Bitget confirms $351.6m breach and freezes withdrawals
The Asia-focused exchange says unauthorised transfers hit parts of its hot and warm wallets on 24 September 2026, with losses covered by a protection fund holding over $464m.

Key points
- Bitget detected the unauthorised transfers at 18:31 UTC on 24 September 2026, according to founder and CEO Gracy Chen.
- About $351.6m was affected, nearly double the $174m to $183m estimated onchain earlier that day.
- Cold wallets were untouched; the breach was limited to parts of the hot and warm wallet layers.
- Withdrawals are paused during a security review, while deposits and trading continue.
- The User Protection Fund holds more than $464m, which Bitget says covers the full estimated loss.
Bitget has confirmed that unauthorised transfers drained roughly $351.6m from parts of its hot and warm wallet infrastructure, an incident the Asia-focused exchange says its User Protection Fund covers. According to Cointelegraph, the confirmed figure is nearly double the early estimates that circulated onchain during the day.
Founder and CEO Gracy Chen said the exchange detected the unauthorised transfers at 18:31 UTC on 24 September 2026. She said the breach was contained to portions of Bitget's hot and warm wallet layers within its three-tier architecture, and that cold wallets remain secure. The exchange has temporarily suspended withdrawals, while deposits and trading stay operational.
The figure grew as the day went on. News.bitcoin reported that blockchain security researchers first flagged large multi-chain movements from Bitget-labelled addresses on Thursday. Social estimates began near $174m and climbed towards $183m as more transactions surfaced. Security firms Hacken and PeckShield had drawn attention to the suspicious wallet activity before any official confirmation existed.
Breach confirmed at Bitget
Bitget says its User Protection Fund holds more than $464m, enough to cover the full estimated loss, and that user account balances remain accurate. The exchange said it has flagged the addresses involved and notified law enforcement and onchain security firms. It pledged a complete incident report, including root cause and corrective measures, within 24 hours, plus hourly updates through official channels.
The exchange has said it will not speculate about the attack vector while its investigation proceeds. The affected amount places the incident among the largest confirmed exchange security incidents of 2026, according to the reporting.
Pausing withdrawals is a costly step for any exchange, even when a protection fund absorbs the loss, because withdrawals are the lifeline of the business. The larger effect is on confidence: users of a centralised venue cannot verify wallet security themselves, so the operational detail Bitget releases becomes the main evidence that funds are safe.
Estimate climbs during the day
The promised root-cause report sets a short deadline for transparency. Also worth watching is when the exchange lifts its withdrawal pause, and whether law enforcement or onchain investigation identifies the addresses Bitget has already flagged.
