Was Bitget Hacked? Bitget Hack Update: Timeline, Impact and Response
Contents · 15 sections
Was Bitget Hacked? Bitget Hack Update: Timeline, Impact and Response
Bitget official incident update on the September 24, 2026 hot/warm wallet theft (last updated October 3, 2026). FAQ section trimmed.
Updated: October 3, 2026
Was Bitget Hacked? What Actually Happened
At approximately 18:31 UTC on September 24, 2026, unauthorized transfers involving certain assets were made across multiple blockchains from a portion of Bitget’s hot and warm wallet infrastructure.
The latest investigation found that the attacker exploited a vulnerability in a third-party security product to obtain high-level internal credentials. The attacker then used those credentials to send fraudulent withdrawal commands to the wallet system, resulting in abnormal transfers that bypassed existing risk controls.
Bitget’s security team subsequently identified the attack path and methods used in the incident. The affected systems were isolated and the underlying vulnerability was remediated.
On September 28 at 07:30 UTC, Bitget CEO Gracy Chen hosted a live AMA to address the security incident, the phased withdrawal resumption and questions from the community.
On September 30, independent investigation reports from Mandiant and SlowMist became available, providing additional findings on the September 24 security incident.
On October 2, Bitget completed its phased withdrawal-resumption plan. Withdrawals for other supported tokens, along with fiat and C2C services, resumed following the earlier restoration of BTC, ETH and USDT withdrawals.
The incident remains contained, and no further unauthorized transfers have been identified following containment. Asset tracing, recovery and further security work remain ongoing.
This article reflects information verified as of the latest update and will be revised if material new findings are confirmed.
Bitget Hack Timeline: Key Events and Latest Updates
The timeline below reflects confirmed developments from the initial unauthorized transfers through the investigation and full completion of the phased withdrawal-resumption plan.
- September 24, 18:31 UTC — The first unauthorized transfers occur from a portion of Bitget’s hot and warm wallet infrastructure.
- September 24, 19:05 UTC — Bitget’s reconciliation system detects a significant discrepancy, and the risk-control system automatically blocks withdrawal requests across the platform.
- September 24, 19:14 UTC — Bitget activates its highest-level emergency response.
- September 24, 19:40 UTC — Containment measures begin.
- September 24, 20:40 UTC — As private-key compromise has not yet been ruled out, the wallet team begins transferring funds to cold wallets.
- September 24, 21:44 UTC — Wallet withdrawal services, including signing services, are shut down and withdrawal-related access is isolated.
- September 25, 08:43 UTC — Bitget’s security team identifies the root cause of the incident.
- September 25, 13:42 UTC — The incident is reported to law enforcement in the jurisdiction where the relevant Bitget entity is based.
- September 26, 04:00 UTC — Following vulnerability remediation, service isolation and security checks, the phased withdrawal-resumption schedule is confirmed.
- September 28, 08:00 UTC — BTC withdrawals begin resuming as scheduled.
- September 29, 08:00 UTC — ETH withdrawals resume across Ethereum, BSC, Arbitrum, Base and Optimism.
- September 29, 15:59 UTC — Bitget releases its 47th Proof of Reserves update, reporting an overall reserve ratio of 131% across 19 covered assets.
- September 30, 05:20 UTC — Independent investigation reports from Mandiant and SlowMist become available.
- September 30, 08:00 UTC — USDT withdrawals resume across Ethereum, BSC, Solana and Tron.
- September 30, 09:00 UTC — The Bitget Protection Fund is replenished to more than $300 million.
- October 2, 08:00 UTC — Withdrawals for other supported tokens, along with fiat and C2C services, resume, completing the phased restoration plan.
Asset tracing, recovery and further security work remain ongoing. Material updates will continue to be published through Bitget’s official channels.
How Much Was Affected in the Bitget Hack?
The final verified amount affected is approximately $388 million.
The transfers involved 12 wallet addresses associated with hot or warm wallets.
The $388 million figure reflects the final verified accounting and classification of transactions associated with the original September 24 incident. It does not represent additional unauthorized transfers following containment or a separate security incident.
No further unauthorized transfers have been identified following containment.
Which Assets and Networks Were Affected?
