
Bitget Security Incident Explained: Timeline, Impact and Security Response
What Happened in the Bitget Security Incident?
At approximately 18:31 UTC on September 24, 2026, Bitget's security systems detected unauthorized transfers from a portion of its hot and warm wallet infrastructure across multiple chains.
Based on the investigation to date, an attacker compromised a critical backend system within the exchange's wallet infrastructure, used it to spoof transaction data, and triggered the authorization process for unauthorized transfers.
Bitget's security team subsequently identified the attack path and methods used to bypass existing security controls. The underlying vulnerability has been identified and remediated.
The incident has been contained, and no further unauthorized transfers have been identified following containment. Mandiant and SlowMist continue to support the investigation, including forensic review and fund tracing.
👉Read the official security incident announcement.
This article reflects information verified as of the latest update and will be revised if material new findings are confirmed.
Bitget Security Incident Timeline
The timeline below reflects confirmed developments as information became available.
| Date and Time |
Confirmed Development |
| September 24, 18:31 UTC |
Bitget detects unauthorized transfers involving a portion of its hot and warm wallet infrastructure and activates its security response. |
| September 24 |
Withdrawals are temporarily paused while security and technical teams conduct containment and additional validation. Trading and deposits continue. |
| Initial assessment |
The affected amount is initially estimated at approximately $351.6 million. |
| September 25 |
The attack path and methods are identified and the underlying vulnerability is remediated. |
| September 25 |
Further transaction classification revises the estimated affected amount to approximately $387.5 million, including additional affected Zcash and TRON transactions. |
| September 25 |
Mandiant and SlowMist support the investigation and recovery efforts. A Recovery Bounty Program is launched. |
| September 26 |
Bitget announces a phased withdrawal restoration schedule. |
| September 28 onward |
Withdrawals are scheduled to resume progressively across BTC, ETH, USDT, other supported assets, fiat and P2P services. |
The investigation, tracing and recovery process remains ongoing. Material updates will continue to be published through Bitget's official channels.
How Much Was Affected?
The amount affected is currently estimated at approximately $387.5 million, revised from the initial estimate of $351.6 million.
The revised figure reflects a more complete accounting of transfers that occurred during the incident. It includes affected transactions involving Zcash and TRON that were not captured in the initial estimate.
The revision does not represent additional unauthorized transfers after containment or a separate security incident.
Because transaction classification and tracing remain ongoing, the estimate may be updated if additional relevant transactions are identified.
Which Assets and Networks Were Affected?
Unauthorized transfers occurred across Ethereum and several EVM networks, XRP Ledger, Zcash and TRON.
Confirmed affected assets include:
-
ETH
-
XRP
-
BNB
-
ZEC
-
USDO
-
XAUT
-
AVAX
-
TRX
-
USDT
-
USDC
The incident was limited to a portion of the exchange's hot and warm wallet infrastructure.
Bitget operates a three-tier wallet architecture comprising hot, warm and cold wallets. Cold wallets across all chains were not affected.
Based on the investigation to date, private-key compromise has also been ruled out. The incident involved the compromise of a critical backend system within the wallet infrastructure.
Was Bitget Wallet Affected?
No. Bitget Wallet was not affected by the incident. It is a separate, non-custodial product and operates on infrastructure separate from the exchange wallet systems involved in the security incident.
Bitget Wallet users' assets remain onchain under users' control.
How Did Bitget Contain and Respond to the Incident?
The immediate response focused on containing unauthorized activity, securing affected infrastructure and validating systems before withdrawal services were restored.
Following containment:
-
no further unauthorized transfers have been identified;
-
the attack path and methods used in the incident have been identified;
-
the underlying vulnerability has been remediated;
-
additional security validation has been conducted across the withdrawal infrastructure;
-
Mandiant and SlowMist have been engaged to support the investigation;
-
relevant law enforcement agencies and financial intelligence units have been notified;
-
fund tracing and recovery efforts have been initiated with industry partners.
Security validation and forensic work remain ongoing as part of the broader investigation and recovery process.
Are User Account Balances Affected?
User account balances remain unaffected.
The temporary withdrawal pause was implemented as a security measure and is not related to the availability of user assets. It allowed security and technical teams to carry out additional validation and security checks across the withdrawal infrastructure before services resumed.
Trading and deposits have continued to operate during the withdrawal restoration process.
Bitget's Protection Fund covers the financial impact of this platform-wide incident.
This should not be interpreted as a separate individual compensation or reimbursement program. No such program has been announced, and user account balances remain unaffected.
How Does the Bitget Protection Fund Apply to the Incident?
The Protection Fund serves as an additional financial protection mechanism for eligible platform-wide security incidents.
For the September 24 security incident, the financial impact falls within the coverage of the Protection Fund.
The Protection Fund is separate from Proof of Reserves. Proof of Reserves provides transparency into assets held by the platform relative to user balances, while the Protection Fund is designed as an additional layer of financial protection.
Updated reserve information will be published as further post-incident verification is completed.
Why Were Withdrawals Temporarily Paused?
Withdrawals were temporarily paused to allow Bitget's security and technical teams to conduct additional validation and security checks across the withdrawal infrastructure.
The pause was a precautionary security measure rather than an indication of insufficient user assets.
Trading and deposits continued to operate while these checks were carried out.
When Will Bitget Withdrawals Resume?
Withdrawals are being restored in phases once the required security checks for the relevant assets and networks are completed.
