Bitcoin BTC $84,551 -0.81% Ethereum ETH $2,677 -1.50% BNB BNB $768 -0.81% Solana SOL $119 -0.94% XRP XRP $1.49 -1.11% Dogecoin DOGE $0.092940 -1.38% Pepe PEPE $0.000004 -3.96% Sui SUI $1.16 -1.65% Fartcoin FARTCOIN $0.176252 -0.95%

Bitget Post Mortem: How $387.5M Left the Exchange in Three Hours

October 3, 2026
No private keys stolen, yet $387.5M gone. Here is how the Bitget hack worked, who covered it, and what remains unanswered

The Bitget post mortem is finally complete enough to read as one story. On September 24, 2026, attackers moved about $387.5 million out of Bitget’s hot and warm wallets. They did it without stealing a single private key. Instead, they broke in through two third-party security products and turned Bitget’s own signing system against it. Withdrawals are fully open again as of October 2. So here is what happened, what Bitget fixed, and what still has no answer.

For the day-by-day updates, our Bitget hack timeline has every step. This post focuses on the lessons instead.


Bitget Post Mortem: The Short Version

  • What: about $387.5 million taken in 19 transfers across seven chains
  • When: September 24, between 18:31 and 21:23 UTC
  • How: two compromised third-party security tools, then spoofed transfer data
  • Who paid: Bitget, through its Protection Fund and its own capital
  • User balances: untouched, according to Bitget
  • Status: all withdrawals, fiat and P2P restored on October 2
  • Recovered: roughly $1.1 million frozen so far

How the Attackers Got In

Mandiant and SlowMist published their findings on September 30. Both firms describe the same path. First, the attackers compromised two security products that Bitget bought from outside vendors. One of those products had a zero-day flaw, meaning nobody knew about the bug yet. From there, they gained privileged internal access. Finally, they reached the production wallet systems.

24 Days Inside

SlowMist traced the earliest malicious activity in the logs to August 31. The theft came on September 24. In other words, the attackers sat inside Bitget for at least 24 days. During that time they studied the systems and waited. Afterwards, they deleted traces of their work.

No Keys Stolen

Most big exchange hacks start with a leaked private key. This one did not. Instead, the attackers fed fake transfer data into the backend. Bitget’s signing process then approved those transfers as if they were real. As a result, the normal customer withdrawal checks never came into play.

Think of it as forged paperwork rather than a stolen vault key. The vault worked exactly as designed. However, the instructions it received were fake.


Three Hours, Seven Chains

Arkham tracked the money in real time. Its numbers show how fast things moved:

  • 18:31 UTC: the first unauthorized transfer leaves Bitget
  • 18:58 to 19:16 UTC: about $228 million exits in 18 minutes
  • 19:44 UTC: ETH on Arbitrum, Optimism and Base starts bridging to Ethereum
  • 20:04 UTC: cross-chain moves finish, with roughly $100 million swapped into 36,600 ETH
  • 20:13 UTC: the first 10,000 ETH wallet receives funds
  • 21:23 UTC: the last outflow

Arkham also flagged one XRP wallet that lost about $153 million. Bitget, however, says its cold wallets stayed untouched. Early on-chain estimates put the loss near $183 million. Later, Bitget raised its own figure from $351.6 million to $387.5 million after tracing all seven chains.


Who Covered the Loss

Bitget absorbed the hit. Before the attack, its Protection Fund held more than $464 million. Bloomberg calculated that the fund then dropped below $200 million. Since then, Bitget has refilled it to about $309 million with company money.

Meanwhile, the latest Proof of Reserves offers some comfort. The September 29 snapshot shows a 131% reserve ratio across 19 assets. Every single asset sits above 100%.

Recovery looks slim, though. About $1.1 million is frozen, and frozen does not mean returned. CEO Gracy Chen told CNBC she does not expect to recover much. Still, Bitget offers a 5% bounty on any funds that come back.

Traders also get something. From September 28 to October 26, Bitget shares 30% of eligible net fee revenue through a reward pool.


