Current outcome
Bitget is gradually returning to normal operations, with its Protection Fund reaching $309M; BTC, ETH and USDT withdrawals are restored, and withdrawals for all tokens are expected to resume Friday. The CEO said the incident caused $388M in user losses and that an inside job or North Korean hackers have not been ruled out; prior investigation items such as the attacker moving ZEC into the Ironwood shielded pool continue.
Progress timeline
22 material updates- #01
Crypto exchange Bitget says $352 million affected in a hack, claims user funds are 'safe'
Bitget CEO Gracy Chen disclosed a breach exposing about $351.6 million through unauthorized transfers from hot and warm wallets, saying cold wallets and user funds are safe while withdrawals are temporarily paused pending a security review.
Source evidence: CoinDesk · CryptoSlate · Decrypt · The Block · The Defiant · finance.biggo.com · Cointelegraph
- #02
Bitget Hack: $351.6M Stolen, Biggest Breach of 2026 - shattered.io
Bitget is reported to have suffered a security breach in which $351.6M was stolen, described as the largest crypto exchange hack of 2026.
Source evidence: shattered.io · The Cryptonomist · Pluang · Substack · TradingView · CNBC · Substack · The Tech Buzz · CryptoSlate · tech-insider.org · Decrypt · Bitcoin Magazine · CoinDesk · CoinDesk · The Defiant · Protos · Binance · tokenpost.com · Coinfomania · CryptoSlate · Cointelegraph · Pluang · CryptoSlate · The American Bazaar · Cointelegraph · Hokanews · 24/7 Wall St.
- #03
$351M GONE… AND THE HACKER IS ALREADY SWAPPING IT! - Binance
$351M has reportedly been stolen in a hack, and the attacker is already swapping the stolen funds.
Source evidence: Binance
- #04
Circle and Tether Freeze Stablecoins Tied to Bitget Hack—But Most Funds Slip Away
Circle and Tether froze roughly $318,000 in USDC and USDT tied to the ~$387 million Bitget hack, while the attacker's ~170 ETH and other exploiter-held ETH remained beyond the issuers' reach.
Source evidence: Decrypt
- #05
Bitget hacker moves $83 million in stolen XRP that Ripple cannot freeze
The attacker behind Bitget's $387.5M breach drained about $83M of stolen XRP from three holding wallets, leaving roughly $75M in accounts that cannot be frozen under the XRP Ledger's rules, while Bitget said its protection fund covers losses and staged withdrawals resume Sept. 28 through Oct. 2.
Source evidence: CoinDesk
- #06
THORChain Rejects Request to Block Bitget Addresses Amid Exploit Fallout - Intellectia AI
THORChain rejected a request to block Bitget-related addresses in the wake of an exploit, with the network's decision highlighting its refusal to censor transactions at the request of an exchange or third party.
Source evidence: Intellectia AI · BeInCrypto · The Defiant
- #07
Bitget freezes XRP withdrawals as 27M stolen tokens move
Bitget left XRP withdrawals disabled as it scheduled its final post-breach withdrawal reopening phase for Oct. 2, while Bitquery traced 27.63 million stolen XRP moving onward from two tracked accounts.
Source evidence: CryptoSlate
- #08
GoPlus Challenges THORChain's Decentralization Claims Amid $80 Million XRP Movement From Bitget Hack - finance.biggo.com
GoPlus pushed back on THORChain's decentralization claims while tracing about $80 million in XRP tied to the Bitget hack.
Source evidence: finance.biggo.com
- #09
Crypto Morning Brief: Upbit L2 Project GIWA Issues Official Clarification, Bitget to Gradually Resume Withdrawals
Upbit's L2 project GIWA issued an official clarification and Bitget announced it will gradually resume withdrawals, according to a crypto morning brief.
Source evidence: 深潮TechFlow · The Defiant · CryptoSlate · CryptoSlate
- #10
- #11
Bitget had 30 minutes to contain its hack before $290 million started moving
Bitget detected unauthorized wallet transfers about 30 minutes before attackers drained $87.6 million and then $202.8 million from its hot wallets, meaning most of the $387.5 million loss occurred after the exchange's emergency protocols were triggered and raising questions about why the compromised signing route stayed live.
Source evidence: CryptoSlate · Cointelegraph
- #12
NEAR Intents says it blocked $50M tied to Bitget hackers
NEAR Intents' SHIELD system blocked over $50 million in attempted transfers tied to the Bitget hackers, freezing $503,000 mid-execution while about $166,000 passed through; NEAR Intents said it will forego Bitget's bounty.
