Bitget spent eight years building a reputation as one of the few major exchanges to avoid a headline-grabbing hack. That streak ended at 18:31 UTC on September 24, 2026, when attackers drained roughly $388 million from the exchange’s hot and warm wallets without touching a single private key. Instead, according to Bitget and two outside forensics firms, the thieves walked in through a zero-day flaw in third-party security software the exchange relied on to protect its own infrastructure.

The breach lands in the middle of what blockchain trackers PeckShield and CertiK both call the worst month for crypto theft in 2026, and it reframes a question the industry keeps avoiding: if an exchange can get robbed without anyone stealing its keys, what exactly is “secure” supposed to mean? This piece walks through the confirmed timeline, the forensic findings from SlowMist and Mandiant, Bitget’s recovery effort, and how the incident stacks up against the rest of a brutal year for exchange and DeFi security.

Inside the Bitget Hack: What Happened on September 24

Bitget first flagged unauthorized transfers at approximately 18:31 UTC on September 24, 2026, moving across multiple blockchains out of a portion of its hot and warm wallet infrastructure. The exchange’s initial damage estimate was $351.6 million. As its internal team traced additional attacker-controlled addresses over the following days, that figure climbed to between $387.5 million and $388 million, depending on which valuation snapshot is used.

Bitget said the losses came from 12 wallet addresses, all drawn from hot or warm storage rather than cold storage, which the exchange keeps offline and out of reach of network-connected systems. That detail matters: cold wallets held, meaning the exchange’s deepest layer of custody never came under direct threat. The exposure was confined to the operational wallets Bitget uses to process everyday withdrawals.

Bitget suspended withdrawals almost immediately after detecting the anomalous transfers, a standard containment step that nonetheless locks out legitimate users for days while an exchange sorts out what happened. CEO Gracy Chen later confirmed the exchange brought in Google Cloud’s Mandiant along with blockchain security firm SlowMist to run independent investigations in parallel, a step larger exchanges increasingly treat as mandatory after a breach of this scale, according to The Hacker News’ coverage of Bitget’s disclosure.

How Attackers Skipped Private Keys and Still Drained $388 Million

The detail that separates the Bitget hack from a conventional exchange breach is what did not happen. The attacker never obtained Bitget’s private keys, the cryptographic codes that would normally be required to move funds out of a wallet. Chen said the intrusion instead ran through a vulnerability in third-party security software the exchange had deployed to protect its own systems. Exploiting that flaw let the attacker harvest high-level internal credentials and then insert fraudulent withdrawal instructions directly into Bitget’s wallet backend.

Because those instructions arrived through a path the wallet system already trusted, internal risk controls accepted them as legitimate. Reporting from FinanceFeeds and Cointelegraph describes the attacker running two test transfers before launching the full drain, a pattern consistent with an intruder validating that their forged access actually worked before committing to the larger theft. In effect, Bitget’s own withdrawal pipeline became the attack vector, not a side door bypassing it.

This is the part security teams outside crypto should pay attention to. Exchanges spend heavily on key management, multisig approvals, and cold storage segmentation. Few scrutinize the security products layered on top of that infrastructure with the same intensity, and this incident shows why that gap is exploitable at scale.

The 25-Day Dwell Time Nobody Noticed

SlowMist’s investigation, as reported by Bitcoin.com News, traced the earliest logged malicious activity to August 31, 2026, nearly four weeks before the September 24 theft. That gap, commonly called dwell time in incident response, means the attacker had quiet, persistent access inside Bitget’s environment for roughly 25 days before cashing out. During that window, the intruder reportedly explored internal systems, established the access needed to forge withdrawal commands, and ran the two test transfers mentioned above, all without tripping the alarms that eventually caught the real theft.

Mandiant’s parallel investigation reportedly identified compromise across two separate third-party security products, with at least one used to deploy a web shell and set up command-and-control communications, the standard playbook for maintaining remote access to a compromised network. Neither Bitget nor the investigating firms have publicly named the vendors involved as of October 8, referring to the affected systems only as “Product A” and “Product B” in disclosed materials, according to BleepingComputer’s writeup of the joint findings.

