Bitget CEO skeptical on fund recovery following zero-day breach of up to $388 million
Bitget suffered a security breach draining up to $388 million in crypto after attackers exploited a third-party zero-day flaw, prompting exchange CEO Gracy Chen to express skepticism about recovering funds even as a $464 million protection fund covers user losses.

Crypto exchange Bitget suffered a major security breach on Sept. 24, 2026, resulting in losses reported between $351.6 million and $388 million drained from its hot and warm wallets across multiple blockchains.[1][5][12][14]
Bitget CEO Gracy Chen said attackers exploited a zero-day vulnerability in a third-party security product to obtain internal credentials, access wallet backend systems, and spoof withdrawal commands. Both Chen and blockchain security firm GoPlus Security confirmed that private keys and cold wallets were not compromised, as the attacker manipulated authorized signing workflows. Chen noted that the attacker executed two test transfers below risk thresholds roughly 30 minutes before draining hot wallets. Security firm Hypernative's reconstruction revealed that Bitget systems flagged unauthorized activity at 18:31 UTC, yet $87.6 million left hot wallets at 19:01 UTC and $202.8 million left warm wallets at 19:16 UTC.[2][6][8][11][12][14]
Bitget enlisted Mandiant and SlowMist to investigate, pointing to IP addresses and attack patterns that matched techniques used by North Korean hacking groups, though the attribution has not been independently confirmed. Chen stated she is 'not very optimistic' about recovering the stolen funds, citing the 2025 Bybit breach where only about 3.5% had been frozen a year later. Bitget suspended withdrawals during the security review before resuming them on Sept. 29, 2026, and stated that all user losses are fully covered by its $464 million User Protection Fund.[1][3][4][7][9][15]
Key facts
- Bitget sustained a security incident on Sept. 24, 2026, with estimated losses ranging from $351.6 million to $388 million.
- Bitget CEO Gracy Chen said attackers exploited a third-party zero-day vulnerability to obtain internal credentials and spoof withdrawal commands.
- Bitget and GoPlus Security stated that wallet private keys and cold storage were not compromised in the attack.
- Hypernative reported that Bitget flagged unauthorized transfers at 18:31 UTC, prior to $87.6 million exiting hot wallets at 19:01 UTC and $202.8 million leaving warm wallets at 19:16 UTC.
- Bitget enlisted forensic firms Mandiant and SlowMist, noting on-chain patterns and IP addresses suspected of linking the exploit to North Korean hackers.
- Chen said she is 'not very optimistic' about fund recovery, noting only about 3.5% was frozen a year after the 2025 Bybit hack.
- Bitget paused withdrawals following the breach before resuming them on Sept. 29, 2026, stating its $464 million User Protection Fund covers all affected user balances.
Sources · 11 sources
- CR
CryptoSlateArticle ·
Bitget’s $351.6 million hack pushes September crypto losses to 2026 high Bitget has suspended withdrawals after unauthorized transfers drained about $351.6 million from a limited number of its hot and warm wallets. The crypto exchange detected the transfers at 18:31 UTC on Sept. 24 and activated its emergency response procedures within minutes, Chief Executive Officer Gracy Chen said. Bitget’s cold wallets and most assets held on the platform were unaffected. Fifteen transfers drained nearly $192 million across seven assets, with Ethereum accounting for the largest share at 44.4%. Source: Bubblemaps Chen said customer balances remain accurate and the losses are covered by Bitget’s User Protection Fund, which currently holds more than $464 million. Deposits and trading continue to operate normally while withdrawals remain paused pending a security review. She said : “The full amount of this loss falls within the coverage of Bitget's User Protection Fund.” The exchange has identified and flagged addresses connected to the transfers and notified law enforcement agencies and on-chain security firms. It has yet to disclose how the wallets were compromised and said it would not speculate on the attack vector while the investigation remains underway. Bitget plans to provide hourly updates and publish a full incident report within 24 hours, including the root cause and corrective measures. Related Reading One wallet links $1.55 million FetchAI theft to massive 408.5 million NTX mint September crypto losses surge past April The breach comes during Bitget’s eighth-anniversary campaign, which the exchange launched this month as it expands beyond crypto into equities, foreign exchange and other markets under its Universal Exchange strategy. It also makes an already expensive month for crypto security even more costly. DeFiLlama had recorded about $331 million in losses across 17 September incidents before the Sept. 19 Fetch.ai exploit . Subsequent attacks pushed that figure above $342 million, with most of the damage linked to a roughly $320 million incident involving Liquid Network . Adding Bitget’s $351.6 million in affected assets would push September’s reported total above $684 million, making it the costliest month of 2026 on a gross-loss basis. That would surpass April, when crypto exploits generated about $646.9 million in losses, largely because of the Drift and KelpDAO attacks. Those two incidents accounted for roughly $577 million of the month’s total. The September figure could still change as investigations determine whether affected assets are recovered or ultimately classified as losses. For Bitget, the immediate focus is restoring withdrawals. Chen said the exchange would keep them suspended until its security review is complete and pledged that “every dollar and every decision will be accounted for, transparently and in full.” The post Bitget’s $351.6 million hack pushes September crypto losses to 2026 high appeared first on CryptoSlate .
Open source - BL
BlockNews@blocknewsdotcomPost on X ·
🚨 LATEST: Bitget CEO Gracy Chen says the attacker behind the $388 MILLION exploit made two test transfers below the exchange’s risk-control threshold just 30 minutes before draining its hot wallets. The attacker reportedly exploited a zero-day flaw in a third-party security product and erased traces of the commands used. Bitget says private keys and cold wallets were not compromised.
Open source - CT
Coin TelegraphArticle ·
Bitget CEO ‘not very optimistic’ on recovering funds from $388M breach Gracy Chen said she saw the 2025 Bybit hack as a “good reference point” for Bitget’s security breach, noting that only a small percentage of funds had been frozen or recovered.
Open source - CR
CryptoSlateArticle ·
Bitget’s North Korea-linked $352 million hack could drain 76% of its protection fund Bitget said its $351.6 million wallet breach bears the hallmarks of North Korean hackers as investigators race to trace and freeze stolen assets. The crypto exchange said analysis of IP activity and blockchain transactions showed the Sept. 24 attack closely matched techniques used by known North Korean hacking groups. Bitget has reported the incident to relevant authorities and enlisted blockchain security firms Mandiant and SlowMist to investigate, Chief Executive Officer Gracy Chen said . Onchain analyst Specter separately linked the XRP taken from Bitget to funds stolen during the $24 million AFX hack in July, which was attributed to the TraderTraitor cluster associated with North Korea’s Lazarus Group . The Bitget attribution remains under investigation and has not yet been independently confirmed by its external security firms. Chart Linking Bitget's Stolen Funds With North Korea-Linked Attackers (Source: Specter) The breach affected ETH, XRP , BNB, AVAX , USDT, USDC and other assets across Ethereum , XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Chain and Base. XRP accounted for the largest loss on a single network, Chen said. Bitget said some blockchain foundations have already confirmed freezes of addresses associated with the attacker. Any successful recovery could reduce the final loss from the $351.6 million of assets initially identified as affected. Cold wallets remained secure, according to the exchange, while Bitget Wallet, its separately operated self-custodial product, was unaffected. Bitget's protection fund faces its largest test The attack has also put Bitget’s financial backstop under scrutiny as withdrawals remain suspended during a wider security review. Bitget said losses left after its assessment will be borne by its User Protection Fund , which holds 5,500 Bitcoin valued at more than $464 million. Chen said the company would replenish the fund after covering the incident. A loss equal to the full $351.6 million estimate would amount to roughly 76% of a fund valued at $464 million. The eventual draw could be smaller if assets are frozen or recovered, while the fund’s dollar value can also change with Bitcoin’s price. Bitget said it has additional resources beyond the fund. Chen disclosed more than $1 billion in proprietary assets and said customer funds remain backed on a 1:1 basis. The company has yet to say how much of those resources it will need, how much will come directly from the protection fund, or what the fund will hold after it makes customers whole. Its latest proof-of-reserves report , published Sept. 17, showed an aggregate reserve ratio of 135% across 19 assets, but the snapshot came before the attack and does not reflect the exchange’s post-breach position. Withdrawals will remain unavailable until Bitget completes additional security checks. Chen said the company would announce a reopening window once it could do so with confidence rather than commit to a timetable before the review is finished. That leaves investigators pursuing two outcomes simultaneously: recovering assets before they move beyond reach and determining how much of Bitget’s own balance sheet it will ultimately need before customers regain full access to their funds. The post Bitget’s North Korea-linked $352 million hack could drain 76% of its protection fund appeared first on CryptoSlate .
