Bitget's systems flagged unauthorized transfers out of exchange hot wallets at 18:31 UTC on 24 September 2026, and by the following morning the Bitget hack had become one of the largest exchange losses of the year. CoinDesk reported the figure at 351.6 million USD. Deposits and trading stayed open, withdrawals were paused, and the exchange said its protection fund would absorb the whole loss. What follows is what is known as of 25 September 2026, and the part of it that matters to anyone holding coins somewhere other than their own device.
How the Bitget hack worked
The attackers never held the keys. According to CEO Gracy Chen, "the attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out," and she stated flatly that "private key compromise has been ruled out." Her own comparison was to forged withdrawal slips pushed through legitimate bank channels while the vault keys never left the building.
The assets went out across several networks. Reporting on the incident lists ether, XRP, BNB, AVAX, USDT and USDC among the stolen holdings, with roughly 183 million USD swapped into ether, which is the usual early step when somebody needs to consolidate a large haul before moving it. Chen said during an X livestream that the company suspects North Korea, an attribution that fits the pattern of the largest exchange thefts of recent years but that nobody outside an investigation can confirm yet.
Why the cold wallets survived and the hot ones didn't
Here is the detail worth sitting with. The breach reached Bitget's hot and warm wallet layers, and its cold wallets came through untouched, because a system that is offline cannot be instructed by a compromised backend no matter how convincing the forged instruction looks. The attacker had working access to the machinery that authorizes transfers and still could not reach anything that required someone to approve it on a device sitting outside the network.
That is the same property a hardware wallet gives one person. Keys generated inside a chip that has no network connection are unreachable by any server that gets compromised, whether the server belongs to an exchange, a wallet company or you. Bitget's own architecture made the argument for cold storage more plainly than any marketing page could, and the company deserves credit for having built that separation in the first place.
The part that affects you even if the money comes back
Bitget's response looks solid on the numbers. The User Protection Fund holds over 464 million USD against a 351.6 million USD loss, Chen said containment was confirmed and no further unauthorized transfers were possible, and the exchange has told users their balances are accurate and their assets protected. Measured against how these events usually go, that is close to the good outcome.
It still leaves 120 million registered users in a position worth understanding. For as long as the security review runs, a balance on Bitget is a number on a screen that nobody can move, and the thing standing between that number and actual coins is a company's willingness and ability to honour it. That willingness is well funded here and it has been absent elsewhere, which is the whole lesson: the custody question is never whether your exchange is trustworthy today, it is what you are exposed to on the day something goes wrong.
Note also that the funds moved while Bitget's own controls were working as designed. Nobody was careless with a password. The authorization process ran and approved transfers that looked legitimate to it, which is a harder problem than a stolen credential and one you cannot audit from the outside.
If you had funds on Bitget
Wait for the official channels and ignore everything else that arrives. Large hacks are followed within hours by emails, direct messages and fake support accounts offering to help you recover or secure your funds, and the people behind them are counting on exactly the anxiety this situation produces. Bitget will not ask you for a recovery phrase, and nobody legitimate ever will.
When withdrawals reopen, treat it as a decision point rather than a return to normal. Work out how much you keep on an exchange because you are trading with it, and how much is sitting there because moving it was never urgent enough to do. The second number is the one this week is asking about.
What your own backup has to survive
Moving coins off an exchange trades one risk for another, and being clear-eyed about that is the difference between a good decision and a panicked one. You take on the job of not losing the keys, and most self-custody losses come from that rather than from attackers. Paper degrades and gets thrown out. Steel plates handle fire and water and are the sensible upgrade from paper, though one object still grants everything to whoever reads it and costs you everything if it disappears.
TapSafe Recovery removes that single point of failure. Half of what a recovery needs lives on the Recovery Tag and half on your paired phone, encrypted in your own iCloud or Google Drive rather than on the handset, so a lost phone costs you nothing and neither half reveals anything alone. Optional Recovery Contacts hold a quarter share each and can see no balances or addresses. Your seed phrase stays reachable on the device as a last resort under the BIP-39 standard, so you keep the freedom to move to other hardware whenever you want.
Where this leaves the question
An exchange is the right tool for buying and trading, and a poor one for keeping. Bitget's cold wallets demonstrated the principle at company scale on 24 September, and the same principle is available to you for the price of a device you tap to approve what it shows you on screen.
Ryder One is 149 USD for the Starter Combo, and the Super Safe Combo is 179 USD. It covers Bitcoin, Ethereum, Solana and a growing list of top ERC-20 and SPL tokens, so check your holdings against that list before planning a move. Keys are generated inside an EAL6+ certified Infineon SLC38 secure element and never leave the chip, the device communicates over NFC only with no Bluetooth, no Wi-Fi and no wired data path, and every transaction is shown in readable detail on the 1.6-inch AMOLED touchscreen before you approve it. The firmware has been audited by Halborn with the full report published, and setup takes about sixty seconds.
Meta description: The Bitget hack moved 351.6M USD through spoofed transfers while the keys stayed intact. Why cold wallets survived, and what frozen withdrawals mean for you.




Share: