What exactly happened?
The Bitget exchange has officially confirmed a security incident. According to a statement by CEO Gracy Chen on the platform X, unauthorized transfers occurred from a limited number of so-called hot and warm wallets (operational wallets connected to the internet, from which the exchange settles routine transactions).
According to CryptoSlate, the exchange recorded the transfers on September 24, 2026, at 18:31 UTC and activated emergency procedures within minutes. The total damage is estimated at approximately $351.6 million. Fifteen transactions drained nearly $192 million across seven different assets, with the largest share (44.4 percent) attributed to Ethereum. According to CryptoSlate, the data on the distribution of the transfers comes from the analytics platform Bubblemaps.
The Polish outlet BitHub.pl cites the same timing of the incident (20:31 Polish time, corresponding to 18:31 UTC) and confirms that this is an officially announced event, not an unverified rumor.
Did clients lose money?
According to Gracy Chen, client balances remain accurate and cold wallets (offline storage separated from the internet), along with most assets on the platform, remained untouched. CryptoSlate reports that the exchange suspended withdrawals and that the losses are to be covered. The exact terms and the speed at which withdrawals will resume do not yet follow from the available sources.
What is confirmed at this moment and what is not is summarized in the table below.
| Item | Status |
|---|---|
| Damage of approx. $351.6 million | Confirmed (CryptoSlate) |
| Detection time Sept. 24, 2026, 18:31 UTC | Confirmed (CryptoSlate, BitHub.pl) |
| Ethereum = 44.4% of drained assets | Confirmed (CryptoSlate, Bubblemaps data) |
| Cold wallets untouched | Stated by the exchange (CryptoSlate) |
| Suspension of withdrawals | Confirmed (CryptoSlate) |
| Perpetrator of the attack | Unproven |
Who is behind the attack?
Caution is needed here. According to Cointelegraph, Gracy Chen stated that a preliminary investigation found IP addresses corresponding to VPN choices that are associated with a hacker group from the DPRK (North Korea). That is an indication, not proof. IP addresses and VPNs can be swapped or falsified, and the attribution of cyberattacks tends to be a lengthy process. Until an independent forensic confirmation is heard, the perpetrator of the attack remains in the status of "unknown."
It is worth recalling that this is a developing situation and the numbers as well as the conclusions may be refined.
How did the market react?
According to the Slovak outlet Kryptonovinky.sk, Bitcoin barely moved on the incident. Over the past 24 hours it weakened by just 0.2 percent and is trading around $84,300. On a seven-day horizon it is still up by more than 10 percent. Kryptonovinky.sk also notes that ETF funds remain in the green.
It is a reminder that an incident at one exchange and the movement of the overall market are two different things. The fact that Bitcoin's price did not fall does not mean that the damage at Bitget is not real. These are separate phenomena that it is only fair not to conflate.
What to watch out for with this type of event?
Without advice on what to do with your money, just what is worth watching in the case of exchange incidents in general:
- Resumption of withdrawals: when and under what conditions the exchange restarts withdrawals is a concrete, verifiable signal.
- Independent forensic reports: attack attribution from on-chain analysts (for example Bubblemaps and others) versus the claims of the exchange itself.
- Coverage of losses: whether and how the exchange actually carries out the declared compensation.
- Communication timeline: how quickly and transparently the exchange provides information.
charliedesk will continue to follow this story and will update it as soon as verified information about the perpetrator of the attack or the resumption of withdrawals appears.

