Cryptocurrency exchange Bitget has suffered a major security breach, with an estimated $351.6 million in digital assets moved from the platform’s hot wallets in a suspected hack that has once again placed the spotlight on digital asset security. The unauthorized movements were first flagged by blockchain security firms earlier in the day before being officially acknowledged by the platform’s leadership.
According to a statement released on Thursday by Bitget CEO Gracy Chen, the exchange’s advanced security systems detected the anomalous transactions late in the afternoon. The platform’s security team immediately activated emergency response protocols to contain the breach and assess the full scope of the unauthorized transfers.
Writing on the social media platform X, formerly known as Twitter, Chen detailed the exact timeline of the detection. At 18:31 UTC on September 24, 2026, Bitget’s automated security architecture flagged unauthorized movements stemming from a portion of the exchange’s hot wallets.
"Our security team activated emergency response protocols immediately," Chen wrote, addressing the user base and the broader cryptocurrency community directly. In a subsequent message emphasizing the exchange’s resilience, she added that Bitget has successfully navigated multiple market cycles over the years and has no intention of running from the current crisis. She assured stakeholders that every single dollar and every decision made during the incident and subsequent recovery will be accounted for transparently and in full.
Based in Victoria, Seychelles, Bitget ranks as the sixth-largest cryptocurrency exchange globally by trading volume. According to data tracked by CoinGecko, the platform routinely processes over $1.1 billion in daily trading volume, making it a major hub for global digital asset liquidity, spot trading, and derivatives.
The security breach arrives at a particularly sensitive time for the broader cryptocurrency industry, as digital asset security remains in the headlines following a persistent string of high-profile security incidents and exploits throughout the year. The compounding effect of these breaches has left the crypto community increasingly on edge regarding custody models, hardware vulnerabilities, and exchange security protocols.
Just a few months prior, in July, hackers successfully exploited a firmware vulnerability in the popular Bitcoin hardware wallet Coldcard. That sophisticated attack targeted device firmware to siphon nearly $120 million in user funds, serving as a stark reminder that even cold storage mechanisms are not entirely immune to well-resourced adversaries when hardware-level bugs are present.
Furthermore, earlier in the same month as the Bitget incident, the crypto ecosystem was rattled by another massive event involving Blockstream’s Liquid sidechain. In that instance, purported white-hat hackers withdrew approximately 4,000 bitcoins—valued at roughly $320 million at the time of the occurrence—directly from the Liquid federation wallet. While those funds were later partially recovered following on-chain negotiations, the sheer scale of the movement underscored the systemic risks inherent in multi-signature and federated custody setups.
Despite the substantial losses sustained during the Bitget breach, CEO Gracy Chen was quick to emphasize that the exchange’s cold storage infrastructure remained completely secure and that user funds maintained in deep storage were safe from compromise. She elaborated on the platform’s defensive design, noting that Bitget operates a strict three-tier wallet architecture. According to Chen, the unauthorized breach was successfully contained to only a portion of the hot wallet and warm wallet operational layers, preventing the attackers from penetrating the deeper layers of the exchange’s asset reserves.
In the immediate aftermath of the detection, Bitget instituted strict operational adjustments to safeguard remaining assets and protect its user base. While platform deposits and ongoing market trading remain fully operational, exchange management took the precautionary measure of temporarily pausing all customer withdrawals. This restriction is slated to remain in place until the comprehensive security review, system audit, and vulnerability patch process are fully completed by the engineering and security teams.
Independent blockchain analytics firms quickly mobilized to track the movement of the stolen funds across public ledgers. Blockchain data intelligence platform Arkham Intelligence launched a dedicated dashboard shortly after the unauthorized transfers were identified. The dashboard tracked a diverse array of cryptocurrencies and digital assets, including various stablecoins, that had been systematically drained from the targeted Bitget hot wallets.
While Bitcoin did not initially appear on Arkham’s preliminary list of affected assets, subsequent analysis by competing crypto security firm Hacken revealed that the premier cryptocurrency was indeed among the assets moved during the incident. Hacken shared its findings on X, noting that Bitcoin transactions had also been detected as part of the broader exploit.
The investigation into the exact vectors used in the breach remains ongoing, with security researchers, on-chain analysts, and internal teams collaborating to trace the illicit flows and determine how the hot wallet infrastructure was compromised.
Leave a Reply