Bitget CEO Gracy Chen said the exchange can absorb the roughly $350 million stolen from its wallets on September 24, 2026, and handle a potential surge in withdrawals when they resume, according to Coinpedia. She compared Bitget’s retail trading volume with that of Bybit, arguing that if Bybit withstood a $1.5 billion loss, Bitget could manage a loss of more than $300 million.
Chen also said the breach has been contained and that no further unauthorized transfers are possible. Ambcrypto reported she ruled out private key compromise, which excludes the more severe risk scenarios, and said the attackers breached Bitget’s backend wallet infrastructure and fooled its authorization process. The exchange has since addressed that breach, she said.
Also readBitcoin Whales Absorb Record Retail Selling as Supply in Loss Hits All-Time High
Key facts
- Bitget detected unauthorized transfers from some hot wallets at 18:31 UTC on September 24, 2026, and activated emergency response protocols, per Bitcoinmagazine.
- Ambcrypto and Bitcoinmagazine put the loss at $351.6 million, while Coinpedia reported about $350 million. XRP accounted for $157.4 million; Ethereum, USDT and USDC together added more than $140 million.
- Chen said the attack was “very likely” carried out by a North Korean group, citing IP addresses matching the VPN choices of a certain DPRK group — she said it was not internal.
- Web3 security analyst Specter linked the stolen XRP to the July AFX hack, attributed to the Lazarus group, according to Ambcrypto.
- Bitget’s user protection funds surpass $464 million, which Ambcrypto reported is sufficient to cover the loss. Chen said cold wallets remained fully secure, per Bitcoinmagazine.
Funds moving on-chain
Ambcrypto reported that the attacker had begun swapping the funds into EVM chains through multiple wallets to obscure and launder them, with $163 million swapped to ETH so far. Some public chains have frozen stolen funds, Coinpedia reported, and recovery efforts continue, though Chen does not expect a full recovery.
Bybit CEO Ben Zhou reached out to offer help, including assistance tracking and tagging the attackers’ wallets, Ambcrypto reported. Bitget said deposits and trading remain fully operational, while withdrawals are paused pending a security review, according to Bitcoinmagazine.
The incident ranks as the second-largest centralized exchange breach after last year’s $1.5 billion Bybit hack, a distinction Ambcrypto highlighted, noting these high-value breaches are mainly handled by Lazarus Group. Bitcoinmagazine placed the year’s security troubles in context, citing a July attack on a firmware bug in the Coldcard hardware wallet that stole nearly $120 million in user funds, and the withdrawal this month of about 4,000 bitcoins — worth about $320 million at the time — from Blockstream’s Liquid sidechain federation wallet.
Why it matters
Centralized exchanges continue to be prime targets, and the Bitget case shows that hot wallet infrastructure can be exploited even when private keys are not compromised. That distinction matters for users: stolen keys would have left attackers with continued control over affected wallets, whereas Bitget says containment has ended the threat of further unauthorized transfers.
For customers, the immediate question is restitution. With protection funds above $464 million against a loss of roughly $352 million, Ambcrypto assessed that users will likely be refunded fully. The pause on withdrawals, however, is the practical pressure point, and Chen has not committed to a timeline.
What to watch
The next developments are the security review’s completion and the exchange’s announcement of a withdrawal timeline. On-chain activity is also worth tracking, since Ambcrypto reported continued swapping of stolen assets into ETH and roughly $163 million already converted. Recovery efforts, including frozen funds on some public chains, remain unresolved, with Chen not expecting full recovery.
Sources: Coinpedia, Ambcrypto, Bitcoinmagazine




