5x rewards · Early stage
Markets

Bitget Hack Drains $351.6 Million, Making September Costliest Month of 2026

A woman using a laptop navigating a contemporary data center with mirrored servers.
Photo: Christina Morillo / Pexels

Bitget, one of the world’s larger crypto exchanges, suspended withdrawals after unauthorized transfers stripped $351.6 million from a limited number of its hot and warm wallets. The breach, detected at 18:31 UTC on Sept. 24, 2026, is now one of the largest single exchange hacks of the year and pushes total industry losses for September above $684 million, the costliest month of 2026 by a wide margin.

CEO Gracy Chen said cold wallets, which hold the bulk of customer assets in offline storage, were unaffected, and that the exchange’s User Protection Fund — which holds more than $464 million — will cover the losses. Deposits and trading are continuing as normal; only withdrawals remain paused while the company runs a security review.

What happened, and why it stings

Hot and warm wallets are the operational layer of any exchange: funds kept partially connected to the internet so users can withdraw quickly, as opposed to cold wallets, which are deliberately isolated for security. That structure makes hot and warm wallets the more exposed target, and it’s exactly where this attack hit. Bitget says it has flagged the compromised addresses, alerted law enforcement and on-chain security firms, and committed to hourly public updates along with a full incident report within 24 hours of detection.

The timing compounds the damage to the exchange’s narrative. The breach landed in the middle of Bitget’s eighth-anniversary campaign, just as the platform is pushing further into equities and foreign exchange under what it calls its Universal Exchange strategy — an ambition to become a one-stop venue spanning crypto, stocks, and FX. A nine-figure hack in the middle of that pitch is an awkward look, regardless of how the exchange ultimately compensates users.

Zooming out, the Bitget incident is not an isolated event but the latest entry in an unusually damaging month. DeFiLlama had already tallied about $331 million in losses across 17 separate September incidents before Sept. 19, including an exploit against Fetch.ai on that date. A subsequent wave of attacks pushed the running total above $342 million, and a Liquid Network incident added roughly $320 million on top of that. Layering Bitget’s $351.6 million onto those figures brings September’s cumulative losses past $684 million — well above April 2026’s total of about $646.9 million, which had been driven largely by the Drift and KelpDAO attacks worth a combined $577 million.

What it means for the industry

The scale of September’s losses reframes a familiar industry debate about custody. Exchanges routinely argue that cold storage protects the vast majority of user funds, and in Bitget’s case that claim appears to hold — cold wallets and most platform assets were untouched. But the incident is also a reminder that the operational wallets exchanges must keep semi-liquid to serve customers remain a persistent point of failure, and that even well-capitalized platforms with dedicated protection funds are not immune.

Bitget’s ability to lean on a $464 million User Protection Fund to make affected users whole is a meaningful backstop, and it distinguishes this episode from breaches where exchanges lack reserves to cover losses outright. Still, the fact that a fund of that size can absorb a $351.6 million hit in a single incident illustrates how large these attacks have become relative to the insurance-style buffers exchanges maintain.

The breach also arrives at a moment when banks and asset managers are moving in the opposite direction, building tokenized infrastructure they argue is more auditable and secure than exchange-run hot wallets. Efforts such as Canada’s largest banks coordinating on tokenized deposits and UK lenders completing interbank tokenized deposit transfers reflect a parallel institutional push toward custody models that keep assets on regulated, permissioned rails rather than exchange-controlled wallets. Incidents like Bitget’s hack give that argument more weight, even if tokenized deposit systems carry their own untested risks at scale.

What comes next

Several concrete markers will show whether Bitget contains the fallout:

  • Whether the promised full incident report, due within 24 hours of detection, identifies the attack vector and confirms no further wallets were compromised.
  • Whether withdrawals resume on the timeline Bitget signals, and whether the User Protection Fund fully reimburses affected users without delay.
  • Whether law enforcement or on-chain investigators trace and potentially recover any of the stolen funds, as has happened in some past exchange breaches.
  • Whether September’s total losses climb further before month’s end, and how the final figure compares with April’s $646.9 million benchmark.

The episode also lands amid broader questions about how governments and institutions want crypto rails to evolve — from proposals in Washington to use dollar stablecoins as a foreign policy tool to traditional finance experiments like IBM’s tokenized deposit link to Swift’s blockchain ledger. Each new exchange hack adds pressure on regulators and institutions to argue their alternative custody models are safer, even as the underlying technology in both camps continues to be tested in real time.

Source: CryptoSlate

This content is for informational purposes only and does not constitute financial or investment advice.

Informational and educational content; not financial, investment, legal or tax advice. Always do your own research.

Read. Comment. Earn.

Share a thoughtful take on this story. Quality comments are scored by AI and earn reward points.

Points (Proof Points) are internal and non-transferable, with no monetary value and no entitlement to $PROOF. Legal

Join the conversation