.
Later, BNB Chain validators coordinated to pause the network and perform an upgrade, so most assets were not successfully transferred out.
Therefore, it must be separated from the Binance exchange attack in 2019:
2019: Binance exchange hot wallet was stolen.
2022: BNB Chain cross-chain bridge vulnerability.
Not the same thing.

8. CoinDCX: about $44 million
Time: July 19, 2025
Amount: about $44 million
Attribution: server intrusion
Number of affected users: 0 customers’ wallets were directly damaged
User handling outcome: CoinDCX bore the loss itself
CoinDCX’s case is also relatively special.
What the attacker breached was an internal operations account used to provide liquidity to a partner exchange, not a customer asset wallet.
In the end, about $44 million USDT was transferred.
CoinDCX officially stated clearly: customer assets were not affected.
All customer assets remain stored in isolated cold wallets; the $44 million loss was borne by CoinDCX’s own reserves.
So strictly speaking, this even cannot be counted as “users’ funds being stolen.”
Instead: the company’s own operating funds were stolen.

9. Coincheck: about 526.3 million NEM
Time: January 26, 2018
Amount: 526.3 million NEM
Customer asset losses at the time: about 46.6 billion yen
Number of affected users: about 260,000
User handling outcome: implement cash compensation
This is a historical case that is well worth adding.
Coincheck’s NEM hot wallet was attacked; about 526.3 million NEM was illegally transferred out.
Coincheck later confirmed in regulatory filings that customer funds losses were about 46.6 billion yen.
Its biggest difference is this: it’s one of the few major exchange attacks where the number of affected users has been explicitly disclosed.
About 260,000 users were affected.
Coincheck then followed a standard of 88.549 yen per NEM and carried out compensation in yen form to eligible NEM holders.
So it is also one of the very typical early cases in the crypto industry:
The exchange suffered a massive attack, but in the end the company’s funds compensated customers.

10. KuCoin: about $275 million–$281 million
Time: September 2020
Amount: about $275 million–$281 million
Attribution: subsequent investigation and on-chain research pointed to North Korea-related attackers
Number of affected users: not disclosed
User handling outcome: large amounts of assets were recovered or frozen; remaining losses were covered by insurance mechanisms and so on
KuCoin also has a very typical case in exchange security history.
Its special part isn’t the amount stolen, but this: the recovery rate is very high afterward.
Large amounts of tokens were restored through project-led upgrades, freezing, re-issuance, and via exchanges and on-chain tracking.
KuCoin ultimately continued operating.

11. BigONE: about $27 million
Time: July 16, 2025
Amount: about $27 million
Number of affected users: not disclosed
User handling outcome: the platform announced it would bear the entire loss
After BigONE experienced the attack, it stated that users’ assets would not be affected by the final loss, and that the platform would bear the related shortfall.
Although $27 million is not that large compared to Bybit, the handling method still falls into a pattern commonly seen among large centralized exchanges today: platform wallet stolen ≠ directly deducting users’ balances.

There are also two other historical incidents that must be looked at separately.
If you expand the scope from “CEXs in recent years” to the entire crypto industry, there are two other very classic cases.
Mt.Gox
Mt.Gox is one of the most famous collapse incidents in the history of crypto exchanges.
Unlike today’s large exchanges quickly using reserves to fill losses, Mt.Gox users went through bankruptcy and civil reorganization procedures lasting over a decade.
Until 2024, some creditor claimants began receiving BTC and BCH repayments.
As of July 16, 2024, the trustee confirmed that repayments of BTC/BCH had been completed to over 13,000 creditors.
As of now, some of the repayment process is still ongoing, and the relevant repayment deadlines have been extended to October 31, 2026.
It shows one thing:
“We might eventually get it back” and “fully reimburse everyone right away” are completely different concepts.
Why don’t most exchanges disclose how many users were stolen from?
After reviewing these cases, you’ll find a very obvious problem:
The amount is often there, but the number of people frequently is not.
Because exchange security incidents typically happen at:
Hot wallets, cold wallets, operational wallets, or multisig wallets managed under the platform’s unified control.
The only thing that may have been stolen on-chain is a handful of addresses, but the assets behind those addresses could correspond to hundreds of thousands or even millions of users.
So it’s hard to simply say:
“Hackers stole money from 100,000 users.”
More accurately, it often is:
Loss occurred in the exchange custody asset pool.
If the platform later uses its own reserves, insurance fund, or protection fund to cover this shortfall, then users’ account balances might even not change.
Therefore, many exchanges basically do not disclose the so-called “number of stolen users.”
Finally, put these events together, and you’ll find a very interesting pattern
As the crypto industry has developed to today, the way large exchanges handle attacks has changed noticeably.
The early Mt.Gox pattern was: exchange gets hacked → liabilities exceed assets → users become creditors → wait for many years, and so on.
Later, Coincheck began to show: exchange hacked → the company paid for it itself.
Then later Binance built SAFU, and more and more platforms began setting up:
User protection fund, insurance fund, risk reserve fund, cold wallet reserves.
So by the time we get to Bybit, CoinDCX, and now Bitget’s case, we’re seeing an increasingly common handling logic:
Platform infrastructure was attacked → the company bore the loss → users’ account balances remain as unchanged as possible.
But that doesn’t mean centralized exchanges have no risk.
Bybit lost nearly $1.5 billion in a single attack—enough to show one thing:
Even if the security system is improved again, there is still no absolute security.
What truly determines whether a security incident will ultimately harm ordinary users—besides technical security—also depends on several very real things:
How much true reserves does an exchange have? Is there strict separation between cold wallets and hot wallets?
Is there a sufficiently large user protection fund? Are assets truly reserved 1:1?
After an attack of hundreds of millions or even billions of dollars, does the company have the capability to fill the hole itself?
This might be more worth users paying attention to than a simple line like “that exchange has never been hacked.”
Because history has already proven: whether an exchange gets attacked is one thing.
After the attack, who ultimately bears the losses is what ordinary users truly should care about. «Data source is from the internet; if anything is incorrect, please point it out anytime»

