{"id":78653,"date":"2026-09-25T14:09:24","date_gmt":"2026-09-25T14:09:24","guid":{"rendered":"https:\/\/crowdfundjunction.com\/blog\/everything-we-know-about-bitgets-massive-351m-hack\/"},"modified":"2026-09-25T14:09:24","modified_gmt":"2026-09-25T14:09:24","slug":"everything-we-know-about-bitgets-massive-351m-hack","status":"publish","type":"post","link":"https:\/\/crowdfundjunction.com\/blog\/everything-we-know-about-bitgets-massive-351m-hack\/","title":{"rendered":"Everything We Know About Bitget\u2019s Massive $351M Hack"},"content":{"rendered":"<p><b>(Originally posted on : Bitcoin News )<\/b><br \/>\n<\/p>\n<div>\n<div class=\"@container mb-[25px] rounded-sm overflow-clip py-0.5 pr-0.5 pl-2.5 bg-success-100\">\n<div class=\"flex flex-col gap-m overflow-clip rounded-[6px] !bg-success-10 p-3 @[420px]:p-m\">\n<h2 class=\"m-0 flex items-center gap-s text-[19px] !text-[#1c1c1c] md:text-[20px]\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"16\" height=\"10\" viewbox=\"0 0 16 10\" fill=\"none\" class=\"shrink-0 text-success-100\" aria-hidden=\"true\"><path d=\"M1 1.5h14\" stroke=\"currentColor\" stroke-width=\"2.5\" stroke-linecap=\"round\"\/><path d=\"M1 8.5h10\" stroke=\"currentColor\" stroke-width=\"2.5\" stroke-linecap=\"round\"\/><\/svg><span>Key Takeaways<\/span><\/h2>\n<ul class=\"m-0 flex list-none flex-col gap-m pl-0\">\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">Bitget detected the $351.6M breach at 18:31 UTC on Sept. 24 and halted withdrawals.<\/span><\/li>\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">Gracy Chen says Bitget\u2019s $464M-plus protection fund can absorb the entire $351.6M loss.<\/span><\/li>\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">Bitget says private keys were not stolen, with a full technical report due within 24 hours.<\/span><\/li>\n<\/ul>\n<\/div>\n<\/div>\n<p>The exchange <a href=\"https:\/\/news.bitcoin.com\/security\/bitget-hit-by-351m-hack-withdrawals-frozen-as-probe-begins\/\">has confirmed the breach<\/a>, frozen withdrawals and begun working with law enforcement and onchain security firms. CEO Gracy Chen says customer balances remain intact, cold wallets escaped untouched and Bitget\u2019s more than $464 million User Protection Fund is large enough to swallow the entire loss.<\/p>\n<h2>How the Bitget Hack Unfolded<\/h2>\n<p><a href=\"https:\/\/x.com\/bitget\/status\/2103236552482848927?s=20\" target=\"_blank\" rel=\"noopener noreferrer\">On Thursday, Bitget disclosed<\/a> that its security systems detected unauthorized transfers from some of its hot wallets at 18:31 UTC on Sept. 24. Emergency procedures were activated within minutes, suspicious addresses were identified and reported, and law enforcement and blockchain security firms were contacted.<\/p>\n<p>The damage was substantial. Bitget estimates that approximately $351.6 million was affected, but says only portions of its hot and warm wallet layers were compromised. The company operates a three-tier wallet architecture and maintains that its cold wallets remain fully secure. Withdrawals were subsequently suspended across the platform as a precaution. Deposits and trading remain operational, while Bitget detailed that customer account balances continue to accurately reflect users\u2019 assets.<\/p>\n<p>That distinction matters because the exchange is effectively saying this is a corporate balance-sheet loss rather than one it intends to pass through to customers. Chen <a href=\"https:\/\/x.com\/GracyBitget\/status\/2103237586374598873?s=20\" target=\"_blank\" rel=\"noopener noreferrer\">explained in several X posts<\/a> that customers would remain whole. The exchange founder said Bitget\u2019s User Protection Fund currently holds more than $464 million, putting the $351.6 million estimated loss about $112 million below the fund\u2019s stated value. The exchange says the entire incident, therefore, falls well within the fund\u2019s coverage.<\/p>\n<p>\u201cWe will not run from this,\u201d Bitget said in its official notice, promising that \u201cevery dollar and every decision\u201d would be accounted for.