Bitget Hack Drains $351M: What Wallet Users Should Know
Bitget lost roughly $351.6 million (USD) from its hot wallets on 24 September 2026, after internal systems flagged unusual outflows within minutes. Anyone holding crypto on an exchange should take note: this shows how fast a hot wallet breach unfolds, and how much rests on the safety net behind it.
What actually happened
Bitget CEO Gracy Chen said monitoring caught abnormal withdrawals from several hot wallets at 18:31 UTC on 24 September 2026. Early internal estimates put losses near $351.6 million (USD), according to Wu Blockchain. Cold storage stayed untouched and user balances were unchanged. Bitget paused withdrawals but kept deposits and trading running, citing a protection fund over $464 million (USD). Separately, Arkham Intelligence and Bubblemaps tracked on-chain outflows of $178 million to $190 million (USD), linked to a wallet tagged Bitget Exploiter 1. A full report is due before 21:30 UTC on 25 September 2026.
How we got here
This echoes February 2025, when Bybit lost about 400,000 ETH, worth $1.4 to $1.5 billion (USD), the largest exchange hack on record, later traced to a compromised Safe multisig interface tied to Lazarus-linked hackers. Bitget lent Bybit 40,000 ETH, worth about $105 to $106 million (USD), interest-free at the time, and Bybit repaid it within days. Earlier breaches at Coincheck, KuCoin, and Bitmart followed the same pattern: stolen keys or manipulated signing tools drained wallets built for daily convenience.
Why this matters for you
Bitget's intact cold wallets and protection fund suggest balances should stay whole, even with withdrawals frozen for now. For anyone using centralized exchanges daily, the takeaway is simple: funds kept for quick access carry more risk than self-custody or cold storage. For bonuz.market users, treat exchange balances as spending money, not savings, and keep long-term holdings in wallets you control. Builders industry-wide face pressure to harden signing interfaces and key management, since both stolen keys and tampered interfaces have caused major hacks before.
The bigger question
Exchanges keep absorbing losses through insurance funds and emergency loans to each other. Does that pattern make the system safer over time, or just delay a harder reckoning over how much crypto custody still sits in hot wallets, where one compromised key can move hundreds of millions in minutes? Who should bear that cost when it happens again?
What to watch
Bitget owes hourly updates and a full root-cause report before 21:30 UTC on 25 September 2026, which should clarify whether stolen keys or a manipulated interface caused the breach. Watch whether the $351.6 million (USD) internal figure converges with the $178 to $190 million (USD) on-chain estimates. Law enforcement is reviewing the case.