A 25-day dwell time is not unusual by enterprise security standards, where breaches often go undetected for months. But for an exchange holding hundreds of millions of dollars in customer funds, nearly a month of undetected access inside wallet-adjacent infrastructure is the kind of finding that invites regulatory scrutiny well beyond the immediate theft.

Zero-Day in Third-Party Software: A Supply Chain Blind Spot

Bitget has said the exploited vulnerability has since been identified and remediated, though it has not published a CVE identifier, a vendor patch reference, or a full technical writeup. That silence is typical in the early weeks after a breach involving a third-party vendor, since disclosure terms are often negotiated separately from the exchange’s own incident response, but it leaves the broader industry unable to check whether the same flaw sits inside its own stack.

This is the same structural weakness that has hit software supply chains repeatedly in 2026: an organization’s own code can be clean while a vendor it trusts becomes the opening. Crypto exchanges are an especially attractive target for this approach because a single successful compromise can be laundered into liquid, hard-to-trace funds within hours, something that is far harder to pull off after breaching a bank or a cloud provider.

Security researchers have long argued that exchanges need the same vendor risk assessment practices that banks apply to core banking software, including code audits, patch SLAs, and continuous monitoring of third-party integrations, not just point-in-time penetration tests. The Bitget case is likely to become the reference incident cited in that argument going forward.

Bitget Hack: Timeline at a Glance

Date (2026)Event
Aug. 31Earliest malicious activity logged inside compromised third-party security product (per SlowMist)
Sept. 24, 18:31 UTCFraudulent withdrawals detected across 12 hot/warm wallet addresses
Sept. 24Bitget suspends withdrawals; initial loss estimate set at $351.6 million
Sept. 25Bitget says North Korea is “very likely” behind the theft; Mandiant and SlowMist engaged
Sept. 27-28Bitcoin withdrawals resume; loss estimate revised up to $387.5-$388 million
Sept. 28Bitget commits to rebuilding its Protection Fund to at least $300 million within one week
Sept. 30SlowMist and Mandiant publish joint findings on the 25-day dwell time and dual-product compromise
Oct. 2-4Bitget reports its Protection Fund restored to approximately $309 million

Why Investigators Point to North Korea

Bitget said North Korea is “very likely” responsible for the attack, a characterization its CEO attached to the investigation within a day of the theft becoming public. The exchange has not published a formal attribution report naming a specific unit or group, and the available reporting treats the North Korea link as an investigative assessment rather than a confirmed, independently adjudicated finding.

The pattern fits a playbook North Korea-linked operators have used against exchanges for years: long dwell times, credential harvesting through a trusted intermediary system rather than a direct key theft, rapid cross-chain movement of stolen funds, and timing designed to maximize the window before an exchange can freeze or trace the proceeds. The same actors have been blamed for a string of 2026 incidents, including the $10.7 million WaterPlum wallet-draining campaign that hit roughly 7,000 wallets earlier this year. No independent law enforcement agency had publicly confirmed an arrest or indictment tied to the Bitget theft as of October 8.

Bitget’s Response: Suspended Withdrawals, Rebuilt Protection Fund

Bitget’s public playbook after the breach followed a now-familiar sequence for exchanges that survive a major hack: contain, disclose, commit to make users whole, then rebuild reserves in public. The exchange suspended withdrawals on detection, resumed Bitcoin withdrawals within days once it judged the affected pathway secured, and pledged on September 28 to restore its Protection Fund, the pool of exchange-owned reserves used to backstop customer losses, to at least $300 million within a week.

By early October, Bitget reported the fund stood at approximately $309 million, modestly ahead of its own target, per the exchange’s own published incident timeline. The exchange has said customer losses from the incident will be covered rather than passed on to users, though public reporting as of October 8 does not include a completed, independently audited reimbursement ledger confirming every affected account has been made whole.

Rebuilding a reserve fund quickly is good optics, but it is not the same as proving the underlying vulnerability is gone. Bitget says the exploited weakness has been patched, yet the exchange’s unwillingness to name the vendor or publish technical detail means outside auditors cannot independently verify that claim.

Market Reaction and the Trust Question for BGB Holders

Bitget’s native token, BGB, absorbed the kind of reputational shock exchanges fear most: a breach that proves the custody model itself, not just one wallet, has a blind spot. Public reporting through October 8 confirms the operational disruption and the days-long withdrawal freeze but does not establish a precise, independently verified percentage move in BGB’s price during the incident window, so any specific figure beyond the confirmed facts above should be treated as unconfirmed.

What is measurable is user behavior during a freeze: withdrawal suspensions on major exchanges reliably drive a spike in support tickets, social media pressure, and competitor marketing aimed at onboarding nervous users elsewhere. Bitget’s decision to resume Bitcoin withdrawals within days, well before the full investigation concluded, reflects how much exchanges now prioritize restoring liquidity quickly over waiting for a complete forensic picture, a trade-off that trades short-term user retention against the risk of reopening a still-compromised pathway.

2026’s Biggest Crypto Exchange and DeFi Hacks Compared

IncidentApprox. LossAttack VectorStatus (Oct. 2026)
Bitget (Sept. 24, 2026)$388MZero-day in third-party security software; forged withdrawal commandsProtection Fund rebuilt to $309M; withdrawals resumed
Liquid Network (Sept. 2026)$320MFlaw in Blockstream’s Liquid sidechain software; unbacked L-BTC minted85% of funds later recovered; sidechain paused during response
WaterPlum wallet campaign (2026)$10.7MMass phishing/malware across ~7,000 walletsAttributed to North Korea-linked actors
Base DeFi vault hack (Oct. 2026)$6MSmart contract exploit drained in roughly 19 minutesIsolated to one Base-based vault
Kelp DAO / LayerZero rsETH exploit (2026)$292M (disputed)Cross-chain bridge integration disputeLitigation ongoing between Kelp DAO and LayerZero

Industry trackers PeckShield and CertiK both flagged September 2026 as the costliest month of the year for crypto theft, with PeckShield counting 55 major incidents and roughly $766.5 million stolen, and CertiK separately logging 97 incidents totaling about $768.4 million, according to Cointelegraph’s September loss tally. The gap between those two tallies is a reminder that even basic loss accounting in crypto security still depends on which tracker’s methodology you trust, let alone the harder questions about attribution and recovery.

Bitget vs Liquid Network: Different Attack, Same Scale

The Bitget and Liquid Network incidents landed within weeks of each other and ended up in roughly the same dollar range, but the mechanics could not be more different. Liquid Network’s breach exploited a flaw in Blockstream’s sidechain software that let an attacker mint unbacked L-BTC and cash out without ever touching the federation’s private keys either, a coincidence of method that is becoming less coincidental as attackers shift away from brute-force key theft toward exploiting the software layers that manage keys and approvals.

Both incidents also diverged sharply in recovery outcomes. Liquid Network clawed back 85% of the stolen $320 million, largely through cooperation with exchanges that froze attacker-controlled funds before they could be laundered. Bitget’s recovery path has instead run through its own balance sheet, replenishing the Protection Fund rather than recovering the stolen assets directly. Neither outcome is clearly superior, but they illustrate that “recovery” after a 2026 crypto hack increasingly means either getting the money back or absorbing the loss internally, with on-chain tracing alone rarely sufficient to guarantee either.

Historical Context: From Mt. Gox to Bybit to Bitget

Exchange hacks have shaped crypto’s public image since Mt. Gox collapsed in 2014 after losing roughly 850,000 bitcoin, an event that still anchors how regulators talk about custody risk more than a decade later. The scale of single incidents has only grown since then. Bybit’s February 2025 breach, widely attributed to North Korea’s Lazarus Group, resulted in losses of roughly $1.46 billion from a compromised cold wallet transfer, the largest crypto hack on record and a reminder that even “cold” storage is only as secure as the signing process around it.

Measured against Bybit, Bitget’s $388 million loss is smaller in absolute terms but arguably more unsettling in method. Bybit’s breach involved manipulation of a cold wallet transfer signing interface, a known and discussed risk in multisig design. Bitget’s breach ran through security software nobody in the industry was publicly treating as a primary attack surface. Each major hack tends to shift where the next generation of defenses gets built, and this one points squarely at vendor risk management as the next gap to close.

