Bitget has confirmed that unauthorized transfers from a limited number of its hot wallets affected approximately $351.6 million in assets on September 24, 2026. The disclosure follows an independent on-chain investigation that tracked more than $134 million through a single collection address in under two hours.
The cryptocurrency exchange said its security systems identified the activity at 18:31 UTC. It immediately activated its emergency response procedures and began a full investigation.
Bitget did not disclose how the wallets were compromised. The exchange said it would avoid speculation while the investigation remains active and would provide further updates through its official channels.
The incident is still developing, but the available evidence establishes a clear sequence: unusual cross-chain movements were detected by independent researchers, funds began moving from Bitget-labelled wallets into a common address, the assets were converted and redistributed, and Bitget later confirmed unauthorized transfers affecting $351.6 million.
Bitget confirms the incident
In its official notice, Bitget said approximately $351.6 million in assets were affected. The statement referred to unauthorized transfers involving a limited number of hot wallets.
The exchange added several important qualifications:
- Bitget’s cold wallets and the overwhelming majority of platform assets remain secure and unaffected.
- Customer account balances remain accurate.
- Deposits and trading continue to operate normally.
- Withdrawals have been temporarily suspended as a precaution.
- Bitget has identified and flagged the relevant transfer addresses.
- The exchange has engaged law enforcement and leading on-chain security partners.
- The User Protection Fund currently holds more than $464 million.
- The incident falls within the fund’s stated coverage.
Bitget also said it is working to restore withdrawals as soon as it is safe to do so.
The distinction between the official estimate and the earlier on-chain figures matters. Independent trackers initially reported suspicious movements valued at roughly $174 million, then increased that estimate to about $183 million. Bitget’s later figure of $351.6 million covers a broader set of affected assets and chains.
Official statement:
https://x.com/bitget/status/2103236552482848927
CEO Gracy Chen’s notice:
https://x.com/GracyBitget/status/2103235655879074084
The first sign of trouble
The first widely reported warning came from on-chain observers who noticed large transfers from several Bitget-labelled wallets into a shared destination. The activity involved ETH, USDT, USDC, XAUT, AVAX, BNB and other assets across multiple networks.
The most visible collection address on Ethereum was:
0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee
Open the address on Etherscan:
https://etherscan.io/address/0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee
The same address was active on Avalanche’s C-Chain:
https://avascan.info/blockchain/x/address/0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee
Before Bitget issued its confirmation, independent researchers could verify only part of the overall movement. Their snapshot showed incoming transfers of:
- 24,373.375940615 ETH
- 34,751,168.120990 USDT
- 12,852,046.242513 USDC
- 3,000.322053 XAUT
- 821,011.971142467 AVAX
Using prices observed during the investigation, that verified subset represented approximately $134.44 million.
This was not a final loss estimate. It covered only the transfers traced to the identified collection address and excluded assets that may have moved through other wallets, networks, swaps or addresses not included in the initial snapshot.
On-chain timeline
18:31:11 UTC – the first funding
The first recorded ETH transfer into the collection address was 0.84 ETH at 18:31:11 UTC.
This timestamp closely matches the time Bitget says its systems detected the unauthorized activity. The first small transfer was followed roughly 28 minutes later by a much larger stablecoin movement.
18:58:59 UTC – 34.75 million USDT moves
At 18:58:59 UTC, the collection address received approximately 34,751,168.12 USDT from a wallet publicly labelled as Bitget 6:
0x1AB4973a48dc892Cd9971ECE8e01DcC7688f8F23
Etherscan:
https://etherscan.io/address/0x1AB4973a48dc892Cd9971ECE8e01DcC7688f8F23
The movement was part of a broader sequence in which several exchange-labelled wallets sent different assets to the same collection address within a short window.