The current schedule is:
| Date and Time (UTC) |
Asset / Service |
Network(s) |
| September 28, 08:00 |
BTC |
Bitcoin |
| September 29, 08:00 |
ETH |
Ethereum, BSC, Arbitrum, Base, Optimism |
| September 30, 08:00 |
USDT |
Ethereum, BSC, Solana, Tron |
| October 2, 08:00 |
Other tokens / Fiat / P2P |
Applicable supported networks |
The phased approach allows services to be restored in an orderly manner while security validation continues across supported assets and networks.
Users do not need to take action before the rollout. Withdrawal availability will be reflected directly on the Bitget platform as each phase becomes available.
👉 Read the official withdrawal resumption announcement.
What Are Mandiant and SlowMist Investigating?
Bitget has engaged Mandiant, a Google Cloud company, and SlowMist to support an independent forensic investigation.
The investigation includes:
-
assessing the scope of affected systems and assets;
-
reviewing the attack path and methods;
-
validating containment and remediation measures;
-
supporting ongoing tracing efforts;
-
cooperating with relevant authorities.
The investigation remains ongoing. Findings that have not been formally verified should not be treated as confirmed conclusions.
This also applies to public speculation regarding attacker attribution. Any final attribution should be based on verified investigative findings.
How Is Bitget Tracing and Recovering the Affected Assets?
Bitget is working with law enforcement, onchain security specialists, exchanges, blockchain projects and other ecosystem participants to trace and recover affected assets.
Some affected assets have already been successfully frozen through coordination with industry partners.
Bitget has also launched a Recovery Bounty Program. Eligible voluntary actions that directly result in affected funds being successfully frozen or recovered may qualify for a bounty calculated at 5% of the funds successfully frozen or recovered, subject to the program's terms and eligibility requirements.
👉Learn more about the Recovery Bounty Program.
Actions carried out pursuant to law enforcement or legal procedures are excluded from the bounty program.
Bitget is also using Bybit's LazarusBounty initiative as a recovery channel and has made live tracing information available to support industry coordination.
Because recovery efforts remain ongoing, frozen, recovered and outstanding amounts should only be reported once they have been verified.
What Happens Next?
The incident has moved beyond immediate containment into the next stages of security validation, withdrawal restoration, forensic investigation and asset recovery.
The current priorities are:
-
restoring withdrawals across supported assets and networks in an orderly manner;
-
completing additional security validation;
-
continuing the independent forensic investigation with Mandiant and SlowMist;
-
tracing and recovering affected assets;
-
cooperating with relevant authorities and industry participants;
-
reviewing security controls based on verified investigation findings.
The incident remains contained. The underlying vulnerability has been remediated. Cold wallets were not affected, and private-key compromise has been ruled out based on the investigation to date. User account balances remain unaffected.
Further information will be published as it is verified.
Frequently Asked Questions
1. What exactly happened in the Bitget security incident?
On September 24, 2026, Bitget detected unauthorized transfers from a portion of its hot and warm wallet infrastructure. Based on the investigation to date, a critical backend system within the wallet infrastructure was compromised and used to trigger unauthorized transfers. The incident has been contained and the identified vulnerability remediated.
2. How much was affected?
The amount is currently estimated at approximately $387.5 million. The figure was revised from the initial $351.6 million estimate after further transaction classification identified additional affected Zcash and TRON transactions.
3. Did the revision from $351.6 million to $387.5 million mean more funds were transferred later?
No. The revised estimate reflects a more complete accounting of transfers that occurred during the original incident. No further unauthorized transfers have been identified following containment.
4. Were Bitget cold wallets affected?
No. The incident was limited to a portion of the hot and warm wallet infrastructure. Cold wallets across all chains were not affected.
5. Were private keys compromised?
Based on the investigation to date, private-key compromise has been ruled out. The incident involved the compromise of a critical backend system within Bitget's wallet infrastructure.
6. Are user account balances affected?
No. User account balances remain unaffected. The temporary withdrawal pause was implemented as a security measure and was not related to the availability of user assets.
7. Has the vulnerability been fixed?
The underlying vulnerability identified during the investigation has been remediated. Additional security validation and forensic investigation remain ongoing.
8. Is Bitget Wallet affected?
No. Bitget Wallet operates separately from the exchange wallet infrastructure involved in the incident and was not affected.
9. When will withdrawals resume?
Under the current schedule, withdrawals are set to resume in phases beginning with BTC on September 28 at 08:00 UTC, followed by ETH on September 29, USDT on September 30, and other supported tokens, fiat and P2P services on October 2.
10. Is the investigation complete?
No. The incident has been contained and the identified vulnerability remediated, but forensic investigation, fund tracing and recovery efforts remain ongoing with support from Mandiant and SlowMist.
Security Reminder
For the latest information on the security incident and withdrawal status, refer only to Bitget’s official website, app, Support Center, and verified social channels.
Bitget will never ask for your private keys, seed phrases, passwords, or verification codes, or ask you to send funds to an external address. Be cautious of phishing links, impersonation accounts, and unofficial recovery services.
- What Happened in the Bitget Security Incident?
- Bitget Security Incident Timeline
- How Much Was Affected?
- Which Assets and Networks Were Affected?
- Was Bitget Wallet Affected?
- How Did Bitget Contain and Respond to the Incident?
- Are User Account Balances Affected?
- How Does the Bitget Protection Fund Apply to the Incident?
- Why Were Withdrawals Temporarily Paused?
- When Will Bitget Withdrawals Resume?
- What Are Mandiant and SlowMist Investigating?
- How Is Bitget Tracing and Recovering the Affected Assets?
- What Happens Next?
- Frequently Asked Questions


