Bitget will very likely survive the incident. The loss of roughly $352M equals about 5–7% of the exchange's on-chain assets and is smaller than its user protection fund (>$464M). The issue is not solvency but liquidity and trust: the outcome will be decided by the scale of outflows in the first days after withdrawals reopen.
01 What happened
On 24 September at 18:31 UTC, Bitget's systems detected unauthorized transfers from part of its hot and warm wallets. According to CEO Gracy Chen, the attacker compromised a critical backend system of the wallet infrastructure, spoofed transaction data and triggered the standard authorization and signing process. Private key compromise has been ruled out. Cold wallets, according to the exchange, were not affected. Withdrawals are suspended; deposits and trading remain operational. Bitget preliminarily links the attack to DPRK-affiliated groups, but this has not been officially confirmed.
What it means: it was not the cryptographic layer that failed, but the chain of trust in front of the signer. The signing system approved the transfers because it trusted data from a compromised backend. This class of vulnerability applies to every exchange that automates hot-wallet top-ups.
02 Timeline (UTC, 24 Sep 2026)
| Time | Event |
|---|---|
| 18:31 | Test transfer of 0.84 ETH from Bitget 6 to a fresh address (later tagged Bitget Exploiter 1) |
| 19:01–19:16 | Main ETH outflows from Bitget 6 and Bitget 35; at the same time ~93.7M XRP leave two Bitget XRPL wallets |
| ≈19:05–19:25 | USDT, USDC and XAUt move to a second address and are swapped into ~22,600 ETH to avoid issuer freezes |
| 20:09–20:19 | Last ETH outflow from Bitget 35; the attacker splits ETH into 10,000 ETH batches across new addresses |
| 20:55 | A further 8.2M USDC leaves Bitget 6 on Avalanche |
| 21:23 | Last recorded on-chain outflows |
| 21:30 | Official Bitget notice: loss ≈ $351.6M, withdrawals suspended |
03 How much was stolen
Bitget's official estimate is $351.6M. Lookonchain's on-chain breakdown across nine assets gives $356.9M; the gap comes from pricing, not from additional losses.
| XRP (102.93M) | $157.5M · 44% |
| ETH (31,890) | $85.8M · 24% |
| USDT / USDC / USDT0 | $75.5M · 21% |
| XAUt, BNB, AVAX, TRX | $38.1M · 11% |
| Asset | Amount | $M | Status |
|---|---|---|---|
| XRP | 102.93M XRP | 157.5 | Mostly held on 7 XRPL addresses, not converted |
| ETH | 31,890 ETH | 85.8 | Being split across new addresses, partly via bridges |
| USDT / USDC / USDT0 | — | 75.5 | Almost entirely swapped into ETH |
| XAUt, BNB, AVAX, TRX | 3,000 XAUt; 12,719 BNB; 821,012 AVAX; 20.59M TRX | 38.1 | Partly converted into ETH |
| Total | ≈ 356.9 | Bitget estimate: 351.6 |
In total, the attacker consolidated EVM assets into roughly 67,982 ETH (~$183M). We assume the stablecoins had already been converted by the time issuers could react, so the chance of a Tether/Circle freeze is low. The main blocking potential lies in the XRP position and in cash-outs via centralized venues.
04 What remains
On the compromised wallets. On-chain data as of 20:32–20:50 UTC on 24 Sep (Etherscan snapshots):
| Wallet | Taken by the attacker | Balance at snapshot |
|---|---|---|
| Bitget 6 0x1AB4973a48dc892Cd9971ECE8e01DcC7688f8F23 | 9,010.9 ETH (~$24.2M) + 8.2M USDC (Avalanche) | ~$20.8M (≈ $12M after the 20:55 USDC outflow) |
| Bitget 35 0xffa8DB7B38579e6A2D14f9B347a9acE4d044cD54 | 15,362.5 ETH (~$41.3M) + 821,012 AVAX (~$8.5M) | ~$275.9M, mostly altcoins (UNI, ENA, AAVE); only 155 ETH left |
Notably, the attacker took only liquid, easily moved assets (ETH, stablecoins, AVAX) and left hundreds of millions in altcoins untouched. According to TechFlow, about $530M remained on the compromised wallets after the attack.
