Bitget Security Incident (Hack) — Official Progress Update

Yes—Bitget was hacked on September 24, 2026. At 18:31 UTC that day, Bitget's security systems detected unauthorized transfers involving certain hot wallets and warm wallets. The investigation found that the attackers exploited a vulnerability in a third-party security product to steal internal network access credentials, forge withdrawal instructions, bypass risk controls, and complete the transfers. Private keys were not compromised, and cold wallets were unaffected. This page continuously compiles verified facts, the root cause of the attack, withdrawal recovery progress, and the latest developments in the investigation and asset recovery.

Last updated: 2026-09-29 00:00 UTC · Incident date: 2026-09-24

View full timeline
Bitget hacking incident in September 2026
Estimated affected funds
$388M
Final verified figures · Involving 12 wallet addresses
Withdrawal status
Phased recovery in progress
BTC/ETH now available; USDT available 9/30; all others available 10/2
Cold wallet status
Unaffected
Securely held in a three-tier wallet architecture
Protection Fund
$464M+
Holding 5500 BTC · Comprehensive reserve ratio 127%

Bitget Hack Timeline: Verified Facts in Chronological Order

Each record below links back to the original official announcement. Historical entries will not be modified retroactively—any corrections will be added as new entries.

Security Incident Statement

Bitget Hack: Incident Overview

At 18:31 UTC on September 24, 2026, Bitget's security system detected unauthorized transfers involving certain hot wallets and warm wallets. The incident has been contained—no further unauthorized transfers will occur. Cold wallets holding the majority of platform assets were unaffected. The affected assets involve Ethereum and multiple EVM networks, XRP Ledger, Zcash, and TRON, including XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX, and TRX.

Following an investigation, it was found that the attacker exploited a vulnerability in a third-party security product to steal internal network access credentials, forged withdrawal commands to the wallet system, and deceived the wallets into executing abnormal transfers that bypassed risk checks. Private keys were not compromised, and cold wallets were unaffected.

Root Cause of the Attack: How Did It Happen?

Following a complete investigation, Bitget has confirmed the full attack chain. The attackers did not use common viruses or malware; instead, they disguised themselves throughout the attack by using legitimate identities and routine operational procedures. This was a highly sophisticated targeted attack.

Key findings: Private keys were not compromised, and cold wallets were unaffected. Bitget has completed vulnerability remediation, reset all internal credentials and tightened access to highly sensitive permissions, notified third-party vendors and disabled the relevant features, and strengthened independent withdrawal verification. A formal security report with more comprehensive technical details will be released soon.

Steal Internal Network Credentials and Infiltrate Internal Systems
A third-party security product used by Bitget contained a zero-day vulnerability, which the attackers exploited to gain access to the platform's critical internal management systems. As the forged identity information appeared genuine and valid, the system recognized the attackers' access as normal user logins.

Forge Withdrawal Instructions and Bypass Risk Controls
The attackers used the stolen high-privilege credentials to access wallet-related backend servers and directly wrote forged withdrawal commands into the wallet system. This caused the wallet to process them as normal withdrawals, bypassing the risk control verification process before withdrawal records were generated and completing the transfer of funds from hot/warm wallets.

Fund Tracking and Recovery Bounty Program

Independent cybersecurity firm Mandiant and SlowMist are assisting with the investigation. Real-time on-chain tracking data has been made public.
Chain
Attacker-Controlled Address
EVM
0x770b10b273fc44fe9197d6bf20f145c2e98463ee
XRP
rwNhefsz1UQEusxhCvHip3RANinWi4CTck
ZEC
t1WgMdtND8NF7NDUuYmq8MpMj1NTCXkMDVG
TRON
TBWNguTTgezw9dVorX441C6nDrZpRxYwKD
Recovery Bounty Program
Eligible individuals or organizations whose voluntary assistance directly leads to the freezing or recovery of funds may receive a bounty equal to 5% of the frozen amount or 5% of the recovered amount. Bitget also recognizes Bybit's LazarusBounty program as one of its core collaboration channels for asset recovery.

Phased Withdrawal Resumption Schedule

This suspension is a precautionary security measure and does not mean funds are unavailable. Trading and deposit services remain fully operational throughout.
Time (UTC)
Coin
Network
Status
September 28, 2026, 08:00
BTC
Bitcoin

Resumed

September 29, 2026, 08:00
ETH
Ethereum, BSC, Arbitrum, Base, Optimism
Pending
September 30, 2026, 08:00
USDT
Ethereum, BSC, Solana, Tron
Pending
October 2, 2026, 08:00
Other coins / Fiat / P2P
—
Pending
This phased approach allows Bitget to resume withdrawal services in an orderly manner following the incident. This plan applies uniformly to all users, with no priority given to anyone. Our goal is to safely restore withdrawal services for all supported assets and networks as quickly as possible.

FAQ

What exactly happened in the Bitget hot wallet security incident? Was Bitget really hacked?

