Bitget Says $351.6M Left Its Hot Wallets as Withdrawals Stay Shut

Bitget detected unauthorized transfers out of its hot and warm wallets at 18:31 UTC on Thursday. By early Friday the exchange had put the total at $351.6 million. Chief executive Gracy Chen said attackers reached the backend systems that instruct those wallets and forged transfer requests, and that private key compromise has been ruled out. Cold wallets were untouched. Deposits and trading stayed open, withdrawals were suspended, and no date has been given for their return.
Forged slips, not stolen keys
Bitget runs what Chen calls a three-tier wallet architecture. Cold storage sits offline, hot wallets are connected to the internet to fund withdrawals, and warm wallets are the semi-connected buffer between the two. Only the hot and warm layers were reached, by her account. The attack needed no key at all.
"Private key compromise has been ruled out," Chen said, describing the breach as "the digital version of slipping forged withdrawal slips through a bank's own teller window."
That description arrived in stages. TheStreet, writing on Thursday, quoted her saying the company would "not speculate on the attack vector until the investigation is complete." CoinDesk's Friday piece, published at 04:29 UTC, has her ruling the vector out and naming the mechanism. About seven hours separate the two accounts, and neither says when the finding firmed up. Chen added that no further unauthorized transfers are possible.
Nobody's list of the stolen assets matches
Three accounts, three inventories. CoinDesk names ether, BNB, AVAX and USDT moving across several chains into one address. Bitcoin Magazine reports that the security firm Hacken later confirmed bitcoin was among the assets, and bitcoin turns up in nobody else's list. The Crypto Times carries a nine-asset breakdown credited to the analytics account Lookonchain, in which XRP is the largest line at $157.48 million, ahead of ether at $85.75 million. Those nine figures add to $356.9 million, roughly $5 million above the headline total, and no outlet performs the sum. The lists do not reconcile.
Attribution is no firmer. An onchain researcher quoted by The Crypto Times noted overlaps with wallets researchers tie to the Lazarus Group, and the same report says Bitget has not confirmed the link. Chen's own preliminary read came hedged in the same breath: the attribution is not yet certain. She said the company does not believe the breach was an inside job.
What the fund would have to cover
Bitget says a user protection fund holding more than $464 million covers the loss in full and that customer balances are accurate. The Crypto Times is alone in doing the arithmetic on that claim, putting a payout at roughly 76% of the fund and leaving about $112 million, against company capital it places above $1 billion. A separate follow-up credits the exchange with an August reserve ratio of 122% across 45 months of proof-of-reserves reports. Both figures rest on one account.
The freeze is the part nobody can test
BGB, the exchange's own token, changed hands near $1.963 in Asian hours on Friday, against a pre-hack range of $2.02 to $2.06. CoinDesk had it 2.9% lower at Thursday's press time, after a sharper initial drop. Most BGB trading happens on Bitget itself, where withdrawals are frozen, so a buyer cannot move the coin off. Detection was not the exchange's own work: independent researchers and Arkham Intelligence, which stood up a dashboard for the movements, flagged the wallets first. One account has the transfers running for nearly three hours after 18:31 UTC, with the last ether leaving 52 minutes before the first public notice. It stands unverified.
A full incident report with a root-cause analysis was promised within 24 hours of Thursday's 21:30 UTC notice, which puts it late on Friday. If $351.6 million holds, this is the largest crypto theft of 2026, ahead of the sum that left Blockstream's Liquid federation on 6 September — CoinDesk gives that one as $320 million and TheStreet as $319 million, and the two do not reconcile. What no statement covers is when withdrawals reopen.
Read also: Stolen Keys Cost More Than Code Bugs in DeFi's 2026 Loss Tally