News · September 24, 2026 · 4 min read
Bitget Wallet Drained of $351.6 Million on 8th Anniversary
I have funded and tested Bitget products with Cardify's own money, so watching a security alert break on September 24, 2026 caught my immediate attention. The exchange confirmed that unauthorized transfers drained $351.6 million from its hot and warm wallets. Here is the full breakdown of what happened, how Bitget's emergency reserve fund is absorbing the financial hit, and what this means for platform balances right now. ## The Details Behind the Hot Wallet Breach At 18:31 UTC on September 24, 2026, automated monitoring systems at Bitget flagged unauthorized asset transfers leaving a limited selection of hot wallets. Early external reports published by Yahoo Finance noted market speculation after roughly $170 million to $176 million shifted from exchange-linked wallets, causing platform users to encounter sudden withdrawal issues. Official statements published shortly after by Bitget CEO Gracy Chen and the main Bitget corporate X account updated the financial impact to approximately $351.6 million. The exploit occurred on Bitget's eighth birthday, making it the eighth-largest crypto hack or loss ever recorded. The magnitude of this theft places Bitget's incident directly behind the FTX collapse and ahead of the Wormhole network breach. Bitget operates a three-tier wallet architecture designed to isolate hot, warm, and cold storage layers. Exchange updates confirmed that cold wallets holding the overwhelming majority of platform assets remained completely secure throughout the intrusion. The unauthorized access was contained entirely within portions of the hot wallet and warm wallet operational layers. https://x.com/bitget/status/2103236552482848927 ## How the User Protection Fund Covers the Loss To offset the financial damage caused by the hot and warm wallet drain, Bitget is drawing directly on its internal User Protection Fund. The dedicated reserve fund currently holds over $464 million in capital. Because the estimated $351.6 million loss falls within the coverage of this reserve, Bitget confirmed that customer account balances remain accurate and protected without requiring user write-downs or haircuts. Platform trading operations and account deposits continue to function normally. As a precautionary safety step, Bitget temporarily suspended withdrawal options while internal security teams perform a comprehensive review across all exchange systems. https://x.com/GracyBitget/status/2103235655879074084 ## Emergency Response Procedures and Community Reaction Bitget activated emergency response protocols within minutes of detecting the abnormal wallet activity. Technical teams identified and flagged the transfer addresses involved, while formally notifying law enforcement agencies and bringing in external on-chain security partners to monitor and trace the stolen assets. CEO Gracy Chen committed to publishing updates every hour across official social channels and releasing a complete incident report within 24 hours of the exploit. The planned post-mortem report will detail the root cause analysis and corrective technical measures taken by the exchange. Chen emphasized that Bitget will not speculate on the specific attack vector while the investigation remains active. She wrote, "Bitget has navigated multiple market cycles. We will not run from this. Every dollar and every decision will be accounted for, transparently and in full." The corporate statement drew immediate commentary across crypto social media channels. Community member @OnlyTerp suggested the exploit marks the beginning of AI-driven attacks targeting profitable companies across the industry. Another commentator, @moonjeff_, questioned the rapid timing of Bitget's statement, pointing out that a detailed seven-paragraph corporate message was posted shortly after the hack became public. Meanwhile, user @Maki___007 raised questions about whether the attacker might attempt to purchase tokens like BATON using the stolen funds. ## Bitget Wallet Incident Breakdown | Parameter | Status and Facts |
| --- | --- |
| Incident Date and Time | September 24, 2026 at 18:31 UTC |
| Total Affected Capital | Approximately $351.6 million |
| Breached Infrastructure | Hot wallet and warm wallet layers |
| Cold Storage Status | Secure and unaffected |
| User Protection Fund Balance | Over $464 million |
| Customer Account Balances | Accurate and fully protected |
| Trading & Deposits | Operating normally |
| Withdrawal Status | Temporarily paused for security audit | ## Practical Takeaways for Neobank and Crypto Card Users Security exploits on centralized crypto exchanges highlight the operational risks inherent in holding custodial balance allocations. Even when an exchange operates a capital cushion like Bitget's $464 million User Protection Fund, emergency withdrawal freezes halt user spending power instantly. Crypto card users reliant on exchange-linked payment products face immediate disruption when operational withdrawals pause. Platforms across the neobank and card space, such as Bybit Card, Wirex One, or RedotPay, rely on steady liquidity flows. Keeping active balance allocations split across non-custodial wallets or separate neobank accounts reduces personal exposure during unexpected security audits. Bitget stated that its engineering teams are working around the clock to restore withdrawal services as soon as platform safety is cleared. ## Sources - https://x.com/bitget/status/2103236552482848927
- https://x.com/GracyBitget/status/2103235655879074084
- https://finance.yahoo.com/markets/crypto/articles/bitget-exchange-reportedly-hacked-over-205821194.html