The attackers exploited a zero-day vulnerability in a third-party security product used by Bitget to breach critical internal management systems and steal high-privilege credentials. They then used these credentials to inject forged withdrawal commands into the wallet system, causing the system to process them as normal withdrawals, thereby bypassing risk control verifications to transfer funds out. After completing the transfers, the attackers deleted their operation traces. The entire process did not use common viruses or malware; it was a highly sophisticated targeted attack. Private keys were not compromised, and cold wallets were unaffected. The relevant vulnerabilities have been patched, and the third-party vendor has been notified and is assisting with the remediation.
The attackers exploited a zero-day vulnerability in a third-party security product used by Bitget to breach critical internal management systems and steal high-privilege credentials. They then used these credentials to inject forged withdrawal commands into the wallet system, causing the system to process them as normal withdrawals, thereby bypassing risk control verifications to transfer funds out. After completing the transfers, the attackers deleted their operation traces. The entire process did not use common viruses or malware; it was a highly sophisticated targeted attack. Private keys were not compromised, and cold wallets were unaffected. The relevant vulnerabilities have been patched, and the third-party vendor has been notified and is assisting with the remediation.
Following final verification, approximately $388M in assets was transferred out, involving 12 wallet addresses, all of which were hot wallets and warm wallets. This figure reflects the latest accounting and classification results for onchain transactions related to this incident.
The suspension is a preventive security measure used to complete the final verification of the withdrawal infrastructure before safely restoring services—it is unrelated to the availability of user assets. Deposit and trading services have remained fully operational throughout the incident.
BTC withdrawals resumed as scheduled (September 28); ETH withdrawals will resume on September 29; USDT will resume on September 30; other tokens, fiat currency, and P2P services are expected to fully resume on October 2. Please see the withdrawal recovery schedule above for details.
The recovery order is categorized by asset type and is unrelated to account tier: BTC is first (September 28), followed by ETH and its EVM networks (September 29), then USDT across supported networks (September 30), and finally other coins, fiat, and P2P (October 2). This schedule applies consistently to all users; there is no VIP or account tier priority.
The recovery order is categorized by asset type and is unrelated to account tier: BTC is first (September 28), followed by ETH and its EVM networks (September 29), then USDT across supported networks (September 30), and finally other coins, fiat, and P2P (October 2). This schedule applies consistently to all users; there is no VIP or account tier priority.
Yes. Your account balance is accurate and unaffected. The financial impact of this incident is covered by the Bitget Protection Fund, which holds 5,500 BTC valued at over $464 million. The cold wallets holding the majority of the platform's assets were not breached.
User account balances are accurate and unaffected. Approximately $388M affected in this incident came from hot wallet and warm wallet infrastructure; any resulting financial impact is covered by the Bitget Protection Fund and will not be passed on to user account balances.
The Bitget Protection Fund holds 5,500 BTC (over $464 million)—higher than the current estimated affected funds of approximately $388 million—and is designated to cover the full financial impact of this platform-level incident. The cold wallets, which hold the majority of the platform's assets, were unaffected by this incident. The latest financial report as of August 31 shows that Bitget's own funds (including the Protection Fund) exceed $1.4 billion.
Yes—Bitget has stated that its Protection Fund (holding 5,500 BTC, worth more than $464M) covers the financial impact of this incident. For independent verification, we recommend cross-checking Bitget's monthly published Proof of Reserves (127% overall reserve ratio, Merkle Tree proof, and reserve ratios) against the official incident-update announcements linked in the timeline above, rather than relying solely on the summary on this page.
Bitget's latest Proof of Reserves shows an overall reserve ratio of 127%. Updated reserve information will be released once the independent forensic review is complete.
Deposit and trading services remained operational throughout the incident, account balances were unaffected, and the breach was limited to hot wallet/warm wallet infrastructure. Cold wallets were not accessed, and private keys were not compromised. Whether to continue holding funds on any exchange is a personal risk decision—this page provides verified facts (the timeline, root cause of the attack, Protection Fund, and Proof of Reserves) so that you can make your own judgment based on the latest information rather than hearsay.
Yes, this is the first security incident of its kind in Bitget's 8 years of operation. This was a targeted attack on the supply chain of a third-party security software, rather than a failure of Bitget's core underlying architecture or private key management—cold wallets were unaffected, and private keys were not compromised. Upon detecting the anomaly, Bitget initiated the highest-level emergency response within minutes and quickly stopped the losses. We are currently conducting an independent review in collaboration with Mandiant and SlowMist, and will comprehensively upgrade our monitoring and management standards for third-party components.
Yes, BTC and ETH withdrawals resumed as scheduled on September 28 and September 29, respectively. Since the resumption, a large number of users have successfully completed withdrawals (as of September 28, 09:00 UTC, 9,585 BTC withdrawals have been processed, totaling approximately 4,098 BTC). USDT and other assets will gradually resume according to the schedule.
Bitget publishes monthly Proof of Reserves and reserve ratios based on the cryptographic Merkle Tree—links are available in the "Fund Security Protection" section above. We recommend cross-checking the published PoR figures against the Protection Fund balance and confirmed transferred-out amount on this page to independently verify the data rather than relying on a single source of information.
Asset recovery efforts are ongoing, and some affected assets have been successfully frozen through collaboration with exchanges, blockchain project teams, and security companies. For real-time data, please refer to the Bitget live tracking dashboard linked above. This page does not repeat specific figures because frozen and recovered amounts will continue to change as the investigation progresses.
These are two limited-time user rewards programs launched by Bitget simultaneously: the Bitget Alliance Program for retail users sets aside 30% of the actual net transaction fees retained from non-institutional users as an exclusive promotion pool for users and introduces a VIP tier retention program; Project Stand Together, for PRO clients and market makers, provides transaction fee and rebate benefits and extends PRO tier protection until November 30. Please refer to the official announcements for the full rules.
The latest entry in the verified timeline above always represents the most recent official update. As of the last update to this page, the latest progress is that BTC withdrawals resumed as scheduled on September 28. We recommend bookmarking this page or following the official X account @Bitget for the latest confirmed information.
Stay updated on the latest developments
This page will continue to be updated as official information is confirmed. If you have account-related questions, please contact customer support directly.
Beware of scams exploiting this incident
Bitget will never ask users to transfer funds or disclose passwords, private keys, seed phrases, or verification codes under the guise of "assisting in asset recovery" or "resuming withdrawals." Please obtain information only through the official channels and links published on this page.