Bitget: Bitget Hit by $350 Million Exploit: Largest Crypto Hack of 2026

Bitget: Bitget Hit by $350 Million Exploit: Largest Crypto Hack of 2026

Bitget Hit by $351.6M Hot Wallet Hack, Withdrawals Frozen as Investigation Underway

Bitget, a major cryptocurrency exchange, has suffered a $351.6 million hot wallet breach, marking the largest crypto hack of 2026 so far. The attack was first detected by Arkham Intelligence, which observed massive withdrawals of AVAX, BNB, ETH, and stablecoins, later swapped to ETH by the attacker.

Bitget CEO Gracy Chen confirmed that the breach was contained to a single hot wallet, with cold wallet funds remaining secure. The attacker exploited a back-end system vulnerability, spoofed transaction history, and triggered unauthorized withdrawals all without accessing private keys. In response, Bitget has temporarily suspended withdrawals while conducting a security review, though deposits and trading remain operational.

The exchange is collaborating with law enforcement and on-chain security firms to trace and recover the stolen funds. A full incident report is expected within 24 hours, detailing the attack vector and remediation steps. To reassure users, Bitget has pledged full reimbursement via its $464 million User Protection Fund, which exceeds the stolen amount.

This breach surpasses other major 2026 crypto hacks, including the $320 million Liquid Network exploit and $292 million KeloDAO attack. While the first half of the year saw a record number of crypto security incidents, losses had been relatively lower until now. Cybersecurity firm CertiK notes a shift in attack methods, with hackers increasingly targeting infrastructure, hot wallets, and private key compromises rather than smart contract vulnerabilities.

Bitget’s commitment to full reimbursement contrasts with past DeFi hacks, where recovery was often uncertain. The exchange has also implemented additional security measures to prevent further theft.

Source: https://coinpedia.org/news/bitget-hit-by-350-million-exploit-largest-crypto-hack-of-2026/

Bitget TPRM report: https://www.rankiteo.com/company/bitget-global

"id": "bit1790303165",
"linkid": "bitget-global",
"type": "Breach",
"date": "9/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'FinTech, Cryptocurrency',
                        'name': 'Bitget',
                        'size': 'Major',
                        'type': 'Cryptocurrency Exchange'}],
 'attack_vector': 'Back-end system vulnerability, transaction spoofing',
 'customer_advisories': 'Withdrawals suspended, deposits and trading remain '
                        'operational; full reimbursement pledged',
 'data_breach': {'data_exfiltration': 'Cryptocurrency withdrawals (AVAX, BNB, '
                                      'ETH, stablecoins)'},
 'description': 'Bitget, a major cryptocurrency exchange, suffered a $351.6 '
                'million hot wallet breach, marking the largest crypto hack of '
                '2026 so far. The attack was detected by Arkham Intelligence, '
                'which observed massive withdrawals of AVAX, BNB, ETH, and '
                'stablecoins, later swapped to ETH by the attacker. The breach '
                'was contained to a single hot wallet, with cold wallet funds '
                'remaining secure. The attacker exploited a back-end system '
                'vulnerability, spoofed transaction history, and triggered '
                'unauthorized withdrawals without accessing private keys.',
 'impact': {'brand_reputation_impact': 'Potential reputational damage',
            'downtime': 'Withdrawals temporarily suspended',
            'financial_loss': '$351.6 million',
            'operational_impact': 'Withdrawals frozen, deposits and trading '
                                  'remain operational',
            'systems_affected': 'Hot wallet'},
 'investigation_status': 'Underway',
 'motivation': 'Financial gain',
 'post_incident_analysis': {'corrective_actions': 'Additional security '
                                                  'measures, full incident '
                                                  'report',
                            'root_causes': 'Back-end system vulnerability, '
                                           'transaction spoofing'},
 'references': [{'source': 'Arkham Intelligence'}, {'source': 'CertiK'}],
 'response': {'communication_strategy': 'Public disclosure, incident report '
                                        'expected within 24 hours',
              'containment_measures': 'Hot wallet breach contained, '
                                      'withdrawals suspended',
              'incident_response_plan_activated': 'Yes',
              'law_enforcement_notified': 'Yes',
              'recovery_measures': 'Full reimbursement via User Protection '
                                   'Fund',
              'remediation_measures': 'Security review, additional security '
                                      'measures',
              'third_party_assistance': 'Law enforcement, on-chain security '
                                        'firms'},
 'title': 'Bitget Hot Wallet Hack',
 'type': 'Hot Wallet Breach',
 'vulnerability_exploited': 'Back-end system vulnerability'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.