In September 2026 Bitget reported a system breach that resulted in a loss of $351.6 million. Source
The company said the unauthorized transfers were limited to some hot wallets while cold wallets and user funds remained safe, and the incident has been described as potentially the biggest hack of 2026. Source
The event followed another major breach in the same month—the Liquid Network hack that moved about $320 million. Source
Bitget operates a three-tier wallet architecture that includes cold, warm and hot layers. The company said the breach affected only a portion of its hot and warm wallets while cold wallets and user funds remained safe. Bitget’s security systems detected unauthorized transfers from some hot wallets at 18:31 UTC on September 24, 2026, and the security team activated emergency response protocols immediately.
On-chain monitoring flagged unusual wallet movements and indicated around $183 million moved from Bitget wallets. Assets involved included ETH, BNB, AVAX and USDT0. Some on-chain records show rapid swaps, including a 19.67 million USDT0 transfer that converted to 7,111 ETH in six minutes. The movements spanned multiple blockchains and consolidated funds into single addresses.
Arkham Intelligence analyst Emmett Gallic said the transactions involved three hot wallets and one cold wallet and that funds were consolidated into a single address across multiple blockchains. Bitget temporarily paused withdrawals while a security review continued. The company also said it would publish an incident report within 24 hours.
Bitget’s security systems detected unauthorized transfers from some of its hot wallets at 18:31 UTC on September 24, 2026, and the security team activated emergency response protocols immediately. Withdrawals were temporarily paused while a security review continued. The company said it would publish an incident report within 24 hours. Bitget communicated these measures publicly as part of its immediate response.
Bitget stated that cold wallets and user funds remained safe following the breach. The company said the full amount of the loss falls within the coverage of its User Protection Fund, which currently holds over $464 million. A Bitget representative was quoted as saying “User funds are safe. The full amount of this loss falls within the coverage of Bitget’s User Protection Fund, which currently holds over $464 million.” Company comments also included “Cold wallets remain fully secure. Bitget operates a three-tier wallet architecture — the breach contained only a portion of the hot wallet and warm wallet layers.”
Arkham Intelligence analyst Emmett Gallic said the transactions involved three hot wallets and one cold wallet across multiple blockchains and that funds were consolidated into a single address. An analyst comment quoted in reporting stated “Looks like Bitget just got hacked for $178M.” Bitget paused withdrawals and continued an ongoing security review while monitoring on-chain activity and coordinating its incident response. The company reiterated its commitment to publish a detailed incident report within 24 hours.
Bitget confirmed an internal security review is ongoing and that withdrawals were temporarily paused while investigators assessed the affected systems. The firm stated that cold wallets and customer assets were protected and that its existing protections cover the incident. Bitget committed to publish a detailed incident report to provide transparency as its review and response continue.