What Bitget Changed

According to Bitget, the vulnerability is closed. In addition, the exchange lists these changes:

  • Critical operations now need multiple approvals
  • Internal login credentials were revoked and reissued
  • Access to the most sensitive systems was restructured
  • The affected vendor feature was switched off
  • Withdrawal verification got stricter

These are sensible steps. That said, most of them are controls you would expect before a $387.5 million loss, not after.


What We Still Do Not Know

Three questions remain open.

First, nobody has named the two security products. Chen declined, citing security risks. Therefore, other exchanges using the same tools cannot easily check their own exposure.

Second, attribution is unsettled. Chen pointed early to IP addresses linked to a North Korean group. However, neither forensic report confirms that.

Third, Bitget’s own full security report is not out yet. We will add it to this post once it lands.


Where Bitget Traders Are Looking Now

Bitget survived, and funds are moving again. Even so, a 24-day silent breach makes many traders want a second venue. Because of that, we refreshed six comparisons with the hack priced in:

  • Bitget vs Hyperliquid: trade perps from your own wallet, with no exchange backend holding your coins
  • Bitget vs MEXC: rock-bottom fees and a huge coin list, plus an honest look at MEXC account freezes
  • Bitget vs Blofin: matching futures costs, less paperwork at signup, and no hack on its record
  • Bitunix vs Bitget: a newer venue with up to 200x leverage, skippable KYC and zero breaches so far
  • OKX vs Bitget: regulated in Europe under MiCA, with a strong built-in Web3 wallet
  • Bybit vs Bitget: Bybit lost far more in 2025 and still made every user whole

Every comparison points to both full reviews. So you can dig deeper before you move a single dollar.


Keep This Content Free

Reading two forensic reports so you do not have to takes hours. If this breakdown helped, you can support us at no cost. Simply sign up through our OKX link or our Bybit link. You get the standard bonuses, and we keep the lights on.


Final Words

The Bitget post mortem carries one uncomfortable lesson. Bitget’s keys were safe, yet the money still left. The weak point was software from outside vendors that Bitget trusted. As a result, every exchange with similar tools now has homework.

Bitget handled the aftermath well. It paid from its own pocket, reopened on schedule and published outside reports within a week. Nevertheless, “handled well” and “safe” are different things. Therefore, keep only trading funds on any exchange. Everything else belongs in a wallet you control.


OKX Exchange AirdropAlert Exclusive Airdrops
Full review of OKX vs Binance for those in doubt

FAQ

What caused the Bitget hack?

Attackers compromised two third-party security products, including one with a zero-day flaw. They then gained internal access and spoofed transfer data. Consequently, Bitget’s own signing system approved the theft.

How much was stolen from Bitget?

About $387.5 million, according to Bitget’s revised figure. The first official number was $351.6 million.

Did Bitget users lose money?

No, according to Bitget. The exchange covered the loss with its Protection Fund and its own capital. User balances stayed the same.

Are Bitget withdrawals open again?

Yes. Bitcoin reopened on September 28, ETH on September 29 and USDT on September 30. All remaining tokens, fiat and P2P followed on October 2.

Was North Korea behind the Bitget hack?

That is not confirmed. Bitget’s CEO pointed to indicators matching a North Korean group. However, the Mandiant and SlowMist reports do not attribute the attack.

Will Bitget recover the stolen funds?

Probably only a small part. About $1.1 million is frozen so far, and the CEO expects limited recovery.

Morten Christensen
Founder, AirdropAlert
Written by
Morten Christensen

Crypto class of '13, airdrop farmer since 2016. Avid trader and DeFi veteran. His market commentary has been featured by Bloomberg, The Wall Street Journal, The New York Times, Forbes, and CNN.

We publish new crypto airdrops for you every day

Trade your crypto

Support us by using our referral link on these exchanges. Claim their sign up bonus and trade your airdropped coins and other cryptocurrencies.

airdropalert-bybit-logo
Airdropalert okx logo
HyperLiquid Logo DEX AirdropAlert
Airdropalert-Binance-logo
Blofin Exchange logo AirdropAlert
mexc-logo-airdropalert