19:01:23 UTC – USDC and tokenized gold arrive
At 19:01:23 UTC, the collection address received approximately:
- 12,852,046.24 USDC
- 3,000.32 XAUT
The XAUT transfer came from a second wallet labelled as Bitget 5:
0x5bdf85216ec1e38D6458C870992A69e38e03F7Ef
Etherscan:
https://etherscan.io/address/0x5bdf85216ec1e38D6458C870992A69e38e03F7Ef
Other Bitget-labelled source addresses identified during the investigation included:
0xffa8DB7B38579e6A2D14f9B347a9acE4d044cD54
https://etherscan.io/address/0xffa8DB7B38579e6A2D14f9B347a9acE4d044cD54
0x97b9D2102A9a65A26E1EE82D59e42d1B73B68689
https://etherscan.io/address/0x97b9D2102A9a65A26E1EE82D59e42d1B73B68689
Wallet labels are attribution evidence, but they cannot prove who signed or authorised any individual transaction. Bitget has now confirmed unauthorized transfers, which is stronger evidence than the labels alone.
19:05:11 UTC – assets move to a second wallet
At 19:05:11 UTC, the collection address sent 0.1 ETH to a second wallet:
0x7c96279Ec1e888Aa56b9B836e0dB26ca48573E1C
Etherscan:
https://etherscan.io/address/0x7c96279Ec1e888Aa56b9B836e0dB26ca48573E1C
Practically all of the collected USDT, USDC and XAUT followed that initial transfer. The second wallet then began converting the assets into ETH.
One transaction produced approximately 1,855.7977 ETH:
https://etherscan.io/tx/0x69803df4d600f43afe3ac31d1360b806337ca7542182ea3655cf99429f4eb4e1
The evidence for the conversion came from token outflows and native ETH receipts sharing the same transaction hash.
19:30:35 UTC – 22,320 ETH moves downstream
At 19:30:35 UTC, the swap wallet forwarded 22,320 ETH to:
0xA6dD3F218B65E32Ccc37BE30f74884133c655545
Etherscan address:
https://etherscan.io/address/0xA6dD3F218B65E32Ccc37BE30f74884133c655545
Transaction:
https://etherscan.io/tx/0xbf42355f96117fea4f6f8f2be7ab1a7e06cfb75cec1aeb1203894e93b7bdd36a
20:09 UTC – more ETH arrives from Bitget-labelled wallets
The transfers from Bitget-labelled source wallets continued after the first conversions had begun.
At approximately 20:09 UTC, another 1,879.2 ETH and 1,395.9 ETH arrived at the collection address. These inflows increased the total volume entering the shared wallet but were not separate additional losses after they were later sent downstream.
20:13:11 and 20:19:11 UTC – 20,000 ETH is distributed
The collection address then distributed 20,000 ETH through two transfers:
- 10,000 ETH at approximately 20:13:11 UTC to
0xD2C2f029eFF5caCc686F24377CfdDcfc82d9F899 - 10,000 ETH at approximately 20:19:11 UTC to
0x600C1f58Eb84cF1d6Dff375E847dBb19f05B84b2
Downstream address 1:
https://etherscan.io/address/0xD2C2f029eFF5caCc686F24377CfdDcfc82d9F899
Downstream address 2:
https://etherscan.io/address/0x600C1f58Eb84cF1d6Dff375E847dBb19f05B84b2
These transactions moved assets that had already been counted when they entered the collection address. Adding the 20,000 ETH to the incoming total would inflate the loss estimate.
At the independent research snapshot, the collection address still held approximately 4,373 ETH on Ethereum and 821,011 AVAX on Avalanche. Balances continued to change as the investigation and asset movements progressed.
Why the transaction pattern mattered
Rapid wallet sweeps are not, by themselves, proof of a hack. Exchanges routinely move funds between cold wallets, hot wallets, market-making accounts, custody providers and internal settlement systems.
The unusual part was the combination of several signals:
- Multiple Bitget-labelled wallets sent different assets to one previously active collection address.
- Stablecoins and tokenized gold were rapidly converted into ETH.
