Bitget Security Incident (Hack) — Official Progress Update
Yes—Bitget was hacked on September 24, 2026. At 18:31 UTC that day, Bitget's security systems detected unauthorized transfers involving certain hot wallets and warm wallets. The investigation found that the attackers exploited a vulnerability in a third-party security product to steal internal network access credentials, forge withdrawal instructions, bypass risk controls, and complete the transfers. Private keys were not compromised, and cold wallets were unaffected. This page continuously compiles verified facts, the root cause of the attack, withdrawal recovery progress, and the latest developments in the investigation and asset recovery.
Last updated: 2026-09-29 00:00 UTC · Incident date: 2026-09-24




Bitget Hack Timeline: Verified Facts in Chronological Order
BTC (Bitcoin, BSC network) withdrawals resumed as scheduled. As of 09:00 UTC on the day, a total of 9,585 withdrawals, totaling approximately 4098 BTC, had been processed. Bitget CEO Gracy Chen introduced the investigation findings in a livestream: attackers exploited vulnerabilities in third-party security products to steal internal network access credentials and forged withdrawal instructions to bypass risk controls. Private keys were not compromised, and cold wallets were unaffected. Bitget also launched two user rewards initiatives: the Bitget Alliance Program and Project Stand Together. View the official public statement →


Security Incident Statement
Bitget Hack: Incident Overview
At 18:31 UTC on September 24, 2026, Bitget's security system detected unauthorized transfers involving certain hot wallets and warm wallets. The incident has been contained—no further unauthorized transfers will occur. Cold wallets holding the majority of platform assets were unaffected. The affected assets involve Ethereum and multiple EVM networks, XRP Ledger, Zcash, and TRON, including XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX, and TRX.
Following an investigation, it was found that the attacker exploited a vulnerability in a third-party security product to steal internal network access credentials, forged withdrawal commands to the wallet system, and deceived the wallets into executing abnormal transfers that bypassed risk checks. Private keys were not compromised, and cold wallets were unaffected.
Root Cause of the Attack: How Did It Happen?
Following a complete investigation, Bitget has confirmed the full attack chain. The attackers did not use common viruses or malware; instead, they disguised themselves throughout the attack by using legitimate identities and routine operational procedures. This was a highly sophisticated targeted attack.
Key findings: Private keys were not compromised, and cold wallets were unaffected. Bitget has completed vulnerability remediation, reset all internal credentials and tightened access to highly sensitive permissions, notified third-party vendors and disabled the relevant features, and strengthened independent withdrawal verification. A formal security report with more comprehensive technical details will be released soon.



Fund Tracking and Recovery Bounty Program


Phased Withdrawal Resumption Schedule
FAQ
What exactly happened in the Bitget hot wallet security incident? Was Bitget really hacked?
How did the attacker breach Bitget?
How much did Bitget lose in this security incident?
Why did Bitget suspend withdrawals after this security incident?
Are withdrawals currently available? What is the recovery progress for each token?
Which tokens will be available for withdrawal first after this Bitget security incident? Does the withdrawal order depend on my account tier?
Which coins can be withdrawn first after this Bitget security incident? Is the withdrawal order related to my account tier?
Are my funds still safe after this Bitget security incident?
Were any user funds lost in this Bitget security incident, or was it only the platform's own funds?
Can Bitget remain solvent after a loss of approximately $388M?
Can the Bitget Protection Fund really cover this security incident? How can I verify this?
Are the reserves still sufficient after the incident? What is the total reserve ratio?
Is Bitget still safe to use after this security incident? Do I need to transfer my funds out?
Is this the first time Bitget has been hacked?
Have any users successfully withdrawn funds following this Bitget security incident?
How can I verify Bitget's Proof of Reserves after the security incident?
How much in funds has been frozen or recovered since this Bitget security incident?
What are the Bitget Alliance Program and Project Stand Together?
What is Bitget's latest official update on this security incident?