State after update: Circle and Tether froze roughly $318,000 in USDC/USDT tied to the Bitget hack; NEAR Intents' SHIELD system blocked over $50 million in related transfers and froze $503,000, with about $166,000 passing through; attacker-held ETH remained beyond some issuers' reach.
Source evidence: Cointelegraph · CoinDesk · The Defiant
- #13
【Bitget BTC 保护基金已流出 3215 枚 BTC,价值约 2.66 亿美元】 Foresight News 消息,据 @ai_9684xtpa 监测
Bitget's BTC protection fund has seen 3,215.28 BTC (~$266M) flow out on-chain, leaving 2,284.71 BTC of the original 5,500 BTC, per @ai_9684xtpa monitoring.
Source evidence: foresightnews
- #14
Bitget CEO ‘not very optimistic’ on recovering funds from $388M breach
Bitget CEO Gracy Chen said she is 'not very optimistic' about freezing or recovering the funds from the ~$388M breach, citing Bybit's Feb 2025 hack (only ~3.5% of stolen funds frozen) as a reference. Bitget launched a bounty offering 5% for frozen and 5% for recovered funds. NEAR Intents team said it blocked over $50M in assets tied to the attack and froze ~$500K; Chen confirmed Tether and Circle blacklisted a linked wallet, freezing $318,013 in USDT/USDC. Withdrawals resumed in stages: BTC on Monday, ETH on Tuesday. Chen said North Korea may be responsible but did not fully rule out an inside job, though she said that possibility had been ruled out.
State after update: Bitget is resuming withdrawals in stages (BTC Monday, ETH Tuesday) and launched a bounty (5% for frozen, 5% for recovered funds); NEAR Intents blocked over $50M in related assets and froze ~$500K; Tether and Circle froze ~$318K; CEO Gracy Chen is 'not very optimistic' about recovering the ~$388M loss and said an inside job has been ruled out.
Source evidence: Cointelegraph · finance.biggo.com · TradingView
- #15
Bitget $388M Hack: CEO Cites Bybit's 3.5% Freeze Rate
Bitget CEO Gracy Chen addressed recovery efforts following a $388M hack at the exchange, contrasting them with Bybit's $1.5B breach and citing Bybit's 3.5% freeze rate as a comparative benchmark.
Source evidence: FinanceFeeds
- #16
【慢雾余弦:朝鲜黑客利用 Cow 与 Chainflip 跨链转移 Bitget 被盗资金并兑换为 BTC】
SlowMist's Yu Xian reports North Korean hackers are laundering Bitget's stolen funds by using Cow Protocol and Chainflip for cross-chain swaps into BTC.
State after update: Bitget's stolen funds are being laundered by North Korean hackers via Cow Protocol and Chainflip cross-chain swaps into BTC.
Source evidence: foresightnews
- #17
SlowMist: Suspected North Korean Hackers Route Bitget Funds Through CoW, Chainfl
SlowMist's MistTrack reports suspected North Korean hackers are laundering stolen Bitget funds (~$350M hack) by using automated CoW Protocol orders that route settled assets into pre-generated Chainflip deposit contracts for conversion to BTC.
Source evidence: wublockchainenglish
- #18
【慢雾:Bitget 热钱包被盗事件涉及第三方产品零日漏洞】
SlowMist's preliminary investigation found that the September 25 Bitget hot wallet theft stemmed from a third-party product zero-day exploited with a compromised internal employee identity and a customized withdrawal tool, enabling ~2h52m of cross-chain transfers and further attempts to manipulate withdrawal records to trigger additional BTC withdrawals; SlowMist is still investigating how the attacker moved between affected systems.
State after update: SlowMist's preliminary investigation attributes the September 25 Bitget hot wallet theft to a third-party product zero-day and a compromised internal employee identity, with the attacker using a customized withdrawal tool to move assets across multiple chains over ~2h52m and attempting further BTC withdrawals; SlowMist continues investigating. Previously, Bitget was resuming withdrawals in stages, launched a bounty, NEAR Intents blocked over $50M in related assets and froze ~$500K, Tether and Circle froze ~$318K, and CEO Gracy Chen was 'not very optimistic' about recovering the ~$388M loss while saying an inside job had been ruled out — a statement now in tension with the preliminary finding of a compromised internal employee identity.