Exchange-wide. Bitget's total on-chain assets are estimated at $5.0–7.0B (DefiLlama ~$5.0B; CoinMarketCap ~$6.4–7.0B; aggregator snapshot dates not stated). The September Proof of Reserves reported a 135% reserve ratio across 19 assets.
05 Is the buffer sufficient?
| Buffer | Size | Loss / buffer | Comment |
|---|---|---|---|
| User Protection Fund | >$464M (5,500 BTC) | ≈ 76% | ≈ $112M left after payout; value tracks BTC price; not independently audited |
| Own capital (CEO statement) | >$1B | ≈ 35% | Not independently verified |
| Reserve surplus over liabilities* | ≈ $1.3B | ≈ 27% | Our estimate: ~$5B assets at 135% PoR |
| Exchange on-chain assets | $5.0–7.0B | 5–7% | Cold storage reportedly unaffected |
* Derived figure: $5B − $5B / 1.35 ≈ $1.3B. PoR is a point-in-time snapshot and does not cover all assets; treat as an order-of-magnitude indicator.
The Bybit precedent (February 2025). A $1.5B loss — about four times larger. The exchange closed the gap with bridge loans, and withdrawals normalized within 72 hours. Bitget's scale makes a comparable recovery scenario realistic.
06 Scenarios
| Scenario | Estimate* | What happens | Outcome for the exchange |
|---|---|---|---|
| Base case | ~70% | Withdrawals reopen within days; outflows within $1–1.5B over the first week | Loss covered by the fund, operations normalize, moderate reputational damage |
| Stress case | ~25% | Delayed reopening; outflows of $2B+ (30–40% of assets); pressure on BGB | Survives, but bridge financing, asset sales and loss of large clients are likely |
| Tail risk | ~5% | Cold storage compromise emerges, or losses prove materially higher than reported | Solvency in question, risk of a prolonged fund freeze |
* StarCompliance expert judgment based on public data, not a quantitative model.
07 What to watch over the next 72 hours
- Withdrawal reopening date. The CEO says hours or days, “but not weeks.” Every delay beyond a week raises the odds of the stress case.
- Net outflows in the first 24–48 hours after reopening (DefiLlama, Arkham). Alarm threshold: over $1.5B in a week.
- The full incident report with root cause analysis, promised within 24 hours.
- The cold wallet discrepancy. In the first hours WuBlockchain reported an affected cold wallet; Bitget denies it. Independent confirmation is needed.
- Protection fund verification — on-chain proof of the 5,500 BTC at the disclosed addresses.
- Freeze results. Bitget says some blockchain foundations have confirmed blocking attacker addresses.
08 Recommendations for compliance teams and counterparties
- Add Bitget Exploiter addresses and linked clusters (11 EVM, 7 XRPL, 1 TRON per SlowMist) to blocklists; block inbound funds with direct or indirect exposure to them.
- Raise the risk level for inbound ETH from fresh addresses and via the Stargate and cBridge bridges in the coming weeks: the attacker is splitting ~68,000 ETH.
- Account for address poisoning: fake tokens and lookalike attacker addresses appeared within hours. Verify addresses in full, not by the first and last characters.
- Clients holding balances on Bitget should avoid panic decisions; once withdrawals reopen, review concentration on a single venue and diversify custody.
Sources: official statements by Bitget and Gracy Chen (X, Support Center); Etherscan (Bitget 6, Bitget 35, Bitget Exploiter 1 addresses); Lookonchain; SlowMist / MistTrack; Unchained; Forbes; CNBC; CoinDesk; Decrypt; Blockhead; Crypto Times; TechFlow; DefiLlama; CoinMarketCap; Bitget Proof of Reserves (September 2026).
starcompliance.io · Not investment advice. Data as of 25 Sep 2026 and subject to change.






