Go Back

Bitget Hack Loss Climbs to $387.5m

Bitget Hack Loss Climbs to $387.5m

Nuwan Liyanage

Nuwan Liyanage

Make Catenaa preferred on (opens in a new tab)

September 27, 2026 – The exchange raised its estimate by $35.9m and set a four-step withdrawal plan. Its $464m protection fund still covers the hole, but the incident ranks among the largest exchange thefts on record.

In Summary

Bitget raised its loss estimate to $387.5m from $351.6m after finding extra transfers on Zcash and TRON.

Withdrawals restart in phases, with Bitcoin on 28 September and all other assets by 2 October.

The exchange says its User Protection Fund, above $464m, covers the loss, and user balances stay intact.

DefiLlama data rank the Bitget hack as the largest crypto theft of 2026 so far.

The Bitget hack is bigger than first thought. In an update on 25 September, the exchange said about $387.5m moved to addresses controlled by the attacker. That is 10% more than its first estimate of $351.6m.

Bitget said the higher figure reflects a fuller count of transfers, not fresh theft. It added assets on Zcash and TRON that its first estimate missed. Moreover, the company says it has contained the incident, and no further unauthorised transfers are possible.

How the Bitget hack unfolded

Bitget’s systems flagged unauthorised transfers from some hot wallets at 18:31 UTC on 24 September. Its first security notice set out the early details. The exchange runs a three-tier wallet system. Only part of the hot and warm layers suffered losses, while cold wallets remained secure.

The stolen assets span Ethereum and several related networks, the XRP Ledger, Zcash and TRON. Bitget lists XRP, ether, USDT, USDC, Zcash, BNB, AVAX, TRX, tokenised gold and cross-chain USDT among them.

Security firms Mandiant and SlowMist are helping with the probe. Bitget says it has found the attack path, including how the attacker bypassed existing controls. It also says the underlying flaw is now fixed.

Who pays for the loss?

For users, the key question is timing rather than solvency. Customers should not bear the cost, according to Bitget. It says user account balances remain unaffected and trading and deposits continue as normal.

The exchange’s User Protection Fund held more than $464m when the breach began. On that figure, the fund exceeds the revised loss by about $76.5m, on Catenaa’s calculations. However, a large payout would leave a much thinner buffer for any future incident.

Recovery work has already started. Bitget says partners have frozen some of the stolen assets. It now offers a bounty of 5% of any funds frozen and 5% of any funds recovered through outside help. So far, however, Bitget has not disclosed how much of the $387.5m partners have frozen.

Bitget will also use Bybit’s LazarusBounty initiative as a core channel for the effort. In addition, a live dashboard tracks the attacker’s addresses as funds move.

Withdrawals return in four steps

Bitget published its restart plan early on 26 September Asian time. Bitcoin withdrawals reopen at 08:00 UTC on 28 September. Ether follows the next day across five networks, including Arbitrum and Base.

Tether withdrawals come back on 30 September, and all other tokens, fiat and peer-to-peer services reopen on 2 October. Bitget says the same approach applies to every user without preference.

The company stresses that the pause is a security step, not a sign of missing funds. It says the delay lets it finish final checks before it restores services safely.

Chief executive Gracy Chen will host a live question session at 07:30 UTC on 28 September. Clear answers there could help calm users before the first withdrawals open.

Where the Bitget hack ranks

The theft stands among the largest ever at a centralised exchange. According to the DefiLlama hacks database, only Bybit, Coincheck, Mt. Gox and FTX lost more.

The Bybit case still dwarfs the rest. The FBI attributed the theft of about $1.5bn in February 2025 to North Korea. Bitget, by contrast, has not formally named an attacker.

The Bitget hack is also the largest of 2026 so far. DefiLlama tracks about $2.24bn in crypto hack losses this year. As a result, this single incident accounts for roughly 17% of the total.

Hot wallets stay online so users can withdraw quickly. That convenience also creates a standing target for attackers. Key theft has therefore become a recurring theme. DefiLlama classifies the Bitget case as a hot wallet key compromise, the same category as the Coincheck loss in 2018.

What traders should watch next

The next few days will test confidence in the exchange. Bitcoin holders will have waited almost four days by the time the first withdrawals reopen, so any slip would sting. Traders will watch whether withdrawals open on time and whether queues build once they do.

Bitget has also promised further updates through its official channels. Meanwhile, exchanges and stablecoin issuers can use the published addresses to block stolen funds. Those addresses cover EVM chains, the XRP Ledger and Zcash.

For the wider market, the Bitget hack adds to pressure on exchanges to prove their reserves and harden hot wallets. Every large theft revives questions about how much customer crypto should sit online at any time.