Bitget Hack $352M: What Happened to Exchange Security
Bitget disclosed on September 24-25, 2026 that suspected North Korean hackers stole about $351.6 million by spoofing its backend authorization system, not by stealing private keys. Withdrawals were paused during the investigation. Bitget says its User Protection Fund fully covers the loss and cold wallets were untouched.
Bitget disclosed on September 24 and 25, 2026 that suspected North Korean hackers, matching a pattern reporting has linked to the Lazarus Group, stole roughly $351.6 million from the exchange’s hot and warm wallets. It’s one of the largest centralized exchange breaches of the year so far. The attackers did not steal private keys; instead, according to Bitget CEO Gracy Chen, they compromised a backend system, spoofed transaction data, and tricked the exchange’s own authorization process into releasing funds it should not have. If you searched Bitget hack $352 million what happened exchange security, that’s the short version — and the more useful question for anyone trading is what this means for holding an active balance on any centralized exchange, not just this one.
I’ve spent years moving positions between exchanges for arbitrage, funding-rate plays, and just plain redundancy, and incidents like this are exactly the reason. Not because Bitget is uniquely reckless, but because this is what a hot-wallet compromise at a large, established platform looks like when it happens to a company with real infrastructure and outside auditors on speed dial.
What Actually Happened at Bitget on September 24-25?
Per Bitget’s own disclosure, the attack targeted hot and warm wallets, the operational reserves an exchange keeps liquid to process everyday withdrawals. Cold wallets, kept offline and disconnected from live systems, were not touched. Neither was Bitget Wallet, the exchange’s separate self-custodial product where users hold their own keys.
Bitget brought in Mandiant and SlowMist, two firms regularly hired for exchange-scale forensic work, to assist the investigation. On-chain analytics firm Lookonchain reported that attackers converted roughly $183 million of the stolen funds into Ether, a common laundering step since ETH is deep and liquid across mixers and cross-chain bridges.
Why the “Spoofed Authorization” Detail Matters More Than the Dollar Figure
Most people’s mental model of an exchange hack is: someone stole the keys, therefore the money is gone the moment the transaction hits the chain. That’s not what Bitget is describing here.
Chen’s characterization was that attackers compromised a backend system and spoofed transaction data to trigger the exchange’s own authorization workflow, effectively getting Bitget’s internal systems to approve withdrawals as if they were legitimate. Her analogy: forged withdrawal slips pushed through a bank’s own teller window, rather than someone drilling into the vault. Mechanically, that’s a meaningfully different failure mode from a stolen private key. A private-key theft means an attacker holds independent signing power outside the company’s control forever. A spoofed-authorization exploit is a process and validation failure, patchable once identified, which is part of why Bitget was able to pause withdrawals and contain further outflow rather than watch funds keep draining.
This distinction matters if you’re trying to judge how a platform’s underlying custody model works — the difference between a custodial exchange holding assets on your behalf and how proof-of-reserves audits are supposed to catch discrepancies is worth understanding before you decide how much of your capital to leave parked anywhere. Our glossary entry on proof-of-reserves breaks down what these audits can and can’t actually verify.
What Bitget Users Should Realistically Expect
Bitget temporarily suspended withdrawals during the investigation, which is standard containment practice, not a sign of insolvency by itself. The exchange says its User Protection Fund, which it states holds approximately 5,500 BTC (worth roughly $464 million as of the disclosure), fully covers the stolen amount. That’s Bitget’s own claim; independent verification typically comes later through published reserve data, and it’s fair for users to watch for that follow-up rather than take any exchange’s word as final.
Bitget has been explicit that it is not shutting down. That framing matters, because 2026 has already seen platforms that genuinely are closing.
| Exchange | 2026 status | Cause |
|---|---|---|
| Bitget | Operating, withdrawals paused during investigation | Backend authorization exploit, ~$352M stolen |
| BitMEX | Operating | Not related to this incident |
| BitMart | Winding down | Company-announced closure |
| AscendEX | Winding down | Company-announced closure |
| CoinEx | Winding down | Company-announced closure |
Lumping Bitget into that closing-down category isn’t accurate based on what’s been disclosed. It’s a real, serious breach, not a company folding.
Is This the Same Story as CEX vs DEX Custody Risk?
Not exactly, but it rhymes. Every time you deposit into a centralized exchange rather than holding coins in a self-custodial wallet, you’re accepting the custodial exchange model: the platform holds keys, executes your orders, and processes your withdrawals through its own internal systems. That’s a trade-off for convenience, speed, and derivatives access you generally can’t get fully on-chain. This incident is a live case study of what goes wrong when that internal system itself gets compromised, independent of whether the cold storage backing it is secure.