Why Exchange Security Keeps Failing Despite Billions in Spending

Exchanges have poured resources into cold storage, multisig custody, and insurance-style protection funds since Mt. Gox, and those investments have genuinely worked against the attacks they were designed to stop. What keeps producing nine-figure losses is the surface area attackers keep finding around that hardened core: the software that monitors it, the credentials that administer it, and the humans who approve transactions within it.

Bitget’s incident, paired with Liquid Network’s a few weeks earlier, suggests the industry’s defensive spending has outpaced its vendor scrutiny. An exchange can run a flawless multisig setup and still get robbed if the monitoring tool watching that setup has an unpatched zero-day. Closing that gap requires treating every piece of third-party software touching wallet infrastructure, not just the wallet software itself, as part of the attack surface that needs continuous auditing.

What Comes Next for Exchange Security in 2027

Based on the pattern this incident fits into, several developments look likely over the next 12 months:

  • More exchanges will start publishing vendor security attestations for the third-party tools touching wallet infrastructure, following the scrutiny Bitget is now facing over its unnamed “Product A” and “Product B.”
  • Expect at least one more nine-figure exchange or bridge hack before the end of 2026, given September’s record $766-768 million in losses and the recurring pattern of credential-based rather than key-based attacks.
  • Protection funds will become a standard disclosure item, with exchanges publishing fund balances proactively rather than only after an incident forces the issue, mirroring what Bitget did with its $309 million rebuild.
  • Regulators in major markets will push harder for mandatory incident disclosure timelines specific to exchanges, closing the gap between when a breach is detected internally and when it becomes public.
  • Forensics firms like Mandiant and SlowMist will increasingly be engaged jointly rather than individually, as exchanges try to cross-validate findings on increasingly complex, multi-vendor compromises.

None of these are guaranteed, but they follow directly from how the industry responded to comparable incidents earlier in 2026, including the aftermath of the Liquid Network breach and the broader pattern tracked in September’s record loss tally.

FAQ: The Bitget Hack Explained

How much was stolen in the Bitget hack?

Bitget’s confirmed loss sits between $387.5 million and $388 million, revised up from an initial estimate of $351.6 million as investigators traced additional attacker-controlled addresses after the September 24, 2026 theft.

Did the Bitget hackers steal private keys?

No. Bitget and its investigators said the attacker never obtained the exchange’s private keys. Instead, a zero-day vulnerability in third-party security software let the attacker harvest internal credentials and insert fraudulent withdrawal instructions that Bitget’s own systems accepted as valid.

Was Bitget’s cold storage affected?

No. Bitget said the losses came from 12 hot and warm wallet addresses used for operational transfers. The exchange’s cold storage, kept offline, was not part of the breach.

Who is responsible for the attack?

Bitget CEO Gracy Chen said North Korea is “very likely” behind the theft, a pattern consistent with prior attacks blamed on North Korea-linked groups. As of October 8, 2026, no independent law enforcement body had published a confirmed attribution or made an arrest tied to the incident.

Will Bitget users get their money back?

Bitget has said it will cover customer losses rather than pass them on to users, and it rebuilt its Protection Fund to roughly $309 million by early October. Public reporting as of October 8 does not include a fully audited, completed reimbursement record for every affected account.

How does the Bitget hack compare to the Liquid Network hack?

Both losses landed in a similar range, $388 million for Bitget versus $320 million for Liquid Network, and neither required stealing private keys directly. Liquid Network’s flaw let an attacker mint unbacked L-BTC through sidechain software, while Bitget’s attacker forged withdrawal commands through a compromised third-party security tool. Liquid Network recovered 85% of its stolen funds; Bitget’s recovery has come through rebuilding its own reserve fund instead.

What is Bitget’s Protection Fund?

It is a pool of exchange-owned reserves Bitget maintains to cover customer losses from security incidents. The exchange pledged on September 28, 2026 to restore the fund to at least $300 million within a week and reported it had reached approximately $309 million by early October.

How long were the attackers inside Bitget’s systems before stealing funds?

SlowMist traced the earliest malicious activity to August 31, 2026, roughly 25 days before the September 24 theft was executed, indicating sustained, undetected access during that window.