A crypto exchange lost more than a third of a billion dollars on Thursday, and by Friday morning traders had mostly shrugged it off. Bitget confirmed that $351.6 million disappeared from a handful of its hot wallets late on September 24, 2026, in what several outlets, including CoinDesk, are now calling the largest single crypto exchange breach of the year. The exchange paused withdrawals, activated its user protection fund, and promised a full incident report by 21:30 UTC today, September 25. What happened at Bitget, how it compares to the rest of 2026’s hack tally, and why the broader market barely moved, is the story below.

Bitget Confirms $351.6 Million Hack, Its Biggest Breach Yet

Bitget’s security team detected unusual withdrawal activity at 18:31 UTC on September 24. Within minutes, blockchain analytics firm Arkham Intelligence had already flagged the outflows publicly, spotting large movements of AVAX, BNB, ETH, and several stablecoins draining from wallets tied to the exchange. Bitget CEO Gracy Chen confirmed the breach hours later in a public statement, putting the total loss at $351.6 million and stressing that cold wallet reserves and customer balances remained untouched.

That figure makes this the costliest single incident to hit a centralized exchange since Bybit’s $1.5 billion loss in February 2025, and it edges out the Liquid Network’s $320 million sidechain exploit from earlier this month. Bitget ranks among the top five exchanges globally by derivatives volume, so a breach of this size lands on an exchange most traders actually use, not a fringe platform.

Inside the Attack Timeline: How the Breach Unfolded

The intrusion moved fast. Once the attacker gained the ability to trigger withdrawals, funds started leaving Bitget’s hot wallets within a single hour, spread across multiple blockchains rather than one chain at a time. That spread-the-load pattern is designed to slow down defenders, since a security team has to freeze or trace assets on several networks simultaneously instead of one.

A newly created wallet then converted about $19.7 million of USDT0, a cross-chain version of Tether, into 7,111 ether in roughly six minutes, according to Decrypt. The attacker paid up to 5% above market price to push the swap through quickly. That detail matters: stablecoins like Tether can be frozen by their issuer once flagged, but ether has no central party that can block a transfer. Converting stolen stablecoins into ether or bitcoin within minutes is a pattern security researchers have tied to earlier North Korea-linked heists, where speed determines how much of the haul survives freezing attempts.

How Attackers Bypassed Bitget’s Wallets Without Stealing Keys

What sets this hack apart from a typical private-key theft is the method. Bitget’s own account says the attacker exploited a back-end system vulnerability and spoofed transaction history to trigger unauthorized withdrawals, all without ever obtaining the exchange’s private keys. That is a meaningfully different threat than the 2025 Bybit heist, where attackers compromised a third-party wallet interface during a routine cold-to-hot transfer.

A back-end logic flaw is arguably harder to defend against than key theft, because it does not require compromising hardware security modules or multisig signers. If a withdrawal-processing system can be tricked into approving requests it should reject, the keys themselves never need to move. Security researchers reviewing the incident will likely focus on how Bitget’s internal risk engine validated withdrawal requests, and whether rate limits or anomaly detection could have caught the spoofed history sooner.

The Lazarus Group Question: Why Investigators Suspect North Korea

Bitget has told investigators it suspects North Korea’s Lazarus Group is behind the breach, according to HackRead. That suspicion tracks with a broader pattern. Lazarus and affiliated groups were responsible for the $1.5 billion Bybit theft in February 2025, the $308 million DMM Bitcoin collapse in 2024, and the $234.9 million WazirX breach the same year. The FBI formally attributed the Bybit hack to Lazarus after tracing the stolen ether through mixing services, a case documented by Picus Security.

Attribution this early is never certain. Bitget has not published on-chain evidence tying the funds to known Lazarus wallets, and the group’s operators routinely reuse techniques that copycat actors can imitate. Still, the operational signature, fast multi-chain withdrawals, immediate conversion into untraceable assets, and a system-level exploit rather than social engineering, matches the toolkit North Korean state hackers have used for years.

Bitget’s Response: Paused Withdrawals and a $464 Million Backstop

Bitget froze withdrawals within hours of the detection while deposits and trading kept running. Chen said the exchange’s User Protection Fund held more than $464 million at the time of the breach, enough to cover the entire loss and reimburse affected users without touching customer deposits. The fund had averaged between $510 million and $600 million through 2025, though the figure fluctuates with market prices since it is partly held in crypto assets rather than cash.

Bitget also flagged the receiving wallet addresses to exchanges and blockchain analytics firms in an attempt to freeze funds before they moved further, and it contacted law enforcement. Chen promised hourly public updates and a full root-cause report, due at 21:30 UTC today. Whether that report actually lands on schedule, and whether it includes verifiable on-chain attribution rather than just a statement of confidence, will shape how much trust the exchange keeps.