Open source - TB
The BlockArticle ·
Bitget confirms $387.5 million security breach affecting exchange hot wallets Bitget said private keys were not compromised and that losses from the incident will be covered by its User Protection Fund.
Open source - LS
Laura Shin@laurashinPost on X ·
"Seven minutes after the first large transfer, our platform's reconciliation system detected a significant discrepancy and the risk system automatically blocked all the user initiated withdrawals ... But this didn't stop the bleed because the hackers ... hacked into our internal system using a third-party zero-day vulnerability," @GracyBitget on the Bitget hack. https://t.co/AJIgCQzWTW
Open source - CN
CNBC@CNBCPost on X ·
Crypto exchange Bitget suspects North Korean hackers may be behind a security breach that affected about $351.6 million in digital assets. Bitget CEO Gracy Chen said investigators identified internet protocol addresses linked to VPN services previously used by a North Korean hacking group. The pattern of the attack also resembled earlier operations attributed to the country. Learn more about the hack and its implications: https://t.co/PzbpImNuAy
Open source - WB
Wu Blockchain@WuBlockchainPost on X ·
GoPlus: Bitget’s $387.5M Hack Exploited the Transaction-Signing Trust Chain, Not Private Keys GoPlus Security said its review of Bitget’s $387.5 million security incident found that the attack did not involve a private-key leak, but rather a compromise of the transaction-signing trust chain. Attackers breached a critical wallet backend system, forged transaction data, and caused Bitget’s authorized signing flow to generate valid signatures for transfers the exchange did not intend to make. GoPlus said the fund-drain window lasted about 2 hours and 25 minutes, with the largest wave moving roughly $185 million in about one minute. It has blacklisted attacker-linked addresses and shared them with ecosystem partners. GoPlus said the incident shows structural similarities to the 2025 Bybit hack, though Bitget has not yet published a full technical report and the initial intrusion method remains unconfirmed.
Open source - CB
Coin Bureau@coinbureauPost on X ·
🚨NEW: Bitget CEO says she is “NOT very optimistic” about recovering funds stolen in the exchange’s $388 MILLION breach. Gracy Chen pointed to the 2025 Bybit hack as a reference, saying only about 3.5% of stolen funds had been frozen roughly a year later. “That’s only the freezing. It’s not about recovery yet.” Bitget says its $464 MILLION protection fund covers every user. Trading and deposits remained open, while withdrawals resumed today.
Open source - TB
The Block@TheBlockCoPost on X ·
THE BLOCK: Bitget CEO Gracy Chen says the attacker behind the $388 million exploit ran two test transfers below the exchange's risk-control threshold 30 minutes before draining hot wallets. The attacker exploited a zero-day vulnerability in a third-party security product, then erased traces of the commands they ran. Private keys and cold wallets were not compromised.
Open source - LS
Laura Shin@laurashinPost on X ·
"The attacker or the hackers ... did some test transfers ... both were below the risk control threshold and did not trigger a system alert," @GracyBitget on the Bitget hack. https://t.co/nCkgzLguCn
Open source - WB
Wu Blockchain@WuBlockchainPost on X ·
Bitget CEO Details How Attackers Stole Approximately $380M In a September 28 livestream, Bitget CEO Gracy Chen @GracyBitget said attackers exploited a zero-day vulnerability in a third-party security product to obtain internal credentials. They used those credentials to access wallet backend systems, insert fraudulent withdrawal commands and bypass risk controls, then deleted traces of the transfers. Chen said private keys were not compromised and an inside job had been preliminarily ruled out. Bitget has not identified the attackers and plans to release an incident report.
