# Bitget Security Breach Exposes $351.6 Million in Cryptocurrency

*Published September 28, 2026*
*Source: [https://cybersecuritynews.com/bitget-hot-wallet-hacked/](https://cybersecuritynews.com/bitget-hot-wallet-hacked/)*

## Executive Summary

*This is a Premium edition. The Executive Summary is available to sec-news.ai members —*
*[read it here](https://www.sec-news.ai/news/bitget-security-breach-exposes-351-6-million-in-cryptocurrency) or [see plans](https://www.sec-news.ai/pricing).*

## Article

Cryptocurrency exchange Bitget has suffered a significant security breach that led to the unauthorized transfer of approximately $351.6 million from its hot and warm wallets. This breach was identified on September 24, 2026, at 18:31 UTC, prompting an immediate response from Bitget's security team. Fortunately, the company's offline cold wallets were not affected, ensuring that customers' account balances remain accurate.

The breach was restricted to certain components of Bitget’s three-tier wallet system. Although a comprehensive list of the stolen assets has not been published, on-chain analysis revealed movements involving cryptocurrencies such as ETH, BNB, AVAX, USDT, and USDC. Initial estimates suggested losses between $174 million and $183 million, but further investigation confirmed the larger figure of $351.6 million.

In response, Bitget temporarily halted withdrawals while its systems undergo a thorough security review. However, deposits and trading services remain operational. The exchange has flagged suspicious recipient addresses, engaged law enforcement, and enlisted the help of blockchain security firms to track the stolen funds. Bitget’s CEO, Gracy Chen, assured users that the financial loss is covered by the company's User Protection Fund, which exceeds the stolen amount by $112.4 million.

During a live Q&A session, Chen mentioned that preliminary evidence indicates potential links to North Korean cybercriminals, possibly the notorious Lazarus Group. Despite these findings, Bitget refrains from making definitive attributions until the investigation is finalized. Notably, the attackers transferred assets immediately after breaching Bitget systems, suggesting a compromise of backend components rather than private keys. Investigators are exploring the possibility of a third-party or supply-chain vulnerability being exploited.

Bitget has committed to providing hourly updates and a comprehensive incident report within 24 hours. Customers are advised to follow only official communications from Bitget, be wary of phishing attempts, and avoid sharing credentials or signing unverified requests.
