Bitget has confirmed unauthorized transfers involving some of its hot and warm wallets. The platform said its security system detected suspicious activity at 02:31:11 UTC+8 on September 25, 2026, Bitget has confirmed unauthorized transfers involving some of its hot and warm wallets. The platform said its security system detected suspicious activity at 02:31:11 UTC+8 on September 25, 2026,

Bitget Hit by a US$351.6 Million Hack: What Happened?

Bitget has confirmed unauthorized transfers involving some of its hot and warm wallets. The platform said its security system detected suspicious activity at 02:31:11 UTC+8 on September 25, 2026, which was 18:31:11 UTC on September 24 and 01:31 WIB on September 25.

The company initially estimated that approximately US$351.6 million in assets had been affected. That figure is substantial, but it is not the only number circulating. On-chain tracker Lookonchain later estimated that roughly US$356.86 million had moved across the wallets and chains it was monitoring, while earlier reports had identified transfers worth more than US$170 million.

Those figures should not be treated as evidence of separate breaches. They are more likely snapshots taken at different times, using different asset prices and address coverage. Bitget’s figure is an internal company estimate. Lookonchain’s figure is an independent reconstruction of publicly visible blockchain movements.

Bitget described the event as unauthorized transfers. The technical cause has not been disclosed, so it would be premature to state whether the incident involved compromised private keys, internal system access, a wallet-management failure, or another attack vector.

Why the Reported Amount Changed So Quickly

The first public observations focused on addresses labelled by blockchain analytics services as being associated with Bitget. Those early observations showed more than US$170 million moving to newly created or previously inactive addresses.

Subsequent reporting identified approximately US$183 million in visible transfers during the early phase of the incident. That was not a final loss estimate. It was an early snapshot of assets that on-chain observers could associate with the event at that time.

Bitget later published its own security notice and estimated the affected amount at US$351.6 million. Lookonchain subsequently placed the total value of traced assets at about US$356.86 million.

The difference between Bitget’s estimate and Lookonchain’s estimate is roughly US$5.26 million, or about 1.5%. That gap can arise from different observation times, changing token prices, additional identified addresses, cross-chain transactions, and differences between an internal incident assessment and a public wallet-tracing model.

The sequence is easier to interpret as a developing investigation:

  • More than US$170 million: early visible transfers from addresses linked to Bitget.

  • Around US$183 million: an early estimate based on assets identified during the first stage of on-chain tracking.

  • US$351.6 million: Bitget’s official estimate of the affected assets.

  • Around US$356.86 million: Lookonchain’s later estimate based on its cross-chain transaction tracking.

Public blockchain data can reveal where tokens move. It cannot independently establish the final loss amount, identify the person controlling a receiving address, prove that an asset remains spendable, or confirm how much value may eventually be recovered.

XRP Was the Largest Asset in the Tracked Wallets

Lookonchain’s breakdown shows that XRP was the largest component of the assets it identified. The tracker reported approximately 102.93 million XRP, valued at roughly US$157.48 million at the time of its snapshot.

Ether was the second-largest identified asset, with about 31,890 ETH worth approximately US$85.75 million. Stablecoins also represented a significant portion of the observed transfers, including USDT, USDC, and USD₮0.


Assets traced after the Bitget hot-wallet incident. The approximately US$356.86 million figure is Lookonchain’s independent on-chain estimate based on wallet snapshots and prevailing asset prices, not Bitget’s final reconciled loss figure. Source: Lookonchain, September 25, 2026.

The token amounts and their dollar values should be read separately. Token balances may remain unchanged while their market values fluctuate. XRP, ETH, BNB, AVAX, TRX, and tokenized gold can all move materially during a short period, which means a dollar-denominated dashboard total may change even if no new tokens are added to the tracked addresses.

What the On-Chain Activity Shows

A. Funds Were Consolidated into New Addresses

The receiving addresses highlighted in early reports were not widely known public operational wallets. That does not identify the attacker, but it explains why the movements quickly drew attention from blockchain trackers.

New addresses are often used to separate transferred funds from their original source before assets are split across wallets, swapped into other tokens, bridged to another network, or routed through additional services. The pattern is common in security incidents, but it is not evidence of a specific individual or organization.

B. Some Funds Were Swapped into ETH

Decrypt, citing on-chain observations, reported that one newly created wallet used about US$19.67 million in USD₮0 to purchase roughly 7,111 ETH on Arbitrum. The transactions were reportedly completed over about six minutes through liquidity-routing services including UniswapX and 1inch Fusion.

Large orders executed quickly can create slippage. In practical terms, the trader receives a less favorable average execution price because the order consumes available liquidity. Decrypt reported that parts of the transaction were executed at prices as much as 5% above the prevailing market price.

This matters because the nominal value of stolen assets is not necessarily the same as the value that can be realized after swaps. Liquidity depth, spreads, slippage, stablecoin freezes, address blacklisting, and subsequent enforcement actions can all affect how much value remains transferable.

C. Wallet Labels Are Not Proof of Custody Architecture

Early reports referred to transfers from wallets labelled as Bitget-related by blockchain analytics platforms. Bitget, meanwhile, said the unauthorized transfers involved some hot and warm wallets and that its cold wallets were unaffected.

Both statements can be useful, but they answer different questions. Third-party wallet labels help analysts investigate activity quickly, yet they do not conclusively establish whether a particular address functioned as a hot, warm, or cold wallet within the platform’s internal custody architecture at the time of the incident.

