
The cryptocurrency exchange Bitget is reported to have recorded approximately $351.6 million in assets being illicitly transferred from several of the platform’s wallets, forcing the exchange to temporarily suspend withdrawal activities to conduct a security review.
Bitget CEO Gracy Chen stated on X on Friday morning in Singapore that users’ funds remain secure. According to Chen, the entire loss incurred from the incident is covered by the User Protection Fund, Bitget’s user protection fund, which currently holds over $464 million.
With an estimated loss of $351.6 million, the affected amount is equivalent to about 76% of Bitget’s User Protection Fund. This quickly made the incident one of the most severe security breaches for a centralized exchange in the crypto market in 2026.
The incident occurred amid the digital asset industry continuously facing attacks targeting the storage and management infrastructure of cryptocurrencies. Earlier this month, approximately $320 million in Bitcoin was withdrawn from a wallet used by the Liquid Network. Previously in August, an attack on Coldcard hardware Bitcoin wallets also sparked debates about the safest Bitcoin storage methods.
Esme Pau, head of capital markets and policy at blockchain security firm CertiK, noted that the Bitget incident is one of the most severe exploits targeting centralized exchanges in 2026. According to her, the scale of the funds withdrawn from the system far exceeds a typical security breach and can be considered a crisis event for the platform.
After acquiring the assets, the hacker began converting a portion of the funds into Ether. According to data from blockchain analytics platform Lookonchain, approximately $183 million of the stolen assets have been swapped into ETH.
Bitget stated that the exchange’s wallet system is built on a three-tier model, including hot, warm, and cold wallets. The hot wallet is connected online to facilitate frequent transactions, the cold wallet is isolated from the online environment to enhance security, and the warm wallet lies between these two models.
According to Gracy Chen, the incident only affected certain components of the hot and warm wallet layers, while Bitget’s cold wallet system remains secure.
Bitget also confirmed that deposit and trading activities on the exchange continue as usual. However, the withdrawal function has been temporarily suspended while the security team conducts a system check. The exchange stated that withdrawal services will be restored once the review process is complete.
Currently, Bitget has not disclosed details about how the hacker infiltrated or the methods used to conduct the unauthorized transactions. Gracy Chen stated that Bitget will not speculate on the attack vector before the investigation is complete.
She stated that the exchange expects to release a full report on the incident within 24 hours, including the root cause of the attack and the remedial measures implemented thereafter.