The incident involved activity across 11 blockchains:
-
Ethereum
-
XRP Ledger
-
Zcash
-
TRON
-
Arbitrum
-
Optimism
-
Base
-
BNB Smart Chain
-
Avalanche
-
Algorand
-
Celestia
Affected assets identified to date include XRP, ETH, USDT, ZEC, ATOM, USDC, USD0, XAUt, BNB, AVAX, TRX, ALGO and TIA.
The incident was limited to a portion of Bitget’s hot and warm wallet infrastructure.
Bitget operates a three-tier wallet architecture comprising hot, warm and cold wallets. Cold wallets across all chains were not affected.
Based on the investigation, private-key compromise has been ruled out.
What Did the Investigation and Independent Reports Find?
The investigation identified an attack path involving a third-party security product and high-level internal credentials.
The attacker exploited a vulnerability in the third-party security product to gain access to high-level credentials and used them to send fraudulent withdrawal commands to the wallet system, bypassing existing risk controls.
On September 30, independent investigation reports from Mandiant, part of Google Cloud, and SlowMist became available.
Their findings broadly align with the attack path previously identified and provide additional detail on how the incident unfolded.
Both investigations identified the compromise of third-party security products as ultimately enabling unauthorized access to Bitget Exchange’s wallet environment.
The affected systems were isolated and the underlying vulnerability was remediated. The relevant third-party vendor was notified and the affected functionality was disabled.
The security review has also extended beyond the affected functionality. Bitget is strengthening controls around third-party product deployment, internal access, withdrawal verification and abnormal-activity monitoring.
Was Bitget Wallet Hacked?
No. Bitget Wallet was not affected by the incident.
Bitget Wallet is a separate, non-custodial product and operates on infrastructure separate from the exchange wallet systems involved in the security incident.
Bitget Wallet users’ assets remain onchain under users’ control.
How Did Bitget Contain and Respond to the Incident?
The immediate response focused on containing unauthorized activity, isolating affected infrastructure and validating systems before withdrawal services were restored.
Following containment:
-
no further unauthorized transfers have been identified;
-
the affected systems and relevant servers were isolated;
-
the attack path and methods used in the incident were identified;
-
the underlying vulnerability was remediated;
-
internal login credentials were revoked and reissued;
-
access to highly sensitive systems was restructured;
-
multiple approvals are now required for critical operations;
-
the relevant third-party vendor was notified and the affected functionality disabled;
-
withdrawal verification was strengthened;
-
Mandiant and SlowMist conducted independent investigations;
-
law enforcement agencies and financial intelligence units were notified;
-
fund tracing and recovery efforts began with industry partners.
Bitget is also strengthening its assessment of third-party security products and anomaly monitoring to improve alert reliability and enable earlier detection of potential threats.
The findings from the Mandiant and SlowMist reports are being incorporated into the broader security review, while asset tracing and recovery efforts remain ongoing.
Are User Account Balances Affected?
No. User account balances remain unaffected.
The temporary withdrawal pause was implemented as a security measure and was unrelated to the sufficiency or availability of user assets.
Its purpose was to allow security and technical teams to secure and validate withdrawal infrastructure before individual networks reopened.
Trading and deposits continued to operate throughout the withdrawal-restoration process.
Bitget’s Protection Fund covers the financial impact of the platform-wide incident.
How Does the Bitget Protection Fund Apply to the Incident?
The Protection Fund serves as an additional financial protection mechanism for eligible platform-wide security incidents.
For the September 24 security incident, the financial impact falls within the coverage of the Protection Fund.
On September 28, Bitget committed to replenishing the fund to at least $300 million within one week. On September 30, the Protection Fund was replenished to more than $300 million, ahead of that deadline.
The fund remains publicly verifiable onchain, allowing users to independently view the associated wallet addresses.
The Protection Fund is separate from Proof of Reserves. Proof of Reserves provides transparency into assets held by the platform relative to covered user balances, while the Protection Fund is designed as an additional financial protection layer.
What Is Bitget’s Latest Proof of Reserves?
Bitget published its 47th Proof of Reserves update following the security incident.
Based on the September 29 snapshot, Bitget’s latest overall reserve ratio stands at 131% across 19 covered assets.
