Bitget Hot Wallet Incident and What User Balances Mean
Bitget says about $351.6 million moved out of part of its hot wallets and warm wallets at 18:31 UTC on 24 September 2026, and that user account balances are still covered by a User Protection Fund of more than $464 million. Cold wallets were not part of the breach, according to the exchange. Withdrawals were paused the same day. Deposits and trading stayed open.
That combination is the whole decision. A fund larger than the stated loss can make the balance on the screen whole. It does not mean a withdrawal will clear while the pause is in place. Anyone with coins on the venue should read the notice as an access problem first and a solvency claim second.
Key Takeaway: The official figure is about $351.6 million, detected at 18:31 UTC on 24 September 2026, limited on Bitget's account to a portion of hot and warm wallets. The protection fund is stated above $464 million, so the stated loss fits inside it with room of roughly $112 million if both numbers hold. Withdrawals were still paused on 25 September. Do not add deposits while that pause stands, and do not treat a North Korea comment as an FBI finding.
What the 24 September notice actually confirmed
Bitget's support notice, posted 24 September 2026, lists a short set of confirmed items. Security systems detected unauthorized transfers from some hot wallets at 18:31 UTC. The estimated amount was about $351.6 million. The exchange said it runs a three-tier wallet setup and that the breach reached only a portion of the hot-wallet and warm-wallet layers. Cold wallets stayed secure. The full loss, it said, falls inside the User Protection Fund, which held more than $464 million. Abnormal addresses were flagged and reported. Law enforcement and on-chain security firms were notified. Withdrawals were suspended pending a security review. Deposits and trading remained operational. A full incident report, including root cause, was promised within 24 hours. The notice also said the company would not speculate on the attack path until the investigation finished.
Those last two sentences matter because the public story moved anyway. By 25 September, chief executive Gracy Chen had described a path. The notice is still the baseline for the dollar loss, the wallet layers, the fund size, and the withdrawal pause. Later interviews add claims. They do not replace the notice.
Dividing 464 by 351.6 gives about 1.32. The fund, as stated that night, was larger than the loss by about $112 million. Later retellings said the fund was above $465 million and that Bitget holds more than $1 billion of its own capital on top. I use "over $464 million" from the notice as the anchored fund line, and I label the $1 billion capital line as a chief-executive statement reported by InvestingLive, not as an audited reserve report published with the notice.
What "user funds are safe" does and does not mean
The notice says account balances are accurate and assets are protected. Chen told CoinDesk the same idea in plainer operational terms: the User Protection Fund covers the loss, balances are accurate, and assets are protected. She also said deposits and trading were open and withdrawals were not.
Read those lines as three separate claims.
| Claim | What would have to be true | What a user can check on 25 September 2026 |
|---|---|---|
| The loss is about $351.6 million | The notice's estimate holds after the promised incident report | Wait for that report on the official support article. Ignore round-number "$352 million" rewrites when they drop the 351.6. |
| Balances on the screen are still good | The loss is assigned to the protection fund, not to a haircut on user accounts | The exchange says this. A user cannot prove it from a balance display alone. Export history from the official app. |
| You can leave | Withdrawals have been restored after the review | The notice and next-day coverage still said withdrawals were paused. A paused withdrawal falsifies "I can leave today." |
| Cold storage was outside the breach | The three-tier description holds | This is an exchange statement. The promised root-cause report is the next check. |
| The fund can pay | More than $464 million is actually available and unencumbered | The notice states the size. It does not attach an auditor's letter in the article itself. |
I would not deposit additional size to a venue that has paused withdrawals, even if I believed the fund math. Fresh deposits increase the amount stuck behind the same switch. Trading remaining open means the matching engine is up. It does not move coins to a wallet you control.
A hot wallet is the internet-connected float an exchange uses for withdrawals and fast transfers. A warm wallet sits between that float and offline cold storage. Losing part of those layers is serious, and it is a different event from an empty cold wallet. The user-facing result can look the same for a day or two, because withdrawals stop either way while the venue checks what still signs.
What the chief executive added on 25 September
CoinDesk reported on 25 September 2026 that Chen said the attacker compromised a critical backend system in the wallet infrastructure, used it to spoof transaction data, and triggered the exchange's authorization process. She said private-key compromise had been ruled out. Damage-control steps were described as complete, with a full technical report still to come. The specific intrusion path was still under investigation in that account.
Cointelegraph, also on 25 September, reported a live question-and-answer session in which Chen said investigators had found IP addresses matching VPN choices associated with a North Korean group, that she did not believe the breach was an inside job, and that the attackers did not forge user withdrawal requests and did not obtain private keys for the cold wallet or for hot and warm wallets. She said some stolen funds had been recovered and did not give an amount. Withdrawals were still suspended at publication.
Hold the layers apart. "Keys were not stolen; a backend was induced to authorize a transfer" is a specific claim about mechanism. "North Korea is highly likely" is a preliminary IP-and-VPN judgment from the company. The February 2025 Bybit theft has an FBI public service announcement attributing about $1.5 billion to North Korean actors tracked as TraderTraitor. I do not copy that attribution onto Bitget. No equivalent FBI notice appeared in the sources reviewed for 24–25 September 2026.
The recovered-funds comment is not usable for sizing. An unnamed amount can be meaningful or trivial. Until an address list or a dollar figure is published, the recovery line stays "some, size unstated."