<\/p>\n<h2>The Blockchain Saw Trouble Before Bitget Spoke<\/h2>\n<p>Before Bitget confirmed anything, blockchain observers were watching millions of dollars pour from exchange-labeled wallets. The early picture centered on roughly $150 to more than $170 million of assets moving to fresh addresses. That is not the behavior of someone shopping around for the best execution.<\/p>\n<p>As the picture widened, onchain researchers tracked assets across several networks. <a href=\"https:\/\/lookonchain.com\/feeds\/74105\" target=\"_blank\" rel=\"noopener noreferrer\">Lookonchain\u2019s later tally<\/a> included approximately 102.93 million XRP worth $157.5 million, 31,890 ETH worth $85.8 million, $34.75 million USDT, $21.05 million USDC, $19.67 million USDT0, 3,000 XAUt, 12,719 BNB, 821,012 AVAX and 20.59 million TRX.<\/p>\n<p>A large portion of the assets movable through Ethereum Virtual Machine-compatible networks was rapidly consolidated and converted into ethereum. Lookonchain estimated that the component eventually reached roughly 67,982 ETH.<\/p>\n<p>The difference between that figure and Bitget\u2019s $351.6 million estimate is important. The roughly $183 million number captured a prominent cluster visible to onchain trackers, while Bitget\u2019s figure reflects its accounting across the affected infrastructure and additional blockchains, including the enormous XRP position. In other words, the first blockchain alarms <a href=\"https:\/\/news.bitcoin.com\/security\/zachxbt-declines-trace-coldcard-hack\/\">and onchain investigators<\/a> caught part of the fire, not the whole building.<\/p>\n<h2>Bitget Says Its Private Keys Were Not Stolen<\/h2>\n<p>The developing technical picture may be the most consequential piece of the incident. In a subsequent update, Chen explained that Bitget\u2019s private keys were not compromised. Instead, according to<a href=\"https:\/\/x.com\/GracyBitget\/status\/2103284083363398137?s=20\" target=\"_blank\" rel=\"noopener noreferrer\"> her preliminary description<\/a>, attackers compromised a critical backend component within the exchange\u2019s wallet infrastructure and were able to forge or spoof transaction data that entered Bitget\u2019s ordinary authorization and signing process.<\/p>\n<figure id=\"attachment_850531\" aria-describedby=\"caption-attachment-850531\" style=\"width:1372px\" class=\"wp-caption aligncenter\"><figcaption id=\"caption-attachment-850531\" class=\"wp-caption-text\">Gracy Chen\u2019s X post on Thursday evening.<\/figcaption><\/figure>\n<p>That would represent a very different attack from simply stealing a private key. If Bitget\u2019s account is confirmed, the system designed to decide what should be signed was manipulated into authorizing transactions that should never have existed. The keys could therefore remain technically secure while the infrastructure feeding instructions to them failed.<\/p>\n<p>Chen said the compromise has been contained and further unauthorized transfers are no longer possible. Bitget, however, has stopped short of formally declaring a final attack vector until its investigation is complete. That leaves plenty of unanswered questions. Investigators still need to establish how the backend was penetrated, what privileges the attackers obtained, why existing controls did not reject the transactions, and whether additional authentication or transaction-policy safeguards could have stopped them.<\/p>\n<h2>Did North Korea\u2019s Lazarus Group Attack Bitget?<\/h2>\n<p>Then there is the <a href=\"https:\/\/news.bitcoin.com\/crypto-news\/fake-it-job-interviews-help-north-korea-steal-millions-in-crypto\/\">North Korea question<\/a>. Reports and social media posts following Chen\u2019s live update have connected preliminary IP or routing information with infrastructure patterns previously associated with North Korean attackers. That <a href=\"https:\/\/news.bitcoin.com\/exchanges\/bitget-hack-xrp-157m-cannot-be-frozen\/\">quickly produced speculation<\/a> that the Lazarus Group may be responsible. For now, that is exactly what it is: speculation.