Bitget says attackers stole $387.5 million from its hot and warm wallets. The exchange suspects DPRK-linked methods and says user balances are covered.
Attackers moved about $387.5 million from Bitget-controlled wallets in the largest reported crypto theft of 2026 so far. The final figure may still change as investigators classify more transactions, but it already exceeds the exchange's initial estimate of $351.6 million.
The breach did not start with a public smart-contract exploit. According to the exchange, the attackers compromised a backend system connected to its wallet infrastructure, falsified the transaction data presented to the authorization layer, and caused legitimate systems to approve withdrawals. Bitget says its private keys and cold wallets were not compromised.
That distinction matters. Strong key custody does not help if the software deciding what those keys should sign has been manipulated.
Bitget says its monitoring systems detected unauthorized transfers at 18:31 UTC on September 24. It suspended withdrawals, flagged the receiving addresses, and brought in law enforcement and blockchain security firms. Deposits and trading remained available.
The first public estimate put the loss at $351.6 million. A later review raised it to $387.5 million after the exchange included additional ZEC and TRX transfers. The affected assets also included XRP, ETH, USDT, USDC, USDT0, XAUt, BNB, AVAX, and TRX across the XRP Ledger, Ethereum and other EVM networks, Zcash, and TRON.
Bitquery traced 21 outbound transfers across eight networks. Its timeline shows two tightly grouped bursts in which several chains paid attacker-controlled addresses within seconds. Transfers continued for almost three hours after the time Bitget says it first detected the incident.
This was not one wallet key being drained in a single transaction. The attackers reached several parts of the exchange's withdrawal infrastructure and moved different assets across multiple chains.
Hot and warm wallets hold assets that an exchange needs for routine withdrawals. They are online or otherwise accessible enough to move funds quickly, but transfers should still pass through internal checks before signing.
Bitget's account indicates that the attackers compromised a critical backend component and spoofed the data used by those checks. The authorization system approved transactions that appeared valid even though the destination and purpose had been manipulated.
The September 25 public update did not include a full technical post-mortem. It said the attack path had been identified, the underlying vulnerability had been fixed, and Mandiant and SlowMist were assisting with the investigation.
Until the post-mortem is available, claims about the exact entry point should be treated as preliminary.
The attackers split much of the ETH and XRP into newly created wallets. Some BNB and TRX was routed through cross-chain services and converted into bitcoin, while most of the stolen ETH remained in fresh wallets during the first days of tracing.
Stablecoin issuers can freeze tokens at specific addresses, but native assets such as ETH and XRP do not have an issuer with the same control. By September 26, Bitquery reported that Tether and Circle had frozen roughly $339,000 in USDT and USDC linked to the breach. That was only a small part of the total loss.
The exchange has launched a recovery bounty program offering 5% of funds successfully frozen or recovered when an eligible party's voluntary work directly produces that result. Court-ordered and law-enforcement actions are excluded from the program.
Bitget has said the attack showed IP behavior and on-chain patterns associated with North Korean operators. TRM Labs found links between the laundering network and wallets used after earlier attacks attributed to TraderTraitor, including the 2025 Bybit breach.
TRM has not made a definitive attribution. Its analysis says another actor remains technically possible and that more evidence is needed.
That qualification should stay attached to the claim. Similar infrastructure and laundering routes are evidence, but they do not by themselves prove who carried out the initial intrusion.
The comparison with Bybit is still relevant. The FBI attributed the February 2025 theft of about $1.5 billion from that exchange to North Korea's TraderTraitor operation. In both incidents, the attackers allegedly manipulated what an authorization process saw rather than simply stealing a private key.
Bitget says customer account balances remain accurate and that its User Protection Fund will cover the incident. The exchange valued that fund at more than $464 million when it first disclosed the breach.
Those are company statements, not an independent audit of every liability created by the hack. The clearest practical test for customers is whether withdrawals return on schedule and continue to process normally.
The published restoration plan starts with BTC withdrawals on September 28 at 08:00 UTC. ETH is scheduled for September 29, USDT for September 30, and other tokens, fiat withdrawals, and P2P services for October 2. The exchange says the vulnerability has been remediated and that no further unauthorized transfers are possible.
Users should check the live withdrawal status inside the platform rather than assuming every network has reopened at once.
Before this incident, the year's largest reported theft was the September 6 attack on Liquid Network. About $319 million in bitcoin was taken, although roughly 85% was later returned.
TRM Labs had counted about $1.73 billion stolen across 333 crypto incidents after the Liquid attack. The $387.5 million Bitget breach now becomes the largest single gross theft reported this year.
The incident also shows why exchange risk is not limited to insolvency or stolen signing keys. A backend service, transaction parser, policy engine, or approval interface can become the point of failure even when the underlying wallet cryptography remains intact.
For traders, a withdrawal pause creates its own exposure. Capital may still appear in an account while being unavailable for rebalancing, margin support, or a hedge on another venue. Keeping all operating liquidity on one exchange turns a security incident into a trading problem as well as a custody problem.
The useful response is not panic. It is to verify withdrawal availability, review open exposure, avoid relying on funds that cannot currently move, and follow incident updates through the exchange's official channels. Attackers often exploit the confusion after a breach with fake support messages and phishing links.