BGB Token Price and Wider Market Reaction

Bitget’s native token, BGB, fell from a $2.02 to $2.06 range on Thursday to about $1.963 during Friday’s Asian trading session, a drop of roughly 3% to 5%. That is a mild reaction for a nine-figure breach, and it suggests traders are pricing this as a Bitget-specific problem rather than a signal that centralized exchanges broadly are less safe.

Bitcoin slipped about 0.29% and ether about 0.2% in the 24 hours following disclosure, both well within normal daily volatility. The wider crypto market was still up close to 10% over the trailing week, according to market data cited by Bitcoin Magazine. Compare that to the days following the Bybit hack in 2025, when bitcoin dropped several percentage points and the whole sector wobbled. Markets increasingly treat individual exchange breaches, even large ones, as isolated operational failures rather than systemic risk, as long as the exchange has a visible reserve to cover the gap.

2026’s Biggest Crypto Hacks, Compared

Bitget’s loss now tops the 2026 leaderboard, but it sits in crowded company. The table below lines up the year’s largest confirmed incidents against the most expensive breach in crypto history for scale.

IncidentDateAmount LostAttributed ToRecovered
Bitget hot wallet breachSept. 24, 2026$351.6 millionSuspected Lazarus GroupNone reported yet
Liquid Network (Blockstream)Sept. 6, 2026~$320 millionSelf-described “white hat”~$272 million (85%)
KelpDAO exploitApril 2026$292 millionNorth Korea-linkedNot disclosed
Drift ProtocolApril 2026$285 millionNorth Korea-linkedNot disclosed
Bybit (historical high)Feb. 2025$1.5 billionLazarus Group (FBI-confirmed)Partial, via tracing

The pattern across four of these five incidents is the same: a state-linked actor, a fast cash-out, and a total north of a quarter-billion dollars in a single event. Only the Liquid Network case broke from that script, with an attacker who negotiated a partial return rather than disappearing with the funds.

Exchange Security Funds: Bitget vs. Binance vs. OKX

Every major exchange now runs some version of an insurance reserve, built to absorb exactly this kind of loss without dipping into customer deposits. How those funds compare says a lot about how much cushion each platform is carrying relative to its size.

ExchangeSecurity/Insurance FundApprox. Fund Size (2026)Reported Cold Storage Share
BinanceSAFU Fund~$1 billion (Feb. 2026)95%+
OKXRisk Shield~$700 million~95%
BitgetUser Protection Fund$464 million (at breach)Not fully disclosed
Industry range (leading exchanges)Varies by platformVaries90%-98% typical

Bitget’s fund covered the loss this time, but the margin was tighter than Binance’s or OKX’s relative buffers. A breach even 30% larger would have wiped out most of Bitget’s reserve in a single event. That math is likely to push mid-tier exchanges toward larger, more transparently audited protection funds over the next year.

Historical Context: From Mt. Gox to the $1.5 Billion Bybit Heist

Exchange hacks are not new, but their scale has grown by orders of magnitude. Mt. Gox lost roughly 850,000 bitcoin, worth about $450 million at 2014 prices, in a breach that took the exchange down entirely and became the industry’s founding cautionary tale. WazirX lost $234.9 million in July 2024. DMM Bitcoin collapsed after losing $308 million later that same year. Then came Bybit’s $1.5 billion loss in February 2025, still the largest crypto theft on record, after Lazarus compromised the development environment behind the exchange’s multisig wallet interface.

What separates Bitget’s incident from Mt. Gox is response capacity. Mt. Gox had no reserve and folded within weeks. Bitget had a nine-figure fund ready before the exchange even finished its internal review. That is the clearest sign of how much exchange risk management has matured, even as the raw dollar amounts stolen keep climbing.

Why September Became 2026’s Costliest Month for Crypto Losses

Bitget’s loss alone pushes September’s total crypto theft above $684 million, according to a CryptoSlate tally, overtaking April as the most expensive month of 2026. April had already been a rough stretch, with the KelpDAO and Drift Protocol exploits combining for $577 million. September now adds Liquid Network’s $320 million and Bitget’s $351.6 million to the ledger inside a single three-week window.

That clustering is worth a closer look for a different reason than the raw totals. Two of September’s three big incidents targeted infrastructure, a sidechain and an exchange back end, rather than a smart contract bug in a DeFi protocol. Earlier in the year, most large losses traced back to DeFi exploits and bridge code. September’s hacks suggest attackers are shifting attention toward the centralized layer of crypto, where a single system flaw can expose far more value than any individual smart contract.

North Korea’s Expanding Share of Global Crypto Theft

TRM Labs put total crypto theft at roughly $972 million across 207 separate incidents in the first half of 2026 alone, with about $643 million, or 66%, tied to North Korea-linked actors. CertiK, which uses a broader definition of a Web3 security incident, counted $1.32 billion over the same stretch. For 2025 as a whole, Chainalysis measured $3.4 billion in total crypto theft, with North Korea responsible for $2.02 billion of it, a 51% year-over-year jump in state-linked losses.