- Large amounts of ETH were forwarded to downstream addresses within minutes.
- More ETH arrived from Bitget-labelled wallets after the first conversions had started.
- Users reportedly encountered withdrawal problems.
- Bitget’s public API showed Ethereum withdrawals unavailable during the incident.
- The exchange later confirmed unauthorized transfers and suspended withdrawals.
Those facts are consistent with a wallet compromise or unauthorized custody operation. They do not reveal the technical attack vector.
The fake-token problem
The address history also contained deliberate contamination. Fake contracts using names such as USDT, USDC and ETH imitated legitimate transfers and sometimes copied the amounts involved.
One fake USDT contract, for example, reproduced the reported 34.75 million USDT movement:
0x34786b43b696f34de244fb76730c79b876eb9177
That contract is not the genuine USDT contract. Researchers excluded these fake entries from the totals.
The presence of copied tokens and tiny transfers designed to resemble legitimate counterparties is a warning for anyone constructing a wallet-loss dashboard from raw transaction feeds. The token contract, network, transaction direction, wallet label and balance impact all need to be checked before an asset is counted.
What remains unknown
Bitget has not disclosed how the unauthorized transfers were authorised or executed. The possible explanations range from a compromised hot-wallet key to an internal authorization failure, an operational mistake or another security issue. The current evidence does not allow those possibilities to be separated responsibly.
The exchange also has not yet provided a final recovery figure. The $351.6 million number describes assets affected, not necessarily assets permanently lost or unrecoverable.
The User Protection Fund holding more than $464 million gives Bitget room to absorb the stated exposure, but the fund’s size alone does not prove that every user withdrawal will be immediate. Bitget’s temporary suspension shows that operational controls remain active while the review is underway.
Users should watch for a formal post-incident report. The most important disclosures would include:
- the attack vector
- whether private keys or signing systems were compromised
- which chains and wallets were involved
- whether stolen assets can be frozen or recovered
- the expected timeline for restoring withdrawals
- whether customer balances were reconciled against exchange reserves
A larger figure than first reported
The official confirmation changes the scale of the incident. The initial independent analysis identified approximately $134.44 million flowing into one address. Bitget now says that $351.6 million in assets were affected across the broader incident.
The two numbers are not necessarily contradictory. The first was a verified subset based on one collection address and a fixed snapshot. The second is the exchange’s estimate of the full affected asset set.
What is now established is more serious than the initial reports suggested. This was not merely a suspicious wallet transfer that might have been authorised exchange activity. Bitget has confirmed that unauthorized transfers occurred.
What remains unproven is the final loss, the attack method and the amount that can be recovered. Until those questions are answered, $351.6 million is best described as the value of assets affected, not a definitive stolen amount.
Sources and further reading
Bitget’s official confirmation:
https://x.com/bitget/status/2103236552482848927
Bitget CEO Gracy Chen:
https://x.com/GracyBitget/status/2103235655879074084
Independent on-chain investigation:
https://x.com/MastrXYZ/status/2103228316127813903
Bubblemaps alert:
https://x.com/bubblemaps/status/2103229553850380794
Crypto Briefing confirmation report:
Bitget confirms over $350M breach and temporarily pauses withdrawals
BeInCrypto’s early on-chain report:
https://beincrypto.com/bitget-hack-176-million-wallet-movements
Wu Blockchain’s early wallet report:
https://www.wublock123.com/news/bitget-suspected-of-being-involved-in-a-wallet-security-incident-with-over-170-million-in-assets-being-transferred-out-68967
Bitget’s public coin-status API:
https://api.bitget.com/api/v2/spot/public/coins
Risk notice
This report is based on Bitget’s official statement and publicly available blockchain records. Wallet labels can be inaccurate, and on-chain attribution does not necessarily establish who controlled a private key. This article is informational only and is not financial advice.
Author: Pulse of Nations Crypto Desk
