Bitget just suffered one of the largest exchange hacks of 2026, losing $387.5 million in unauthorized withdrawals. CEO Gracy Chen’s response: the company still plans to go public within three years.
The breach, detected on September 24 at 18:31 UTC, drained funds from both hot and warm wallets using spoofed transaction data. Among the stolen assets were approximately 103 million XRP, worth roughly $157 million, along with ETH and USDT. Cold wallets were not compromised, and no private keys were exposed.
Inside the breach
The initial damage estimate came in at $351.6 million, but that figure was revised upward to $387.5 million after Bitget recovered additional assets on Zcash and TRON networks.
Chen disclosed that the attack’s fingerprints resemble previous operations attributed to North Korean hacking groups. That assessment is based on IP address analysis and transaction pattern tracing, prompting Bitget to inform law enforcement and launch an on-chain tracing initiative.
Bitget has brought in Mandiant and SlowMist to investigate the breach and patch whatever gaps the attackers exploited. Withdrawals remain suspended while the platform shores up its defenses.
The $464 million safety net
The exchange maintains a User Protection Fund of over $464 million specifically designed for scenarios like this one. That fund will fully cover the $387.5 million in losses, meaning affected users should ultimately be made whole, with roughly $76 million to spare.
IPO ambitions in a tough market
Chen herself has described 2026 as challenging for crypto companies eyeing public listings. The culprit is competition for investor attention from AI and space technology sectors, which are commanding sky-high valuations and drawing capital away from digital asset firms.
The three-year IPO timeline Chen has outlined gives Bitget a runway to recover from the reputational damage and demonstrate that its security overhaul actually works. Any IPO prospectus will need to disclose this breach prominently, and how the company handled the aftermath, the speed of user reimbursements and the effectiveness of its security upgrades, will matter as much as the breach itself.
Disclosure: This article was edited by John Chen. For more information on how we create and review content, see our Editorial Policy.

57 minutes ago
27







English (US) ·