§ — Article

Bitget Hack, 24 Sep 2026: Losses, Remaining Assets and Resilience.

Bitget will very likely survive the $352M hack — about 5–7% of its on-chain assets. StarCompliance incident brief on losses and remaining reserves.

StarCompliance Desk
Editorial
Sep 28, 2026·5 min read
Share
Bitget Hack, 24 Sep 2026: Losses, Remaining Assets and Resilience
Article
№ 302
Incident brief · Analytical note · 25 September 2026 · StarCompliance Research
Key takeaway

Bitget will very likely survive the incident. The loss of roughly $352M equals about 5–7% of the exchange's on-chain assets and is smaller than its user protection fund (>$464M). The issue is not solvency but liquidity and trust: the outcome will be decided by the scale of outflows in the first days after withdrawals reopen.

$351.6M
loss
(official estimate)
$464M+
protection fund
(5,500 BTC)
$5.0–7.0B
on-chain assets
of the exchange
135%
reserve ratio
(PoR, September)

01  What happened

On 24 September at 18:31 UTC, Bitget's systems detected unauthorized transfers from part of its hot and warm wallets. According to CEO Gracy Chen, the attacker compromised a critical backend system of the wallet infrastructure, spoofed transaction data and triggered the standard authorization and signing process. Private key compromise has been ruled out. Cold wallets, according to the exchange, were not affected. Withdrawals are suspended; deposits and trading remain operational. Bitget preliminarily links the attack to DPRK-affiliated groups, but this has not been officially confirmed.

What it means: it was not the cryptographic layer that failed, but the chain of trust in front of the signer. The signing system approved the transfers because it trusted data from a compromised backend. This class of vulnerability applies to every exchange that automates hot-wallet top-ups.

02  Timeline (UTC, 24 Sep 2026)

TimeEvent
18:31Test transfer of 0.84 ETH from Bitget 6 to a fresh address (later tagged Bitget Exploiter 1)
19:01–19:16Main ETH outflows from Bitget 6 and Bitget 35; at the same time ~93.7M XRP leave two Bitget XRPL wallets
≈19:05–19:25USDT, USDC and XAUt move to a second address and are swapped into ~22,600 ETH to avoid issuer freezes
20:09–20:19Last ETH outflow from Bitget 35; the attacker splits ETH into 10,000 ETH batches across new addresses
20:55A further 8.2M USDC leaves Bitget 6 on Avalanche
21:23Last recorded on-chain outflows
21:30Official Bitget notice: loss ≈ $351.6M, withdrawals suspended

03  How much was stolen

Bitget's official estimate is $351.6M. Lookonchain's on-chain breakdown across nine assets gives $356.9M; the gap comes from pricing, not from additional losses.

XRP (102.93M)$157.5M · 44%
ETH (31,890)$85.8M · 24%
USDT / USDC / USDT0$75.5M · 21%
XAUt, BNB, AVAX, TRX$38.1M · 11%
AssetAmount$MStatus
XRP102.93M XRP157.5Mostly held on 7 XRPL addresses, not converted
ETH31,890 ETH85.8Being split across new addresses, partly via bridges
USDT / USDC / USDT0—75.5Almost entirely swapped into ETH
XAUt, BNB, AVAX, TRX3,000 XAUt; 12,719 BNB; 821,012 AVAX; 20.59M TRX38.1Partly converted into ETH
Total≈ 356.9Bitget estimate: 351.6

In total, the attacker consolidated EVM assets into roughly 67,982 ETH (~$183M). We assume the stablecoins had already been converted by the time issuers could react, so the chance of a Tether/Circle freeze is low. The main blocking potential lies in the XRP position and in cash-outs via centralized venues.

04  What remains

On the compromised wallets. On-chain data as of 20:32–20:50 UTC on 24 Sep (Etherscan snapshots):

WalletTaken by the attackerBalance at snapshot
Bitget 6
0x1AB4973a48dc892Cd9971ECE8e01DcC7688f8F23
9,010.9 ETH (~$24.2M) + 8.2M USDC (Avalanche)~$20.8M (≈ $12M after the 20:55 USDC outflow)
Bitget 35
0xffa8DB7B38579e6A2D14f9B347a9acE4d044cD54
15,362.5 ETH (~$41.3M) + 821,012 AVAX (~$8.5M)~$275.9M, mostly altcoins (UNI, ENA, AAVE); only 155 ETH left

Notably, the attacker took only liquid, easily moved assets (ETH, stablecoins, AVAX) and left hundreds of millions in altcoins untouched. According to TechFlow, about $530M remained on the compromised wallets after the attack.