For that reason, public address labels alone are not enough to prove that a cold wallet was compromised. A detailed incident report, affected-address map, and forensic explanation would be needed to confirm the precise custody classification of each wallet.

D. Traceability Does Not Guarantee Recovery

Public blockchains make many transfers observable. Analysts can follow recipient addresses, token balances, swaps, bridges, and downstream wallet activity. That transparency can help exchanges, stablecoin issuers, security firms, and law-enforcement agencies respond more quickly.

However, traceability is different from recoverability. Funds may be divided across multiple addresses, swapped into other assets, moved through bridges, or routed through services that are difficult to stop. Recovery depends on response speed, cooperation from issuers and intermediaries, address freezes, available liquidity, jurisdiction, and the ability to identify the party controlling the funds.

What Bitget Has Said So Far

Bitget said it marked and reported relevant addresses, engaged law-enforcement authorities and on-chain security organizations, and began an emergency response within minutes of detecting the suspicious activity.

The platform also temporarily suspended withdrawals while it conducted a security investigation. Deposits and trading, according to Bitget’s announcement, continued to operate normally during the review.

Bitget said the User Protection Fund would cover the losses and described the fund as being worth more than US$400 million. That assurance is important, but it does not by itself answer several practical questions for users, including the fund’s asset composition, immediate liquidity, compensation process, and timeline for normal withdrawal operations to resume.


Bitget’s official statement on unauthorized transfers involving some hot and warm wallets. The company estimated affected assets at US$351.6 million and said its User Protection Fund, valued at more than US$400 million, would cover the losses. This reflects Bitget’s September 25, 2026 statement. The root cause and forensic findings had not yet been published.

At the time of writing, Bitget had not disclosed the technical root cause. Its promised incident report will matter more than speculative explanations because it should clarify the affected wallet set, attack method, security controls, and remediation measures.

Why Proof of Reserves Does Not Resolve the Core Question

Proof of Reserves can provide evidence of asset holdings or reserve ratios at a particular point in time. It does not replace a security investigation when unauthorized transfers occur.

A reserve report may show that assets were present in wallets on a particular reporting date. It does not automatically demonstrate that access controls were secure, that a protection fund can be deployed immediately, that user liabilities remain fully covered after an incident, or that previously reported wallet balances remain under the platform’s control.

Bitget had published Proof of Reserves material before this event. That earlier information remains only a historical snapshot. Users will need a post-incident update that addresses current assets, liabilities, withdrawal status, protection-fund coverage, and any additional security controls.

What Matters Next

The next meaningful updates are likely to come from four areas:

  • The forensic report: The root cause, affected wallet addresses, attack path, and remediation plan will determine whether the event was a contained operational failure or a broader security issue.

  • Withdrawal operations: A full restoration of withdrawals, any withdrawal limits, and actual processing times will provide a practical test of operational recovery.

  • Movement of the tracked addresses: Further transfers, swaps, bridges, stablecoin freezes, or address blacklisting may clarify the trail of funds. They should not be treated as proof of recovery without confirmation.

  • Updated reserve and liability disclosures: Information on available assets, user liabilities, and the protection fund is more useful than a single wallet-balance figure.

The incident also highlights the difference between keeping assets available for active trading and holding assets for long-term custody. Hot wallets enable fast deposits, withdrawals, and settlement, but their operational connectivity creates a different risk profile from wallets that are not continuously exposed to online systems.

That does not mean every platform faces the same risk. It does mean users should understand custody exposure, avoid leaving unnecessary balances on trading accounts, use two-factor authentication, enable withdrawal-address whitelists where available, and verify security updates through the platform’s official channels.

The Most Important Questions Are Still Unanswered

Bitget has confirmed unauthorized transfers and estimated the affected value at US$351.6 million. Lookonchain’s data provides a more detailed public view of the assets it tracked, with XRP and ETH accounting for the largest portions of its snapshot.

The available evidence still does not answer the key questions: how access to the wallets was compromised, how much of the identified value remains under the control of the receiving addresses, whether any assets have been frozen, and how user liabilities will be reconciled after the event.

The next decisive evidence will be Bitget’s forensic report, its withdrawal-status updates, action against relevant addresses, and verifiable disclosures about user protection. Until then, on-chain figures should be treated as evolving transaction evidence rather than a final explanation of the entire incident.

Disclaimer

This article is provided for informational and educational purposes only. It is not investment advice, a recommendation to use or avoid any platform, or a security assessment of any service. Digital-asset prices can change rapidly, and dollar valuations in on-chain reports depend on the asset prices used at the time of each snapshot.

Statements concerning the affected amount, cold wallets, the User Protection Fund, operational status, and Bitget’s response are based on the company’s own announcement. Asset breakdowns and wallet activity are drawn from independent on-chain tracking and do not, by themselves, establish attacker identity, technical root cause, final loss, or successful recovery of funds. Readers should follow official updates and forensic disclosures before reaching conclusions.


 

Market Opportunity
Harmony Logo
Harmony Price(ONE)
$0.0022406
$0.0022406$0.0022406
USD

The articles shared on this page are sourced from public platforms and are provided for reference only. They do not represent the position or views of MEXC. All rights belong to MEXC. If you believe any content infringes upon the rights of a third party, please contact [email protected] for prompt removal. MEXC does not guarantee the accuracy, completeness, or timeliness of any content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be interpreted as a recommendation or endorsement by MEXC. For expert insights and in-depth analysis, visit MEXC Learn.

Latest Updates on Harmony

View More
View More