If you’re newer to trading and haven’t thought through how much custodial risk you’re comfortable carrying on any single platform, our beginner learning path covers the basics of self-custody versus exchange custody before you scale up position size.
The Practical Lesson: Diversify Where Your Trading Balance Sits
The honest takeaway isn’t “abandon Bitget” or “centralized exchanges are all doomed.” Large, well-capitalized exchanges get targeted precisely because they hold large sums, and this incident shows that even a mature platform with outside forensic firms on retainer can have a backend process fail. That risk doesn’t disappear if you switch to a different exchange, it just moves with you, wherever your active balance lives.
What does reduce concentration risk is spreading your working trading capital across more than one venue rather than parking everything, funds included, on whichever platform has your favorite chart layout. Practically, that can mean keeping only what you need for open positions on any single exchange, moving profits to cold storage or a second venue periodically, and checking whether a platform publishes proof-of-reserves data you can actually verify rather than just claims. Our exchange rankings compare platforms including Bitget, BYDFi, Bybit, and OKX on exactly these security-adjacent factors, not just fee schedules.
For traders specifically thinking through where to route capital they’d otherwise consolidate on one platform, our breakdowns of alternatives to a single exchange and posts on platforms that have shut down and where users moved are worth a read alongside this one, the pattern across both is the same: single-platform concentration is a single point of failure, whether the failure is a hack or a business closure.
None of this requires panic. It requires treating “which exchange holds my active balance” as a risk-management decision you revisit periodically, the same way you’d rebalance a portfolio, rather than a set-and-forget choice from whenever you first signed up. For the official record on this incident, Bitget’s own statements are posted at bitget.com, and it’s worth checking there directly rather than relying solely on secondhand summaries, including this one.
[SECURITY NOTICE] Bitget Hot Wallet Incident - September 24, 2026At 18:31 UTC on September 24, 2026, Bitget's security systems detected unauthorized transfers from some of our hot wallets. Our security team activated emergency response protocols immediately.What we have...
Frequently asked questions
Is Bitget safe to use after the 2026 security incident?
Bitget's cold wallets and its separate self-custodial Bitget Wallet product were not affected, and the exchange says it engaged Mandiant and SlowMist to investigate. Whether it is safe enough for your own risk tolerance is a personal call, but the company has not announced any shutdown or insolvency, unlike some smaller platforms that closed in 2026.
Will Bitget reimburse users who lost funds in the hack?
Bitget says its User Protection Fund, which it states holds roughly 5,500 BTC worth about 464 million dollars, fully covers the amount stolen. That is the company's own claim as of late September 2026, and independent confirmation typically comes later through published proof-of-reserves data.
Which crypto exchanges have the strongest security in 2026?
No exchange is hack-proof, since Bitget itself was a large, established platform when this happened. Traders generally look at cold storage ratios, published proof-of-reserves audits, incident response history, and insurance or protection funds when comparing exchanges on our [exchange rankings](/rankings/exchanges/).
How do I withdraw my funds from Bitget right now?
During the investigation Bitget temporarily suspended withdrawals, which is standard practice while a security team traces stolen funds and patches the exploited process. Check Bitget's official announcements channel or app for the current status before assuming withdrawals are open.
Does Bitget operate legally in my country after the breach?
A security incident does not by itself change an exchange's licensing status; Bitget's regulatory standing varies by jurisdiction regardless of this hack. Check your local regulator's registry and Bitget's own terms for your specific country.
What is Bitget doing to prevent future exchange hacks?
Bitget brought in outside firms Mandiant and SlowMist to investigate the backend compromise, and paused withdrawals while patching the authorization flow attackers exploited. The company has not published a detailed public post-mortem of the technical fix as of this writing.
How is this different from an exchange losing its private keys?
A stolen private key lets an attacker sign transactions directly and independently of the exchange. Here, per CEO Gracy Chen, attackers instead spoofed transaction data to trick Bitget's own internal authorization system into approving withdrawals, comparable to forged paperwork getting waved through a bank's teller window rather than someone breaking into the vault.
Should I move all my funds off Bitget now?
Bitget has stated the loss is covered and it is not shutting down, so a full panic exit is not the proportionate response the facts currently support. The more defensible move is spreading active trading balances across more than one exchange going forward, regardless of which platform you use.