Bitget has confirmed about $351.6 million in unauthorised transfers out of its hot and warm wallet infrastructure on Sept. 24, in what may be the largest breach of a centralised exchange so far in 2026. The platform’s systems flagged the transfers at 18:31 UTC and withdrawals for all users were suspended as a precaution, while deposits and trading stayed open.
According to the security team’s preliminary finding, relayed by chief executive Gracy Chen, attackers compromised “a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out”. Chen ruled out a private-key compromise — the vector behind some of the industry’s biggest losses — and said “loss containment is confirmed”: no further unauthorised transfers are possible. The offline cold wallets “remain fully secure”.
On-chain tracker Lookonchain counts at least nine tokens in the haul. The largest single line is about 102.9 million XRP, worth roughly $157.5 million, followed by 31,890 ether (about $85.8 million). The rest is mostly stablecoins — about $34.8 million of USDT, $21.1 million of USDC and $19.7 million of USDT0 — plus smaller amounts of Tether Gold, BNB, AVAX and TRX, for a total near $357 million. Much of the stablecoin balance was quickly swapped into ether, which no central issuer can freeze: on Arbitrum a freshly created address spent about $19.67 million of USDT0 to buy about 7,111 ETH through UniswapX and 1inch Fusion. Early on-chain counts of $174 million to $183 million covered roughly half the haul because they missed the XRP-ledger legs.


