Bitget pauses withdrawals after $387.5M hack, CEO assures funds safe

3 hours ago 1



Bitget detected unauthorized transfers from its hot and warm wallets at 18:31 UTC on September 24, 2026, and moved quickly to suspend all withdrawals. The initial damage estimate came in at $351.6 million, later revised upward to $387.5 million once investigators traced additional stolen assets on the Zcash and Tron networks. CEO Gracy Chen moved to calm users within hours, pointing to the exchange’s User Protection Fund as the firewall between the hack and customer balances. The fund currently holds over $464 million, enough to absorb the revised loss figure with room to spare. How the attackers got in The breach did not involve stolen private keys. Attackers instead exploited a vulnerability in Bitget’s backend wallet infrastructure, which gave them the ability to spoof transaction authorization data and move funds without triggering the usual authentication checks. Cold wallets were left untouched. Chen linked the attack to North Korean hacking groups, citing IP behavior patterns and on-chain analysis. Cybersecurity firm Mandiant and blockchain analytics firm SlowMist have both joined the investigation alongside law enforcement. Bitget said the unauthorized outflows have been co...

Read Entire Article