Exchange-wide. Bitget's total on-chain assets are estimated at $5.0–7.0B (DefiLlama ~$5.0B; CoinMarketCap ~$6.4–7.0B; aggregator snapshot dates not stated). The September Proof of Reserves reported a 135% reserve ratio across 19 assets.

05  Is the buffer sufficient?

BufferSizeLoss / bufferComment
User Protection Fund>$464M (5,500 BTC)≈ 76%≈ $112M left after payout; value tracks BTC price; not independently audited
Own capital (CEO statement)>$1B≈ 35%Not independently verified
Reserve surplus over liabilities*≈ $1.3B≈ 27%Our estimate: ~$5B assets at 135% PoR
Exchange on-chain assets$5.0–7.0B5–7%Cold storage reportedly unaffected

* Derived figure: $5B − $5B / 1.35 ≈ $1.3B. PoR is a point-in-time snapshot and does not cover all assets; treat as an order-of-magnitude indicator.

The Bybit precedent (February 2025). A $1.5B loss — about four times larger. The exchange closed the gap with bridge loans, and withdrawals normalized within 72 hours. Bitget's scale makes a comparable recovery scenario realistic.

06  Scenarios

ScenarioEstimate*What happensOutcome for the exchange
Base case~70%Withdrawals reopen within days; outflows within $1–1.5B over the first weekLoss covered by the fund, operations normalize, moderate reputational damage
Stress case~25%Delayed reopening; outflows of $2B+ (30–40% of assets); pressure on BGBSurvives, but bridge financing, asset sales and loss of large clients are likely
Tail risk~5%Cold storage compromise emerges, or losses prove materially higher than reportedSolvency in question, risk of a prolonged fund freeze

* StarCompliance expert judgment based on public data, not a quantitative model.

07  What to watch over the next 72 hours

  • Withdrawal reopening date. The CEO says hours or days, “but not weeks.” Every delay beyond a week raises the odds of the stress case.
  • Net outflows in the first 24–48 hours after reopening (DefiLlama, Arkham). Alarm threshold: over $1.5B in a week.
  • The full incident report with root cause analysis, promised within 24 hours.
  • The cold wallet discrepancy. In the first hours WuBlockchain reported an affected cold wallet; Bitget denies it. Independent confirmation is needed.
  • Protection fund verification — on-chain proof of the 5,500 BTC at the disclosed addresses.
  • Freeze results. Bitget says some blockchain foundations have confirmed blocking attacker addresses.

08  Recommendations for compliance teams and counterparties

  • Add Bitget Exploiter addresses and linked clusters (11 EVM, 7 XRPL, 1 TRON per SlowMist) to blocklists; block inbound funds with direct or indirect exposure to them.
  • Raise the risk level for inbound ETH from fresh addresses and via the Stargate and cBridge bridges in the coming weeks: the attacker is splitting ~68,000 ETH.
  • Account for address poisoning: fake tokens and lookalike attacker addresses appeared within hours. Verify addresses in full, not by the first and last characters.
  • Clients holding balances on Bitget should avoid panic decisions; once withdrawals reopen, review concentration on a single venue and diversify custody.

Sources: official statements by Bitget and Gracy Chen (X, Support Center); Etherscan (Bitget 6, Bitget 35, Bitget Exploiter 1 addresses); Lookonchain; SlowMist / MistTrack; Unchained; Forbes; CNBC; CoinDesk; Decrypt; Blockhead; Crypto Times; TechFlow; DefiLlama; CoinMarketCap; Bitget Proof of Reserves (September 2026).

starcompliance.io · Not investment advice. Data as of 25 Sep 2026 and subject to change.

Previous
Article

Coinbase Scam Calls, Emails and Texts: How Impersonation Works

Next
Article

StarCompliance and CryptoProcessing: Operational Cooperation

§ — Related reading

Continue down the thread.

§ — Engage

Got a case that rhymes with this one?
Start an intake.

Response within two business hours. Confidential. Success-fee terms on recovery work.