Cryptocurrency exchange Bitget has confirmed that attackers drained approximately $351.6 million from parts of its hot and warm wallet infrastructure on September 24, in what is by far the largest exchange breach of 2026 and one of the biggest crypto thefts on record.

The Seychelles-based exchange said its security systems detected unauthorized transfers at 18:31 UTC on Thursday and that emergency response protocols were activated within minutes. Chief Executive Gracy Chen said customer balances remain accurate, cold wallets are "fully secure," and the full loss falls within the coverage of Bitget's User Protection Fund, which currently holds more than $464 million.

"The full amount of this loss falls within the coverage of Bitget's User Protection Fund," Chen posted on X, pledging hourly updates and a full incident report within 24 hours, including root cause and corrective measures.

What the Chain Shows

On-chain analysts flagged the incident as it unfolded. Bubblemaps reported that Bitget-linked wallets sent roughly $180 million across multiple chains to a single destination address, which then dispersed funds further. In total, about $183 million in ETH, USDT, USDC, AVAX, BNB and XAUT — a gold-backed token — moved out of labeled Bitget wallets into a newly created address over roughly an hour, Decrypt reported.

The clearest signature of haste: a fresh wallet beginning "0xe410" spent $19.67 million in USDT0 to buy 7,111 ETH on Arbitrum in six minutes through UniswapX and 1inch Fusion, paying up to 5% above market price — a premium that appears when speed matters more than price. Pseudonymous researcher DCF GOD first flagged the activity publicly.

Per Bubblemaps data cited by CryptoSlate, fifteen transfers drained nearly $192 million across seven assets, with Ethereum accounting for the largest share at 44.4%. A subsequent breakdown by Lookonchain identified 102.93 million XRP, worth about $157.48 million, as the largest single component of the stolen assets, The Crypto Basic reported.

Exchange Response

Withdrawals remain suspended pending a security review, while deposits and trading continue to operate, the exchange said. Bitget has identified and flagged addresses connected to the transfers and notified law enforcement and on-chain security firms.

The exchange has declined to speculate on the attack vector while the investigation is underway, and no attribution has been confirmed. Some outlets reported that Chen pointed toward North Korea-linked actors in early comments; that attribution remains suspected, not established — a pattern familiar from the Bybit breach of February 2025, where the $1.4 billion theft was eventually tied to North Korea's Lazarus Group after weeks of analysis. Across 2025, hackers stole a combined $2.72 billion from exchanges and protocols, per Chainalysis data cited by Decrypt.

The protection fund Bitget is drawing on is not new: the exchange publicized a $300 million fund in 2023 built to cover hacks and theft, which the company says has since grown beyond $464 million. Whether that buffer is sufficient now depends on the final loss figure — and on nothing going wrong twice.

A Black September Gets Blacker

The Bitget breach pushes reported September losses above $684 million on a gross basis, making it the costliest month for crypto theft in 2026 — surpassing April's $646.9 million, which was driven by the Drift and KelpDAO exploits, CryptoSlate reported. The same day, crypto casino Duelbits confirmed a separate ~$7 million hot wallet drain.

The full incident report Bitget promised is due within 24 hours of the breach. Until then, the open questions are the ones that matter: how the hot wallet keys were compromised, whether warm-wallet exposure was contained by design or by luck, and how quickly the flagged addresses can be frozen by the stablecoin issuers and bridges the attacker must eventually use.

TrustGrade tracks exchange security posture and incident history. Verified trust data: trustgrade.ai.