How this compares with the Bybit theft
The useful peer is Bybit's 21 February 2025 incident, because Bitget's own chief executive has used it as a scale comparison and because the mechanics differ.
| Bitget, 24 September 2026 | Bybit, 21 February 2025 | |
|---|---|---|
| Stated size | About $351.6 million | About $1.5 billion in the FBI PSA; a preliminary report cited more than $1.4 billion including 401,347 ETH |
| Layer named | A portion of hot and warm wallets | Ether multisignature cold wallet, via a compromised signing interface |
| Keys | Company says keys were not taken | Signers approved a disguised transaction after Safe{Wallet} developer infrastructure was compromised |
| Who says it was North Korea | Chief executive, preliminary, IP and VPN pattern | FBI PSA, 26 February 2025, TraderTraitor |
| User exit | Withdrawals paused; fund claimed above $464 million | Withdrawals were a liquidity crisis the venue funded with loans and purchases, including 40,000 ETH from Bitget's own reserves |
Surviving a larger theft at another company is not evidence this fund will pay this week. It is a historical parallel for "an exchange can fill a hole and reopen withdrawals." The condition here is still the pause, the incident report, and whether the fund number survives contact with that report.
What to do with an account while withdrawals are paused
Use the official notice only: https://www.bitget.com/support/articles/12560603896024. Do not follow wallet addresses posted in replies, and do not pay anyone who messages you offering to unlock a withdrawal.
- Stop new deposits until withdrawals work again on the official app. Trading can stay available and still be the wrong place to add collateral.
- Export balances and recent history from inside the logged-in account so you have a record if the incident report revises the story.
- If you have open derivatives, know that a withdrawal pause and a working matching engine can diverge. Reduce leverage only through tools the venue still offers. This note does not tell you to market-sell into a thin book.
- Treat any recovery percentage as unknown until a number and a publisher are attached.
- Re-read the incident report when it posts. If the loss moves above the fund, or cold wallets enter the story, the 25 September coverage is stale and the "covered in full" line has to be rebuilt from the new document.
Key Takeaways
- About $351.6 million, 18:31 UTC on 24 September 2026, part of hot and warm wallets. Cold wallets were stated as untouched. Withdrawals paused. Deposits and trading were left on.
- "User funds are safe" on the notice means the loss is assigned to a protection fund stated above $464 million, and balances are said to be uncut. It does not mean a withdrawal succeeds today.
- The 25 September chief-executive account adds a spoofed-backend path and says keys were not stolen. The North Korea link is her preliminary judgment. It is not an FBI attribution.
- Some funds were said to be recovered, with no amount. Ignore private "recovery" messages. Wait for the official report before treating the story as closed.
Frequently Asked Questions
Are Bitget user funds safe after the September 2026 hack?
The exchange says yes, in a specific sense: the loss of about $351.6 million is covered by a User Protection Fund of more than $464 million, and displayed balances were not haircut. Withdrawals were paused. Safe, in that notice, is a coverage statement plus an access freeze. It is not a completed withdrawal.
Did hackers steal Bitget's private keys?
Gracy Chen said on 25 September 2026 that private-key compromise had been ruled out. Her account, via CoinDesk and Cointelegraph, is that a backend system was used to spoof transfer data and trigger an authorized signing process, and that user withdrawal requests were not forged. That is a company finding. The full technical report promised in the notice is the document that would let an outsider test it.
Is North Korea confirmed as the attacker?
Not in the sources available on 25 September 2026. Chen said IP addresses matched VPN choices associated with a North Korean group and called that link highly likely. The FBI has attributed the separate February 2025 Bybit theft. That PSA does not name this Bitget incident.
Can I withdraw from Bitget right now?
The 24 September notice suspended withdrawals pending review, and 25 September coverage still described the pause as in force. Check the official support article rather than a screenshot in a chat. Deposits and trading being open does not lift the withdrawal switch.
Related reading
How to Buy and Store Chiliz (CHZ) Safely: A Beginner's Guide
What Is the Crypto Funding Rate and Why Does It Matter in Trading?
How Crypto Funding Rates Affect Long and Short Positions: A Trader's Analysis
Is PancakeSwap Safe? Key Risks and Security Tips for DeFi Users
How to Get Started with Filecoin: A Beginner's Guide to Storing and Retrieving Data
How to Use Uniswap to Swap Tokens: A Step-by-Step Guide
Uniswap (UNI) Is Ethereum's Decentralized Exchange Protocol Enabling Peer-to-Peer Token Trading
Wofi vs Traditional Finance: Key Differences and Benefits
The Impact of ETH Funding Rates on Your Trading Profits: Insights for OneBullEx Users
How to Choose the Best Crypto Exchange for Trading
Risk disclosure
Cryptocurrency prices are highly volatile. This article is for educational purposes only and does not constitute financial, investment, legal, or tax advice. Always do your own research and consider your financial situation and risk tolerance before making any decision. Loss estimates, fund sizes, and withdrawal status reflect the cited notices and reports as of 25 September 2026 and can change when Bitget publishes its incident report. Platform access, deposits, and withdrawals vary by region and account status. A protection-fund statement is the company's claim about coverage, not a guarantee that a withdrawal will clear.


