Bitget security breach drains $387.5M, but its fund covers every dollar

17 hours ago 40
Bitget security breach

Bitget just became the latest cautionary tale in crypto security, and the numbers are staggering: $387.5 million vanished from the exchange in a matter of hours. Yet in the middle of what amounts to one of the largest exchange hacks of 2026, CEO Gracy Chen did something unusual. She doubled down on the company’s long-term ambitions, reaffirming plans to take Bitget public within three years even as the fallout from the Bitget security breach was still being tallied.

Key takeaways

  • Bitget lost $387.5 million in unauthorized withdrawals, an amount revised upward from an initial estimate of roughly $351.6 million.
  • The breach hit hot and warm wallets only; cold wallets and private keys were never compromised, according to CEO Gracy Chen.
  • Stolen assets included roughly 103 million XRP (worth about $157 million), plus ETH and USDT, with additional tokens reportedly affected across several blockchain networks.
  • Bitget’s $464 million User Protection Fund will fully cover the losses, leaving about $76 million to spare.
  • Despite the breach, Chen says Bitget still plans to go public within three years, even as 2026 shapes up as a tough year for crypto IPOs.

Inside the Bitget security breach: how the money disappeared

The attack was detected on September 24 at 18:31 UTC, when Bitget’s systems flagged unauthorized transfers moving out of parts of its infrastructure. According to CNBC, the exchange recorded 19 separate transfers pulled from hot and warm wallets, while its cold storage remained untouched throughout the incident.

Bitget’s security team later determined that attackers had breached a critical backend wallet system and used it to spoof transfer data, effectively tricking the exchange’s authorization-signing process into approving withdrawals that should never have gone through. Chen was direct about what was not compromised: “Private key compromise has been ruled out,” she said, drawing a clear line between this incident and hacks where signing keys themselves are stolen.

Among the assets drained were approximately 103 million XRP, worth roughly $157 million at the time, along with ETH and USDT. Other reporting on the incident also pointed to ether, USDC, Avalanche and BNB moving across networks including Ethereum, the XRP Ledger, Avalanche, BNB Smart Chain and Arbitrum, suggesting the attackers cast a wide net across Bitget’s supported chains rather than targeting a single asset.

The dollar figure attached to the breach has shifted more than once. Early on-chain estimates put the damage closer to $183 million, and Bitget’s own initial assessment landed at $351.6 million. That number was later revised upward to $387.5 million after the exchange recovered additional stolen assets tracked across the Zcash and TRON networks, underscoring how fluid loss estimates tend to be in the first hours after a major exchange hack.

Why this matters for exchange security

The fact that cold wallets held firm while hot and warm wallets were exploited through spoofed authorization data is a reminder that even well-funded platforms remain exposed at the operational layer, not just at the level of key custody. For users, it reinforces a familiar lesson: the segregation between hot and cold storage is what limited this Bitget security breach from becoming a total loss event.

North Korea in the frame, as Mandiant and SlowMist dig in

Bitget says preliminary evidence points toward North Korean hackers, though the exchange has stopped short of formal attribution. Chen said investigators identified IP addresses linked to VPN services previously tied to a North Korean hacking group, and that the overall pattern of the intrusion echoed earlier operations attributed to the same actors.

The exact method used to breach Bitget’s systems remains under technical investigation. To get answers, the exchange has brought in Mandiant and SlowMist, two firms with track records in crypto incident response, to trace how the attackers got in and to patch whatever gaps they exploited. Bitget also said it has notified law enforcement and launched an on-chain tracing effort to follow the stolen funds across blockchains.

Support has come from an unexpected corner of the industry. Bybit CEO Ben Zhou said his team was standing by to help Bitget, a nod to the fact that Bitget had supported Bybit during its own $1.5 billion hack in February 2025. Zhou added that Bybit is updating its LazarusBounty platform to assist in tracing the funds stolen from Bitget, effectively turning a rival exchange’s crisis response tool into a shared industry resource.

Withdrawals frozen, but the safety net holds

Withdrawals on Bitget remain suspended while engineers repair and reinforce the systems that were exploited. Deposits and trading, however, are continuing as normal, and Chen has said the freeze on withdrawals “shouldn’t take weeks,” even if she declined to commit to an exact timeline.

The financial cushion behind that promise is Bitget’s User Protection Fund, which holds more than $464 million. According to Chen, the losses of $387.5 million will be entirely covered by the reserve, so users who were affected should end up fully compensated, leaving about $76 million remaining even after the deficit is addressed. It’s a rare instance of an exchange having a large enough dedicated fund to make an attack of this size a solvable balance-sheet problem rather than an existential one.

Gracy Chen’s IPO bet, even after the hack

Despite the breach, Chen has not backed away from Bitget’s biggest strategic goal: going public. She reaffirmed plans to take the exchange public within three years, a timeline that now doubles as a test of how well the company recovers from reputational damage.

Chen has also been candid about the environment crypto firms are navigating. She has described 2026 as a challenging year for crypto companies eyeing public listings, largely because investor attention and capital are being pulled toward AI and space technology sectors, both commanding valuations that are hard for digital asset firms to compete with.

That three-year runway gives Bitget time to show its security overhaul actually works and to demonstrate that user reimbursements move quickly and cleanly. Any future IPO prospectus will need to disclose this breach in detail, and how the company handled the aftermath, particularly the speed of reimbursements and the durability of its post-breach security upgrades, could end up mattering to investors as much as the breach itself. In an industry where a single incident can define an exchange’s reputation for years, Bitget’s response to this hack may say more about its readiness for public markets than any revenue figure could.

FAQ

What wallets were affected in the Bitget security breach?

The breach affected hot and warm wallets but not cold wallets or private keys.

How much money did Bitget lose in the hack?

Bitget lost $387.5 million in unauthorized withdrawals during the security breach, an amount revised upward from an initial estimate of about $351.6 million.

Who is suspected to be behind the Bitget hack?

The cyberattack is linked to North Korean hacker patterns based on IP address analysis and transaction pattern tracing, according to Bitget CEO Gracy Chen.

What is Bitget doing to handle the breach?

Bitget engaged Mandiant and SlowMist to investigate the breach, notified law enforcement, launched an on-chain tracing initiative, and suspended withdrawals while improving security. Its $464 million User Protection Fund is set to fully cover the losses.

Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

Read Entire Article