CyberSecurityNews

Bitget Hot Wallet Hacked – Attackers Stole $351.6 Million From Hot Wallets


Cryptocurrency exchange Bitget has confirmed a security breach affecting approximately $351.6 million in assets after unauthorized transfers were detected in parts of its hot and warm wallet infrastructure.

The incident was identified at 18:31 UTC on September 24, 2026, prompting the security team to activate emergency response procedures within minutes. Bitget said its offline cold wallets remained secure and that customers’ account balances continue to reflect their holdings accurately.

The compromise was contained within portions of Bitget’s three-tier wallet architecture, according to an official security notice. Although the exchange has not yet published a complete inventory of stolen assets, on-chain observers tracked movements involving ETH, BNB, AVAX, USDT, and USDC.

Early estimates placed suspicious transfers between $174 million and $183 million before Bitget established the $351.6 million exposure.

Bitget temporarily suspended withdrawals while investigators review its wallet systems and determine whether any infrastructure is at risk. Deposits and trading remain available. The exchange said it identified and flagged recipient addresses, informed law-enforcement agencies and engaged blockchain-security companies to trace the funds.

Bitget Hot Wallet Hacked

Chief executive Gracy Chen said the loss is covered by Bitget’s User Protection Fund, which the company values at more than $464 million. That assurance leaves a buffer of roughly $112.4 million above the estimated loss, but users will watch how the fund is deployed and whether withdrawals resume without reducing the balance.

The incident demonstrates why protection reserves must be verifiable, liquid, and accessible during a large exchange compromise.

During a live question-and-answer session, Chen said preliminary evidence included IP addresses resembling VPN infrastructure previously associated with a North Korean threat group. She also said the activity followed patterns seen in earlier North Korean operations, raising suspicion around the Lazarus Group.

However, attribution remains unconfirmed, and Bitget has said it will not formally speculate until its investigation is complete. North Korean actors were blamed for the approximately $1.5 billion Bybit theft in 2025, making any tactical overlap significant but not conclusive.

Chen further indicated that the attackers transferred assets directly after gaining access to Bitget systems, rather than submitting fraudulent customer withdrawal requests. Preliminary findings reportedly suggest the intruders did not obtain private keys and may have compromised a critical backend component supporting wallet services.

Investigators are examining whether a third-party tool or supply-chain attack enabled forged transfer instructions to reach authorized signing infrastructure.

Bitget has promised hourly updates through official channels and a full incident report within 24 hours, covering the root cause, affected systems, and corrective actions. Until that report appears, the precise initial-access vector, persistence mechanism, and control failures remain unknown.

Customers should rely only on verified Bitget communications, remain alert to phishing messages exploiting the withdrawal pause and avoid sharing credentials or signing unsolicited wallet requests.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC



Source link