The Bitget incident is a hot wallet compromise, not a breach of offline storage, and that distinction decides how much of the damage users and the exchange will ultimately absorb. The exchange’s CEO says cold wallets are intact, that customer funds are safe, and that a protection fund can cover the entire loss. The size of that loss is still contested: on-chain trackers saw about $183 million leave, while Decrypt reports more than $350 million.

That gap matters because the two figures come from different vantage points. One is what outside analysts could see moving from publicly labeled addresses. The other is the number reported after the CEO confirmed the hack.

Key Takeaways

  • Bitget CEO Gracy Chen confirmed unauthorized transfers from hot wallets, detected at 18:31 UTC on Sept 24, 2026.
  • On-chain data showed roughly $183 million in assets moved to one new address in about an hour; Decrypt reports total losses above $350 million.
  • Chen says cold wallets remain “fully secure” and the loss falls within Bitget’s User Protection Fund, which holds over $464 million.
  • The attacker converted stablecoins to ETH in minutes at a roughly 5% premium, a sign of speed over price.

What happened on Sept 24

Bitget’s security systems flagged unauthorized transfers from some hot wallets at 18:31 UTC on Sept 24, according to a notice Chen posted on X. The company says it activated emergency response protocols immediately.

Outside observers noticed first. Analysts at Bubblemaps and Arkham flagged unusual activity late Thursday, describing Bitget as “potentially hacked,” per Decrypt. Pseudonymous researcher DCF GOD, who first flagged the activity on X, reported that wallets tagged as Bitget’s sent ETH, AVAX, BNB, USDC, USDT and XAUT (a token backed by physical gold) to the same address. Over about an hour, roughly $183 million left wallets labeled as the exchange’s.

Users reported blocked withdrawals, and Bitget confirmed the hack after Decrypt published its first report.

How the funds moved

The mechanics point to a deliberate, time-pressured cash-out. A newly created address beginning with “0xe410” took $19.67 million in USDT0, a cross-chain version of Tether’s dollar-pegged stablecoin, and swapped it for 7,111 ETH in six minutes on Arbitrum.

The swaps ran through UniswapX and 1inch Fusion, which let traders exchange tokens on-chain without an intermediary. Decrypt reports, citing other reports, that whoever placed the orders paid up to about 5% above the market rate. That kind of premium shows up when speed matters more than execution price.

The conversion has a practical purpose. Stablecoins like USDT can be frozen by their issuer, while ETH is decentralized and hard to seize. Swapping into it quickly puts the proceeds beyond easy reach.

Outflows from the publicly labeled wallets appeared to stop roughly six minutes after the first suspicious trade and stayed quiet for at least 20 minutes, per Decrypt. That pattern is consistent with an exchange freezing withdrawals while it investigates, though the brief does not confirm a cause for the pause.

Hot wallets, cold wallets and a conflicting detail

The hot wallet is the internet-connected reserve an exchange uses to process everyday withdrawals quickly. A cold wallet is kept offline. Chen said only hot wallets were affected and that cold wallets remain “fully secure.”

Decrypt’s own subheading says the wallet drained “hot and cold reserves labeled as belonging to Bitget,” which sits awkwardly against the CEO’s statement. The article body attributes the offline-storage claim to Chen and does not independently verify it. Until Bitget publishes a fuller account or on-chain evidence settles it, treat the cold wallet claim as the company’s position.

The same caution applies to the total. The $183 million figure reflects assets tracked moving to the new address in roughly an hour. The figure above $350 million is the amount Decrypt reports as drained, and the article credits Chen’s confirmation of the hack, though the CEO’s quoted statements in the brief do not themselves state a dollar amount.

The protection fund and its limits

Chen’s core claim is that customers will not bear the loss. “User funds are safe. The full amount of this loss falls within the coverage of Bitget’s User Protection Fund, which currently holds over $464 million,” she wrote on X.

The fund has grown. In 2023, Bitget publicized a $300 million protection fund built to cover hacks, theft and similar losses, Decrypt notes. On the numbers given, a loss above $350 million would consume most of a $464 million fund, while a $183 million loss would use well under half. Which figure holds determines how much cushion remains.

A recurring exchange risk

Bitget is one of the larger centralized trading platforms, and it is not alone in being targeted. Decrypt points to Bybit, which lost $1.4 billion in February 2025 after attackers spoofed a signing screen to hijack a routine cold-wallet transfer, the largest crypto theft on record. The Bybit case shows cold storage is not immune when the signing process is compromised, which is one reason the cold wallet claim above deserves scrutiny.

Across the industry last year, hackers stole a combined $2.72 billion from exchanges and protocols, per the same report.

What to Watch

  • The final loss figure. Whether Bitget or on-chain analysts reconcile the $183 million and $350 million-plus numbers.
  • Cold wallet confirmation. Whether evidence supports Chen’s statement that offline reserves were untouched.
  • Withdrawals. Users reported blocked withdrawals; the brief gives no timeline for restoring them.
  • The attacker’s address. Further movement from the “0xe410” address, and whether the ETH is moved or frozen.
  • Fund draw-down. How much of the $464 million User Protection Fund is used to cover losses.

Sources