The $387 Million Bitget Hack, and What It Means If Your Crypto Sits on an Exchange
In This Article
Introduction
On September 24, someone walked $387.5 million out of Bitget's hot and warm wallets in about an hour, and the story of how they did it is more useful than the number itself. This wasn't a phishing link. It wasn't a stolen seed phrase. It wasn't even, strictly speaking, a break-in — no private keys were stolen and no user's withdrawal request was forged. Attackers got into a backend system inside Bitget's wallet infrastructure and spoofed transaction data well enough that the exchange's own authorization process approved the payouts as routine.
That distinction is the entire reason this is worth ten minutes of anyone's time who keeps crypto on an exchange, not just Bitget's users.
What Actually Happened
Bitget's security systems flagged unauthorized transfers at 18:31 UTC on September 24. Within about an hour, on-chain investigators had already tracked roughly $183 million in stablecoins, ETH, XRP and other assets leaving wallets tied to the exchange. The attacker moved fast on purpose — swapping stolen stablecoins for ETH within minutes, a standard move to get ahead of any exchange freeze, since stablecoin issuers can blacklist an address but nobody can claw back ETH once it's moved.
The confirmed total climbed twice: to $351.6 million when Bitget went public with the breach, then to $387.5 million the next day as the investigation traced further transfers. That makes it the largest single crypto hack of 2026 so far.
Not a Phishing Story
Almost every crypto-loss story that reaches a general audience is some version of "someone got tricked." A fake airdrop, a cloned wallet-connect popup, a seed phrase typed into the wrong website. This one wasn't that, and the difference matters. The attacker didn't need a single user to click anything. They compromised infrastructure Bitget itself controls — the backend system that approves outbound transfers — and fed it spoofed data convincing enough to pass as a legitimate payout instruction.
In other words: nothing any Bitget customer did, or didn't do, made a difference here. That's the uncomfortable part of custodial risk. It doesn't live in your habits. It lives in the exchange's own systems, and you have no visibility into how well-defended they are.
Why North Korea Is the Suspect
Bitget CEO Gracy Chen said investigators traced IP addresses and on-chain behavior patterns to VPN infrastructure previously linked to North Korea's state-backed hacking groups. It's not the first time this year: North Korean-linked actors were tied to a $280 million theft from Kelp and a $290 million theft from Drift earlier in 2026. Attribution in crypto hacks is never airtight — VPN fingerprints and wallet-clustering patterns are strong circumstantial evidence, not a signed confession — but the pattern across three separate platforms in one year is hard to wave away as coincidence.
Why Customers Aren't Actually Losing Money
The headline number is $387.5 million, but Bitget says no customer lost a cent of it. The exchange's User Protection Fund holds more than $464 million, built specifically to absorb an event like this, and Chen confirmed it will cover the full loss. Customer balances on the platform remain intact even though the stolen assets themselves are gone for good.
Withdrawals are coming back in phases rather than all at once: Bitcoin withdrawals resumed at 08:00 UTC on September 28, with Ethereum and other EVM-network withdrawals following on September 29. That staggered restart is standard practice after a breach — it gives the exchange time to confirm each network's systems are clean before opening the tap.
The Part That Actually Matters for You: Hot Wallets vs. Cold Wallets
Here's the distinction that turns this from "a story about Bitget" into something worth understanding regardless of which exchange you use. A [hot wallet](/glossary/hot-wallet) is connected to the internet — it's how an exchange keeps enough crypto liquid to process withdrawals on demand. A [cold wallet](/glossary/cold-wallet) is kept offline, usually on dedicated hardware, specifically so it can't be reached remotely no matter how good an attacker's access to internet-facing systems is.
Every major exchange keeps the large majority of customer funds in cold storage precisely because hot wallets are the part of the system an attacker can actually reach. Bitget's hot and warm wallets were the target here — not because cold storage failed, but because cold storage was never in the blast radius to begin with. That's the whole design logic of separating the two.
The broader lesson isn't "hot wallets are bad" — an exchange can't function without them, since somebody has to be able to withdraw on a Tuesday afternoon without a multi-day delay. It's that keeping crypto on any exchange, hot or cold, means trusting that exchange's engineering team over your own control of the keys. That's the real meaning of [custodial vs. non-custodial](/glossary/custodial-vs-non-custodial): custodial convenience is a real trade, not a free one.
What This Means If You Keep Crypto on an Exchange
None of this is an argument to panic-withdraw everything today. It's an argument for being deliberate about a trade-off most people make without ever naming it:
- Exchange balances are a convenience, not a vault. Keep what you need for active trading or near-term use there. Treat anything you're not planning to touch for months as a candidate for self-custody.
- User protection funds are real, but they're not a guarantee. Bitget's fund covered this one in full. Not every exchange holds one this size, and a fund can only absorb what it's large enough to cover.
- "Which exchange" is a real question, not a formality. Track record, transparency about incidents, and the size of a protection fund are the closest thing to due diligence available before something goes wrong, not after.
- Self-custody has its own risks, not zero risk. The [Coldcard firmware flaw](/blog/coldcard-wallet-hack-116-million-self-custody-bitcoin-2026) that leaked $116 million earlier this year is proof that moving off exchanges doesn't mean moving off risk entirely — it means trading exchange risk for a different set of risks you're now responsible for managing yourself.
