How Did the Attack Bypass Existing Safeguards?
Bitget confirmed a security incident on September 24, 2026, involving unauthorized transfers from its hot and warm wallets, affecting approximately $351.6 million in digital assets. The exchange detected the breach and immediately suspended withdrawals while launching a preliminary investigation into the source of the compromise. No private-key leak has been found so far, according to Bitget’s internal assessment.
Breaking news
Investment Activity Surges in Global Cryptocurrency Markets
Bitcoin Faces Resistance Near Record Highs as Crypto Infrastructure Recovers
Wall Street Giant Predicts Bitcoin Surge as New Crypto Funds Enter the Market
Sleeping Ethereum Giants Stir After Years of SilenceThe breach occurred despite Bitget’s existing security protocols, raising questions about potential vulnerabilities in its backend infrastructure. Investigators are focusing on whether the attack exploited a system-level flaw rather than compromised user credentials. Bitget emphasized that user funds remain under custody and that the platform is working with cybersecurity experts to trace the movement of assets and strengthen defenses.
Security analysts suggest the breach may have involved manipulation of transaction approval processes or temporary access to wallet signing mechanisms. Bitget stated that multi-signature requirements were in place, but attackers might have exploited a delay or misconfiguration in the validation window. The exchange has not disclosed whether internal systems or third-party integrations were involved in the exploit.
Bitget has engaged external forensic teams to conduct a full system audit and is reviewing all access logs related to wallet operations. The platform plans to enhance real-time monitoring and introduce additional authorization layers for large withdrawals. Until the investigation concludes, withdrawals remain paused, and users are advised to monitor official channels for updates on fund safety and service restoration. Frequently Asked Questions
What Steps Is Bitget Taking to Prevent Recurrence?
Was user data compromised in the breach? Bitget has not reported any exposure of personal data or KYC information, focusing the investigation solely on unauthorized asset movements.
When will withdrawals resume? Withdrawals will remain suspended until the investigation is complete and security enhancements are implemented; no timeline has been provided.
Are affected users eligible for compensation? Bitget has not announced a compensation policy but stated it is assessing the full impact and will communicate next steps to users as information becomes available.