Bitget Reports $387.5 Million Hack
Bitget reports a $387.5 million wallet breach and plans to reopen withdrawals in stages from September 28. The exchange says customer balances remain intact as investigators trace stolen funds.


The cryptocurrency exchange says customer balances remain intact as investigators trace stolen assets and security teams prepare to restore withdrawals.
September 26, 2026 — Cryptocurrency exchange Bitget has raised its assessment of a September 24 security breach to approximately $387.5 million, after investigators identified additional assets transferred to attacker-controlled addresses.
The revised figure is up from an initial estimate of $351.6 million. Bitget said the increase reflects previously uncounted transfers involving Zcash and TRON, rather than another attack or further unauthorized withdrawals.
The exchange detected suspicious transfers at 18:31 UTC on September 24 and suspended withdrawals while conducting a security review. According to its initial notice, the breach affected portions of its hot and warm wallet infrastructure. Cold wallets remained secure, while deposits and trading continued.
Bitget says it has identified and fixed the underlying vulnerability. Cybersecurity firms Mandiant and SlowMist are assisting with the investigation, and the exchange is conducting additional checks before restoring withdrawal services.
Withdrawals scheduled to reopen in stages
The announced reopening begins with Bitcoin on September 28, followed by Ether on September 29 and USDT on September 30. Other tokens, fiat withdrawals and peer-to-peer services are scheduled for October 2. Each phase is scheduled for 08:00 UTC, according to reporting on Bitget’s restoration notice.
These are planned reopening dates; they do not mean withdrawals have already resumed.
Exchange pledges to cover the loss
Bitget said customer account balances remain accurate and that the incident falls within the coverage of its User Protection Fund, which held more than $464 million when the initial notice was published. That assurance is the exchange’s statement about its ability to absorb the loss, rather than evidence that the stolen assets have been recovered.
Recovery efforts are proceeding separately. Bitget has offered eligible participants a bounty equal to 5% of funds successfully frozen and another 5% of funds successfully recovered, subject to its program conditions. It said some assets had been frozen through industry cooperation.
Investigation leaves questions unanswered
Independent blockchain analysis by Bitquery found that transfers continued for nearly three hours after Bitget’s stated detection time. That timeline raises questions about how quickly the exchange’s emergency controls contained the breach.
Reporting on CEO Gracy Chen’s preliminary assessment has pointed to a possible North Korean connection. Attribution remains unconfirmed, and a complete public explanation of the security failure remains an important outstanding part of the investigation.
For customers, the next test is operational: whether Bitget restores access on schedule and provides a clear account of what failed, what was repaired and how much money can be recovered.
