Bitget Hack has become one of the biggest crypto security incidents of 2026 after the exchange confirmed that about $387.5 million in crypto assets were transferred to attacker-controlled addresses. The figure was initially estimated at $351.6 million but was later revised after Bitget identified additional affected assets on the Zcash and TRON networks. The higher figure does not mean another $35.9 million was stolen later; it reflects a fuller accounting of the original incident.
The incident was detected on September 24 at 18:31 UTC, and Bitget temporarily suspended withdrawals while keeping trading and deposits available. The exchange says the vulnerability has now been identified and fixed, while Mandiant and SlowMist continue to assist with the investigation.
Bitget Crypto Hack: What Happened?
The Bitget crypto hack affected parts of the exchange’s hot and warm wallet infrastructure. According to Bitget, its cold wallets were not affected, and the separate self-custodial Bitget Wallet product was also not impacted.
The company said the attack did not involve the theft of private keys. Instead, attackers compromised a critical backend system within the wallet infrastructure and used it to spoof transaction data, causing the exchange’s authorization process to approve transfers that appeared legitimate.
Crypto Laundering Probe: UAE and Sweden Arrest Seven in $7.1 Million Case
That distinction is important. This was not simply a case of hackers obtaining a private key and transferring everything directly. The investigation is focused on how the attackers entered the backend system and bypassed existing security controls.
Bitget Security Breach: Which Crypto Was Affected?
Bitget’s updated investigation identified affected assets across Ethereum and other EVM networks, XRP Ledger, Zcash and TRON.
The confirmed assets include:
- XRP
- ETH
- USDT
- ZEC
- USDC
- USDT0
- XAUt
- BNB
- AVAX
- TRX
On-chain tracking showed that XRP accounted for one of the largest portions of the transferred assets, while significant amounts of ETH and stablecoins were also involved. The exact asset values can change as prices move and investigators continue tracing the wallets.
Bitget’s revised $387.5 million figure includes Zcash and TRON transfers that were not included in the first $351.6 million estimate.
Bitcoin Price 2026 Roller Coaster: From $98K to $58K, Then Back to $87K
How Did the Bitget Hack Happen?
The publicly available information points to a backend compromise rather than a direct private-key theft.
Bitget says the attacker manipulated transaction data inside a critical wallet-related backend system and triggered its authorization process. In simple terms, the system was made to treat malicious transfers as legitimate transactions.
The exact initial entry point and every technical step involved have not yet been publicly disclosed. Mandiant, SlowMist, Bitget’s security team and law-enforcement authorities are continuing the investigation.
There have also been reports pointing to possible North Korean links, based on similarities in attack patterns and other indicators. That remains an attribution under investigation, rather than an independently established identity of the attacker.
Crypto Payments in UAE: What Can You Buy, Pay and Invest in With Crypto?
Bitget Withdrawals: When Will They Resume?
This is now the biggest question for Bitget users.
After the security review, Bitget announced a phased withdrawal restoration rather than reopening every asset at once. The current schedule is:
| Date | Withdrawal service |
|---|---|
| September 28 | Bitcoin (BTC) |
| September 29 | Ethereum (ETH) |
| September 30 | USDT |
| October 2 | Other tokens, fiat and P2P services |
The planned reopening starts at 08:00 UTC on the respective dates. Bitget says additional security validation is being carried out across the withdrawal infrastructure.
Trading and deposits have remained available, while the temporary withdrawal suspension was described by Bitget as a security measure following the incident.
Can the Stolen Crypto Be Recovered?
Bitget has started a recovery effort and launched a Recovery Bounty Program.
The exchange says eligible parties can receive a 5% bounty for funds successfully frozen through their voluntary efforts and another 5% for funds successfully recovered, subject to the program’s conditions. Bitget has also made fund-tracing information available to exchanges, blockchain projects and security teams.
Some funds have already been frozen through cooperation with industry participants. Circle and Tether also froze a combined amount of roughly $318,000 in USDC and USDT linked to the incident, although that represents only a small portion of the total amount transferred.
What Happens Next for Bitget?
Bitget says the underlying vulnerability has been remediated and that the incident is contained, with no further unauthorized transfers possible from the exploited weakness. The company is now focused on security validation, fund tracing and recovery while the wider investigation continues.
Bitget has also said its User Protection Fund held more than $464 million when the incident was disclosed, and that the reported loss falls within the fund’s coverage.
For users, the immediate focus is therefore on the phased withdrawal reopening, continued security checks and the recovery of stolen assets.
Final Takeaway
The Bitget Hack started with an initial $351.6 million estimate but has since been revised to $387.5 million after investigators identified additional Zcash and TRON transfers. Bitget says private keys were not compromised; instead, attackers manipulated a backend wallet system to trigger unauthorized transfers.
The vulnerability has been fixed, withdrawals are scheduled to return in stages from September 28, and recovery efforts are underway. The investigation into exactly how the attackers gained backend access—and who was behind the operation—is still continuing.