All 19 covered assets were reported above the 100% reserve benchmark, meaning the covered user assets remained backed at more than 1:1 based on the latest snapshot.
The September 24 security incident did not impact Bitget’s reserves.
Proof of Reserves remains separate from the Protection Fund. PoR provides transparency into platform reserves relative to covered user balances, while the Protection Fund provides an additional layer of financial protection.
Why Were Withdrawals Temporarily Paused?
Withdrawals were temporarily paused to allow Bitget’s security and technical teams to secure and validate withdrawal infrastructure across multiple blockchains and assets.
The underlying vulnerability was identified and remediated, after which additional security checks were conducted for individual withdrawal routes before they reopened.
The pause was a precautionary security measure rather than an indication of insufficient user assets.
Trading and deposits continued to operate while these checks were carried out.
Have Bitget Withdrawals Fully Resumed?
Yes. Bitget completed its phased withdrawal-resumption plan on October 2, 2026.
BTC withdrawals were restored first on September 28, followed by ETH on September 29 and USDT on September 30.
On October 2, withdrawals for other supported tokens resumed, together with fiat and C2C services that had been temporarily suspended following the incident.
The completed rollout was:
Date and Time (UTC)Asset / Service Status September 28, 08:00 BTC Withdrawals resumed September 29, 08:00 ETH Withdrawals resumed across Ethereum, BSC, Arbitrum, Base and Optimism September 30, 08:00 USDT Withdrawals resumed across Ethereum, BSC, Solana and Tron October 2, 08:00 Other supported tokens / Fiat / C2C Services resumed and phased restoration plan completed
The phased approach allowed individual assets and networks to reopen after the required security validation had been completed.
The same restoration approach applied across users without priority based on account tier.
What Do the Mandiant and SlowMist Reports Show?
Bitget engaged Mandiant, part of Google Cloud, and SlowMist to independently investigate the September 24 security incident.
Reports from both firms became available on September 30.
Their findings broadly align with the attack path previously identified and provide additional information on how the incident unfolded.
Both investigations identified the compromise of third-party security products as ultimately enabling unauthorized access to Bitget Exchange’s wallet environment.
The reports provide independent analysis of the incident and are informing improvements to Bitget’s security controls.
Their publication does not mark the end of all post-incident work. Asset tracing, recovery and broader security improvements remain ongoing.
This also applies to public speculation regarding attacker attribution. Attribution should only be treated as confirmed if supported by verified investigative findings.
How Is Bitget Tracing and Recovering the Affected Assets?
Bitget is working with law enforcement agencies, onchain security specialists, exchanges, blockchain projects and other ecosystem participants to trace and recover affected assets.
Some affected assets have already been frozen through coordination with industry partners.
Bitget has also published identified attacker addresses and relevant tracing information to support broader industry collaboration and asset recovery.
A Recovery Bounty Program remains in place. Eligible voluntary actions that directly result in affected funds being frozen or recovered may qualify for a bounty equal to 5% of the amount frozen or recovered, subject to the program’s terms and eligibility requirements.
Assets frozen or recovered through law enforcement or other legal proceedings are not eligible for the bounty.
Bitget is also using Bybit’s LazarusBounty as one of its asset-recovery channels.
Because recovery efforts remain ongoing, frozen, recovered and outstanding amounts should only be reported once they have been verified.
What Happens Next?
With the phased withdrawal-restoration plan completed, the focus has shifted to asset tracing and recovery, continued security validation and longer-term security improvements.
The current priorities include:
-
tracing and recovering affected assets;
-
cooperating with relevant authorities, exchanges, blockchain projects and security specialists;
-
applying findings from the Mandiant and SlowMist investigations;
-
strengthening controls around third-party security products;
-
reviewing internal access and critical-operation controls;
-
strengthening withdrawal verification and abnormal-activity monitoring;
-
continuing to publish verified updates as material developments are confirmed.
The vulnerability has been remediated and the incident remains contained. No further unauthorized transfers have been identified following containment.
Cold wallets were not affected, private-key compromise has been ruled out, user account balances remain unaffected, and the phased restoration of withdrawals and related services has been completed.
Further verified information will be published through Bitget’s official channels as asset recovery and post-incident security work continue.
Tags
Only on this entry: hot-wallet