Frequently Asked Questions
Q: Is my money safe if I have funds on Bitget?
A: According to Bitget, yes — the exchange says its User Protection Fund is covering the full $387.5 million loss, so no customer balance is reduced. Withdrawals are reopening in phases, Bitcoin first.
Q: How did hackers get in without phishing anyone?
A: They compromised a backend system inside Bitget's own wallet infrastructure and spoofed transaction data well enough that Bitget's automated authorization process approved the transfers as routine. No user credentials, seed phrases, or private keys were involved.
Q: What's the difference between a hot wallet and a cold wallet?
A: A hot wallet stays connected to the internet so an exchange can process withdrawals on demand — it's also the part reachable by a remote attacker. A cold wallet is kept offline, usually on hardware, specifically so it can't be reached remotely at all. Exchanges keep most customer funds in cold storage for exactly this reason.
Q: Is this the biggest crypto hack of 2026?
A: Yes, at $387.5 million it's the largest confirmed crypto theft so far this year, ahead of the roughly $290 million Drift theft and $280 million Kelp theft earlier in 2026 — both also linked to suspected North Korean state-backed hackers.
Q: Why do exchanges keep any funds in hot wallets if they're the risk?
A: Because an exchange with zero funds available for instant withdrawal isn't functional — every withdrawal would require manually retrieving assets from cold storage, which can take hours or days. Hot wallets are a deliberate, limited exposure exchanges accept to keep the platform usable.
Q: Should I move my crypto off exchanges after this?
A: That depends on how you use it and how much risk you're comfortable managing yourself. Self-custody removes exchange risk but replaces it with the responsibility of securing your own keys — including risks like the 2026 Coldcard firmware flaw, which affected wallets with no exchange involved at all. Neither option is risk-free; they're different risks.
Q: Why is North Korea suspected instead of a random hacking group?
A: Bitget's investigators traced IP addresses and VPN infrastructure to patterns previously linked to North Korean state-backed hacking operations, and the fast stablecoin-to-ETH conversion matches tactics seen in earlier 2026 thefts from Kelp and Drift that carried the same attribution. It's strong circumstantial evidence, not a confirmed claim.
The Bottom Line
$387.5 million disappearing from an exchange in about an hour sounds like the kind of thing that should change how you think about keeping crypto anywhere but your own wallet. It should — just not in the direction of "exchanges are unsafe, full stop." Bitget's customers are being made whole, the breach targeted infrastructure no user could have defended against, and cold storage did exactly what it's designed to do by staying entirely out of reach. The real takeaway is narrower and more useful: know which wallet type is holding your funds at any given exchange, understand that a protection fund is a backstop and not a guarantee, and size what you keep on any single platform to what you're actually willing to have depend on that platform's own security team having a good week.
This content was created with AI assistance and may contain errors, always verify before acting. Not financial advice. Always do your own research before making any investment decisions.
Frequently Asked Questions
Is my money safe if I have funds on Bitget?
According to Bitget, yes — the exchange says its User Protection Fund is covering the full $387.5 million loss, so no customer balance is reduced. Withdrawals are reopening in phases, Bitcoin first.
How did hackers get in without phishing anyone?
They compromised a backend system inside Bitget's own wallet infrastructure and spoofed transaction data well enough that Bitget's automated authorization process approved the transfers as routine. No user credentials, seed phrases, or private keys were involved.
What is the difference between a hot wallet and a cold wallet?
A hot wallet stays connected to the internet so an exchange can process withdrawals on demand — it's also the part reachable by a remote attacker. A cold wallet is kept offline, usually on hardware, specifically so it can't be reached remotely at all. Exchanges keep most customer funds in cold storage for exactly this reason.
Is this the biggest crypto hack of 2026?
Yes, at $387.5 million it's the largest confirmed crypto theft so far this year, ahead of the roughly $290 million Drift theft and $280 million Kelp theft earlier in 2026 — both also linked to suspected North Korean state-backed hackers.
Why do exchanges keep any funds in hot wallets if they are the risk?
Because an exchange with zero funds available for instant withdrawal isn't functional — every withdrawal would require manually retrieving assets from cold storage, which can take hours or days. Hot wallets are a deliberate, limited exposure exchanges accept to keep the platform usable.
Should I move my crypto off exchanges after this?
That depends on how you use it and how much risk you're comfortable managing yourself. Self-custody removes exchange risk but replaces it with the responsibility of securing your own keys — including risks like the 2026 Coldcard firmware flaw, which affected wallets with no exchange involved at all. Neither option is risk-free; they're different risks.
Why is North Korea suspected instead of a random hacking group?
Bitget's investigators traced IP addresses and VPN infrastructure to patterns previously linked to North Korean state-backed hacking operations, and the fast stablecoin-to-ETH conversion matches tactics seen in earlier 2026 thefts from Kelp and Drift that carried the same attribution. It's strong circumstantial evidence, not a confirmed claim.
Let AI summarize these channels for you daily
Pick your favorite crypto YouTube channels and news sites. Get a 5-minute AI brief every morning.
Choose Your Sources