Status reviewed September 28, 2026: Bitget confirmed an exchange hot/warm-wallet infrastructure incident, not a breach of the separate self-custodial Bitget Wallet. The company says the event is contained and the vulnerability remediated, while forensics and recovery remain ongoing. Withdrawal availability must be checked in the account for each asset and network.

What happened?

According to Bitget's initial security notice and subsequent incident summary, systems detected unauthorized transfers from part of the exchange's hot and warm wallet infrastructure across multiple chains at about 18:31 UTC on September 24.

Bitget says an attacker compromised a critical backend system, spoofed transaction data and triggered the authorization process. The company says the attack path was identified, the underlying vulnerability remediated and private-key compromise ruled out based on the investigation to date. Mandiant and SlowMist continue to support forensic review and tracing.

Why did the estimate rise from $351.6M to $387.5M?

The initial estimate was about $351.6 million. After further transaction classification, Bitget revised it to about $387.5 million, including Zcash- and TRON-related transfers not captured initially. The company says this was a more complete accounting, not a second drain after containment.

What was and was not affected?

AreaPublished statusImportant context
Exchange hot/warm walletsPart of the infrastructure had unauthorized transfersRemediation is reported complete; forensics continue
Cold walletsBitget says they were unaffectedThis remains a company disclosure rather than something users can prove from an account balance
User ledger balancesBitget says they were unaffectedA displayed balance and immediate withdrawal availability are different questions
Bitget WalletReported unaffectedIt uses separate self-custodial infrastructure
WithdrawalsPhased restorationAvailability varies by asset and network

Withdrawal restoration schedule

Bitget's published schedule lists BTC on September 28 at 08:00 UTC, ETH on supported EVM networks on September 29, USDT on selected networks on September 30, and other tokens, fiat and P2P on October 2. This is a plan, not this site's guarantee. Users should rely on the authenticated withdrawal screen.

Direct impact on users

  • Liquidity restriction: trading and displayed balances can remain available while funds cannot leave through a paused network.
  • Operational errors: staggered reopening increases the chance of choosing the wrong network or resubmitting delayed requests.
  • Phishing: fake compensation, expedited withdrawal and asset-migration messages exploit the event.
  • Trust and cost: the market will assess restoration, investigation transparency, fund recovery and the economic cost of using the Protection Fund.

Impact on BGB and the exchange industry

BGB is closely tied to expectations for the Bitget ecosystem, so an exchange security event can raise volatility and cause the market to reprice platform, regulatory and protection-fund risk. Even if users are made whole, remediation, tighter controls and reputation repair can affect the business.

The broader lesson is that cold storage and multisignature controls do not by themselves solve a compromised transaction-construction or backend authorization system. Exchange security must protect the complete route from transaction data and approvals to signing and withdrawal restoration.

Five things to monitor

  1. Whether each network reopens and real test withdrawals settle normally.
  2. Whether a full forensic report explains the entry point and failed controls.
  3. Freezing, tracing, recovery and bounty progress.
  4. Protection Fund replenishment and updated reserve disclosures.
  5. Any further unauthorized transfer or service restriction.
A company statement that balances are safe is not the same as deposit insurance or the end of operational risk. After a network reopens, test a small amount before making a larger custody decision.

Practical next step: the Bitget user safety and withdrawal checklist.