Bitget reported an estimated $351.6 million in unauthorized transfers from some of its wallets and temporarily suspended withdrawals. Its systems detected the transfers at 18:31 UTC on September 24, 2026.

CEO Gracy Chen said attackers compromised a critical backend system in the wallet infrastructure, spoofed transaction data and triggered the exchange's own authorization process. Private keys were not stolen.

Bitget says only portions of its hot and warm wallet layers were compromised, and cold wallets were untouched.

Bitget says its User Protection Fund holds more than $464 million, which covers the loss in full. Deposits and trading remain open, but withdrawals are paused.

Bitget says the attack pattern is highly consistent with North Korean hacker groups. It has brought in Google-owned Mandiant and SlowMist for a third-party investigation. (Bleeping Computer)

Lookonchain's tally of the stolen assets included about 102.93 million XRP worth $157.5 million and 31,890 ETH worth $85.8 million, plus 12,719 BNB.

Analysts called it one of the most substantive centralized exchange exploits of 2026. FailSafe's CEO said it destroys the illusion that major exchanges have solved hot-wallet security.

Recovery looks limited so far. Circle and Tether have frozen only about $339,100 of stablecoins linked to the hack.