Those numbers describe a group that has effectively turned crypto theft into a funded, recurring state program rather than opportunistic hacking. If Bitget’s suspicion is confirmed, this incident extends a run that already includes two of the year’s three biggest hacks and the largest crypto theft ever recorded. Stolen credentials and system-level access, not exotic cryptography breaks, remain the tool of choice.

Competitive Fallout: What This Means for Mid-Tier Exchanges

Bitget sits just below the very largest exchanges by volume, and this hack puts every platform in that tier under pressure to prove its own back-end withdrawal logic can withstand a similar spoofing attempt. Expect Bybit, Kraken, and other mid-to-large exchanges to publish or reference third-party audits of their withdrawal validation systems in the coming weeks, not because they were named in this incident, but because customers will ask.

There is also a trust dimension distinct from the technical one. Bitget’s decision to keep deposits and trading open while pausing only withdrawals is becoming the standard playbook, since it avoids the appearance of insolvency while still limiting further loss. Exchanges that instead halt all activity during an incident tend to see sharper token price drops and slower user return, a pattern visible in the muted BGB reaction compared to past full-freeze responses at other platforms.

5 Predictions for Exchange Security After Bitget

Based on how the market and Bitget itself have responded so far, a few outcomes look likely over the next two to three months.

  • Bitget’s report lands, but attribution stays soft. Expect a technical post-mortem by the promised deadline, but full, verifiable Lazarus attribution will likely take weeks longer, mirroring the FBI’s slower confirmation of the Bybit case.
  • Mid-tier exchanges grow their protection funds. Platforms sized similarly to Bitget will move to expand insurance reserves well past the amount needed to cover a single worst-case incident, rather than the amount needed to cover an average one.
  • Withdrawal-logic audits become a marketing point. Exchanges will start publicizing third-party reviews of back-end withdrawal systems specifically, not just cold storage practices, since that is where this breach originated.
  • North Korea-linked attribution keeps climbing in year-end reports. If confirmed, this incident will push North Korea’s 2026 share of crypto theft well past the 66% mark TRM Labs already recorded for H1.
  • Regulators reference this case in exchange oversight debates. With the Federal Reserve already moving on stablecoin issuer rules this month, expect this hack to surface in discussions about whether exchange reserve funds need mandatory minimums rather than voluntary ones.

What Crypto Users Should Do Right Now

If you hold funds on Bitget, the practical advice is straightforward. Wait for the official incident report before moving assets, since panic withdrawals once the pause lifts can create their own liquidity problems. Check whether your specific assets were among those swept in the breach, since Bitget has said the incident was contained to particular hot wallets rather than the whole platform.

More broadly, this is a reasonable moment to review how much of your holdings sit on any single exchange versus in self-custody or hardware wallets. Exchange protection funds work only as long as they are large enough and liquid enough to cover the specific incident in front of them. Spreading exposure across a few platforms, and moving long-term holdings off exchanges entirely, remains the most reliable defense against any single back-end failure, no matter how well-funded the exchange’s insurance pool looks on paper.

Frequently Asked Questions

How much money did Bitget lose in the September 2026 hack?
Bitget confirmed a loss of $351.6 million from several hot wallets on September 24, 2026, making it the largest single crypto exchange breach reported so far this year.

Are Bitget user funds safe after the hack?
Bitget CEO Gracy Chen said cold wallet reserves were untouched and that the exchange’s $464 million User Protection Fund covers the stolen amount, so customer balances should remain intact regardless of the breach.

Who is suspected of carrying out the Bitget hack?
Bitget has told investigators it suspects North Korea’s Lazarus Group, a state-linked hacking operation tied to several of the largest crypto thefts in recent years, including the $1.5 billion Bybit heist in 2025.

How did the attacker steal funds without private keys?
According to Bitget, the attacker exploited a flaw in a back-end system and spoofed transaction history to trigger unauthorized withdrawals, bypassing the need to compromise the exchange’s actual private keys.

Is Bitget still operating normally after the breach?
Deposits and trading have continued as normal. Only withdrawals were paused, pending completion of Bitget’s security review and its incident report, due September 25, 2026.

How does this compare to other 2026 crypto hacks?
At $351.6 million, the Bitget breach surpasses the Liquid Network’s $320 million exploit and the KelpDAO and Drift Protocol incidents from April, each near $285-292 million, making it 2026’s largest confirmed loss to date.

Did the Bitget hack affect Bitcoin or Ethereum prices?
No significant impact. Bitcoin fell about 0.29% and ether about 0.2% in the 24 hours after disclosure, both within normal daily trading ranges, while BGB, Bitget’s own token, dropped 3% to 5%.

What should I do if I have funds on Bitget?
Wait for the official incident report rather than reacting immediately, confirm whether your specific holdings were among the affected wallets, and consider moving long-term holdings to self-custody regardless of the outcome.