<\/p>\n<p>The coincidences are impossible to ignore. North Korean hackers, particularly the <a href=\"https:\/\/news.bitcoin.com\/lazarus-group-launders-1-95m-in-stolen-ethereum-via-tornado-cash\/\">state-funded Lazarus Group<\/a>, have been blamed for some of crypto\u2019s largest thefts, most notably the approximately $1.5 billion Bybit breach in February 2025. Until investigators publish technical indicators, laundering patterns or other evidence tying Bitget\u2019s attacker to a known group, however, Lazarus should remain a hypothesis rather than a conclusion.<\/p>\n<h2>What Happens to Bitget Users Now?<\/h2>\n<p>For customers, the immediate problem is withdrawals. They remain disabled while Bitget conducts its security review. The exchange says its teams are simultaneously fixing the affected infrastructure and preparing to restore withdrawals, but Chen has declined to provide a reopening time she cannot guarantee. Deposits and trading remain available.<\/p>\n<p>The protection fund is now also under a microscope. Bitget says its more than $464 million value comfortably covers the estimated loss, although the notices released so far do not amount to an independent, real-time audit of the fund\u2019s composition or segregation.<\/p>\n<p>Recovery is another matter. <a href=\"https:\/\/news.bitcoin.com\/what-are-stablecoins-a-simple-explanation-of-the-digital-asset-bridging-crypto-and-fiat\/\">Fiat-pegged stablecoins<\/a> such as USDT and USDC can potentially be frozen through issuer-controlled contracts when assets remain identifiable. Native ethereum sitting in fresh wallets is considerably harder to stop, making the attacker\u2019s rapid conversion into ETH particularly significant.<\/p>\n<p>Chen has been <a href=\"https:\/\/x.com\/GracyBitget\/status\/2103383343178154140?s=20\" target=\"_blank\" rel=\"noopener noreferrer\">updating the community regularly<\/a>, and she stressed that the exchange is working with Mandiant and Slowmist on a full investigation into the incident. She reiterated once again that \u201cuser balances remain intact\u201d and said Bitget\u2019s User Protection Fund will cover losses stemming from the breach. Chen further added that Bitget Wallet was unaffected because its self-custodial infrastructure is separate from the exchange.<\/p>\n<p>This incident also should not be confused with Bitget\u2019s roughly $100 million April 2025 market-making, bot and arbitrage episode. That was a separate event with a different mechanism. The next major piece of evidence should come directly from Bitget. The exchange has promised hourly updates and a full incident report within 24 hours of its initial notice, including root-cause analysis and corrective measures.<\/p>\n<p>Until then, three numbers tell most of the story: $351.6 million was affected, more than $464 million supposedly stands behind it, and Bitget users are waiting for withdrawals to come back online. The fourth number, how much of the stolen crypto can actually be recovered, remains anyone\u2019s guess.<\/p>\n<\/p><\/div>\n<p><a href=\"https:\/\/news.bitcoin.com\/featured\/everything-we-know-about-bitgets-massive-351m-hack\/\">Source link <\/a><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>(Originally posted on : Bitcoin News ) Key Takeaways Bitget detected the $351.6M breach at 18:31 UTC on Sept. 24 and halted withdrawals. Gracy Chen says Bitget\u2019s $464M-plus protection fund can absorb the entire $351.6M loss. Bitget says private keys were not stolen, with a full technical report due within 24 hours. The exchange has [&hellip;]<\/p>\n","protected":false},"author":19,"featured_media":78654,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0},"categories":[32],"tags":[],"_links":{"self":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/78653"}],"collection":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/users\/19"}],"replies":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/comments?post=78653"}],"version-history":[{"count":0,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/78653\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media\/78654"}],"wp:attachment":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media?parent=78653"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/categories?post=78653"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/tags?post=78653"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}