Open source - CO
Cointelegraph@CointelegraphPost on X ·
🚨 UPDATE: Bitget says its breach came from a third-party security vulnerability, not compromised wallet private keys. https://t.co/NMIwpmLjdQ
Open source - CR
CryptoSlateArticle ·
Bitget had 30 minutes to contain its hack before $290 million started moving Bitget detected unauthorized wallet transfers about 30 minutes before attackers began draining hundreds of millions of dollars from the crypto exchange, raising questions about why its security response failed to contain the breach. The exchange said its systems flagged unauthorized transfers at 18:31 UTC on Sept. 24 and that its security team immediately activated emergency protocols. However, blockchain security firm Hypernative's reconstruction of the attack shows that most losses came later: $87.6 million left hot wallets at 19:01, and another $202.8 million left warm wallets at 19:16. Those two bursts, completed in a combined 24 seconds, accounted for about three-quarters of the $387.5 million Bitget ultimately said was moved to attacker-controlled addresses. The sequence suggests Bitget had roughly half an hour after its initial alert to prevent the first major wave and about 45 minutes before the largest transfer burst. It also shifts scrutiny from how the attacker first gained access to how the exchange responded once its own systems indicated something was wrong. Hypernative said the attacker initially tested the compromised route at 18:31 with transfers of 0.84 ETH and 93 TRX to new addresses. After waiting about 28 minutes, the attacker moved $34.75 million of USDT at 18:58 before accelerating the drain across multiple blockchains. Bitget's containment controls failed to stop the signing? Bitget said its investigation found that the attacker compromised a backend system in its wallet infrastructure, spoofed withdrawal data, and tricked the exchange's authorization process into approving the transfers. The company said private keys were not compromised. That attack path makes the response window especially significant. Hypernative said the transactions were signed by Bitget's own wallets and resembled ordinary customer withdrawals closely enough to pass through its infrastructure. The security firm identified several controls that could have interrupted the attack after the initial alert. One would have required every signed transfer to correspond with an independently stored customer withdrawal or approved treasury transaction. Such a check could have prevented a compromised backend service from creating its own authorization. Hypernative also found unusual transaction parameters in the attacker's requests, including gas limits that differed from Bitget's normal withdrawal pipeline . Comparing proposed transactions against parameters normally generated by the exchange could have flagged the 18:31 test transaction before the larger withdrawals began. Velocity limits provided another potential barrier. Hypernative said warm wallets moved $202.8 million across five networks within nine seconds at 19:16. Caps on how much individual wallet tiers could transfer within short periods, coupled with secondary approval requirements, could have delayed or blocked much of that wave. Most critically, Hypernative said anomalous-transfer alerts could trigger an automatic suspension of the affected signer rather than relying on manual intervention. Instead, attacker-linked transfers continued until 21:23 UTC, almost three hours after Bitget's stated detection time. Bitget has since said it remediated the vulnerability and that no further unauthorized transfers occurred after containment. Mandiant and SlowMist remain involved in the forensic investigation. Related Reading Bitget’s $351.6 million hack pushes September crypto losses to 2026 high The unresolved issue is now what Bitget's security systems did with the 18:31 alert and why the compromised signing route remained operational long enough for roughly $290 million to leave in the two major waves that followed. The post Bitget had 30 minutes to contain its hack before $290 million started moving appeared first on CryptoSlate .
Open source - CO
CoinMarketCap@CoinMarketCapPost on X ·
UPDATE: 🚨 Bitget CEO Gracy Chen says the exchange has brought in Mandiant and SlowMist to investigate its ~$351.6M hack, with withdrawals still suspended. https://t.co/kqmRaUpOZX
Open source