Source evidence: foresightnews
- #19
【Bitget 已向保护基金划转 2000 枚 BTC,规模回升至 2 亿美元】
Bitget moved 2,000 BTC (~$166M) from its cold wallet to its protection fund address, restoring the fund's on-chain balance to 2,484.71 BTC (~$206M), beginning to fulfill its pledge to replenish the fund to $300M within a week.
State after update: SlowMist's preliminary investigation attributes the September 25 Bitget hot wallet theft to a third-party product zero-day and a compromised internal employee identity, with the attacker using a customized withdrawal tool to move assets across multiple chains over ~2h52m and attempting further BTC withdrawals; SlowMist continues investigating. Previously, Bitget resumed withdrawals in stages, launched a bounty, NEAR Intents blocked over $50M in related assets and froze ~$500K, Tether and Circle froze ~$318K, and CEO Gracy Chen was 'not very optimistic' about recovering the ~$388M loss. Latest development: Bitget has moved 2,000 BTC (~$166M) from its cold wallet to its protection fund, bringing the fund's on-chain balance back to 2,484.71 BTC (~$206M), fulfilling part of its pledge to restore the fund to $300M within a week.
Source evidence: foresightnews
- #20
SlowMist traces Bitget hack activity to Aug. 31 zero-day exploit
SlowMist's progress report traces the earliest malicious activity in the Bitget theft to Aug. 31, when an attacker exploited a zero-day in a third-party security product; it also found the attacker accessed 'Product A' database via a hidden script after retrieving its password from an environment variable, with similar activity on two other nodes on Sept. 23 and Sept. 25, and on Sept. 25 accessed a second security product ('Product B') management platform using an internal employee identity, attempting command injection, server config changes and uploading malicious files; on-chain verification found the earliest transfer at 2:31 am UTC+8 Sept. 25 (93 TRX, then 0.84 ETH 11 seconds later), compiled transfers spanning ~2h52m until 5:23 am.
State after update: SlowMist's investigation pushes the timeline of the Sept. 25 Bitget hot wallet theft (~$388M) back to Aug. 31, attributing it to a third-party security product zero-day; the attacker moved laterally over weeks across two third-party security products and a wallet application host, and used a deleted, highly customized withdrawal tool that forged risk-control parameters to issue withdrawal requests; SlowMist continues investigating how the attacker moved between affected systems. Bitget had previously resumed withdrawals in stages, launched a bounty, NEAR Intents blocked over $50M in related assets and froze ~$500K, Tether and Circle froze ~$318K, and Bitget moved 2,000 BTC from its cold wallet to its protection fund, restoring the fund to 2,484.71 BTC (~$206M).
Source evidence: Cointelegraph
- #21
【Bitget 被盗事件攻击者开始将约 2700 枚 ZEC 转入 Ironwood 屏蔽池】
On-chain investigator ZachXBT said the attacker linked to the Bitget hot-wallet theft has started moving roughly 2,700 ZEC (~$3.8M) into Zcash's Ironwood shielded pool; the Bitget hot wallet had lost about 18,900 ZEC (~$28.3M) in total.
State after update: SlowMist pushed the Bitget hot-wallet theft timeline back to Aug. 31, attributing it to a third-party security product zero-day; the attacker moved laterally over weeks and used a customized withdrawal tool that forged risk-control parameters. Bitget resumed withdrawals in stages, launched a bounty, NEAR Intents blocked over $50M in related assets and froze ~$500K, Tether and Circle froze ~$318K, and Bitget moved 2,000 BTC from its cold wallet to its protection fund. Latest development: the suspected DPRK-linked attacker began moving roughly 2,700 ZEC (~$3.8M) into Zcash's Ironwood shielded pool, part of the ~18,900 ZEC (~$28.3M) stolen from Bitget's hot wallet.
Source evidence: foresightnews · wublockchainenglish
- #22
Bitget ‘gradually back to usual’ as protection fund reaches $309M
Bitget CEO Gracy Chen said operations are gradually returning to normal and the Protection Fund has reached $309M; withdrawals for all tokens will resume Friday, while BTC, ETH and USDT access has already been restored. She said the incident resulted in $388M in user losses and Bitget has still not ruled out an inside job or North Korean hackers.
State after update: Bitget is gradually returning to normal operations, with its Protection Fund reaching $309M; BTC, ETH and USDT withdrawals are restored, and withdrawals for all tokens are expected to resume Friday. The CEO said the incident caused $388M in user losses and that an inside job or North Korean hackers have not been ruled out; prior investigation items such as the attacker moving ZEC into the Ironwood shielded pool continue.
Source evidence: Cointelegraph