Bitget Hacked for US$351.6 Million: CEO Livestream Rules Out Private Key Leak

The biggest exchange hack of 2026, and the update from the CEO livestream: no private key leak, a compromised backend system, some hacker addresses frozen.

Share
Bitget Hacked for US$351.6 Million: CEO Livestream Rules Out Private Key Leak

Quick answer: Bitget was hacked on 24 September 2026 and about US$351.6 million was taken from hot and warm wallets. On 25 September, CEO Gracy Chen held a livestream of more than three hours and said there was no private key leak: an attacker breached a core backend system of the wallet service, generated false transfer data and pushed it through the approval and signing process. Withdrawals stay paused and the company says its protection fund covers the loss.

Key takeaways

  • How much: about US$351.6 million, the largest crypto exchange hack of 2026.
  • How: no private key leak. The CEO says a core backend system of the wallet service was breached, false transfer data was generated and pushed through the approval and signing process.
  • What was hit: hot and warm wallets across seven chains. Cold wallets and Bitget Wallet were not affected.
  • Where users stand: balances are correct and covered by a US$464 million protection fund, and withdrawals stay paused until the security review finishes.

Bitget, one of the largest crypto exchanges, lost about US$351.6 million to an attacker on 24 September 2026. Here is what is known so far, from the company and from on-chain trackers.

What happened

At 18:31 UTC on 24 September 2026, Bitget detected transfers it had not authorised leaving a limited number of its hot and warm wallets. The company says it started its emergency procedures within minutes and paused withdrawals.

Chief executive Gracy Chen put the damage at about US$351.6 million. Fifteen transfers moved close to US$192 million across seven assets, with Ethereum the largest share at 44.4 percent, according to on-chain analysis by Bubblemaps. Cold wallets were not touched.

Chen has pointed publicly to North Korea. No technical report has been published yet, so the attack method is still unknown.

The update from the CEO livestream

On 25 September, Gracy Chen held a livestream of more than three hours and posted a summary afterwards. These are the points she made.

  • No private key leak. The attacker breached one of the core backend systems of the wallet service, generated false transfer data and triggered the approval and signing process from inside.
  • Assets hit: ETH, XRP, BNB, AVAX, USDT, USDC and others, across Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC and Base. All on-chain cold wallets were confirmed secure.
  • Some hacker addresses frozen. Bitget contacted the affected chain foundations and several confirmed freezes.
  • Attribution: IP behaviour and on-chain analysis are consistent with known North Korean patterns, per the company. It has reported the incident to authorities.
  • Bitget Wallet was not affected. It runs on separate infrastructure from the exchange.
  • Balance sheet: a protection fund of more than US$464 million plus company assets stated at more than US$1 billion, with user funds backed 1:1.

The company had announced the livestream a few hours earlier, while the incident was still unfolding.

The first detailed account came from co-founder Xie Jiayin, who posted the timeline and the US$351.6 million figure in Chinese.

What Bitget says about customer money

  • Customer balances are correct on the platform.
  • The loss is covered by the User Protection Fund, which holds more than US$464 million.
  • Deposits and trading are still running.
  • Withdrawals are paused while a security review runs. No end time has been given.
  • Addresses linked to the attacker have been flagged, and a full report is promised.

In Chen's words: the full amount of the loss falls within the coverage of the protection fund.

How it compares with the rest of 2026

This is the largest crypto exchange hack of 2026, and it pushes September past April as the costliest month of the year for crypto theft.

Measure2026 so far
Hacks counted in the first half207
Total stolen, TRM Labs estimateabout US$972 million
Total stolen, CertiK estimateabout US$1.32 billion
Share attributed to North Koreaabout 66 percent, or US$643 million
This single incidentUS$351.6 million

Most large losses this year came from stolen keys and social engineering rather than clever smart contract bugs. The Bitget attack method has not been published, so it is not yet clear which category it falls into.

What to do if you have funds on an exchange

  1. Do not panic-move funds through unfamiliar links. Phishing always spikes in the days after a hack.
  2. Follow the exchange's own announcement channels, not messages sent to you.
  3. Once withdrawals reopen, move out anything you are not actively trading.
  4. Check whether the exchanges you use publish a protection fund at all. Most do not.

Why this matters even though the money is covered

Nobody is short a dollar if the fund pays. But a correct balance you cannot withdraw is not the same as money in your hand. Rent does not pause. A market that moves while withdrawals are frozen moves without you.

That is the difference between custody and self-custody. On an exchange, someone else holds the button that stops your withdrawal. Fizen is non-custodial, so there is no such button here, and the trade is blunt: if you lose your recovery phrase, nobody, Fizen included, can restore it.

Frequently asked questions

How much did Bitget lose?

About US$351.6 million, confirmed by the company on 24 September 2026.

How did the Bitget hack happen?

According to the CEO's 25 September livestream, an attacker breached a core backend system of the wallet service, generated false transfer data and pushed it through the approval and signing process. A private key leak has been ruled out.

Is customer money safe?

Bitget says balances are correct and the loss is covered by its User Protection Fund, which holds more than US$464 million.

Can I withdraw from Bitget right now?

Withdrawals were paused after the hack. Deposits and trading continued. Check the exchange's own announcements for the current status.

Which wallets were hit?

Some hot and warm wallets. Cold wallets and most assets on the platform were reported unaffected.

Who was behind it?

Bitget's CEO has pointed to North Korea. That is an attribution, not a confirmed finding, and no technical report has been published yet.

No pause button on your own balance

Fizen is a non-custodial USDT app: the balance sits in a wallet you control, with an investment from Tether in the company. The trade is real, because nobody, Fizen included, can restore a lost recovery phrase. Availability depends on your country and partners. Not offered to US Persons.

See how self-custody works

Terms and conditions

  • Information only. This article reports a publicly documented security incident and general security practice. It is not an offer or sale of any product or service, and it is not financial, legal or tax advice.
  • For readers in the United States. This article provides information only. It is not an offer, solicitation or sale of any product or service, and it is not financial, investment, legal or tax advice. Fizen is not offered to US Persons.
  • Independent. Fizen is not affiliated with, endorsed by or a partner of Bitget, Bubblemaps, TRM Labs or CertiK. Figures here are what the company and public reports stated on 24 and 25 September 2026, and may be revised as the investigation continues.
  • Full terms. See the Master Terms of Use, Privacy Policy and Disclaimer on the Fizen website.

Sources

Reported 25 September 2026, using company statements and press coverage from 24 and 25 September 2026.