The Largest Exchange Breach of 2026
On September 24, 2026, Bitget — one of the ten largest cryptocurrency exchanges in the world by trading volume — disclosed a major security incident. Unauthorized transfers drained approximately $351.6 million from the exchange’s hot and warm wallets, making it the single largest crypto exchange hack of the year.
The exchange’s systems flagged the first suspicious activity at 18:31 UTC, when several hot wallets began sending funds to unknown addresses. Independent blockchain analysts were among the first to notice the unusual movements, initially reporting around $183 million in outflows. The exchange later confirmed the final figure: $351.6 million.
How It Happened
Bitget CEO Gracy Chen clarified that the attack did not involve the theft of private keys — the conventional method used in most crypto wallet breaches. Instead, the attackers took a more sophisticated route: they compromised the exchange’s internal wallet management backend, forged transaction data, and manipulated Bitget’s own authorization process into approving the withdrawals.
The exchange operates a three-tier asset storage architecture. The breach affected only a portion of the hot and warm wallet layers, while the cold wallets — kept entirely offline — remained untouched. Deposits and trading continued to function normally throughout the incident; withdrawals were temporarily suspended pending a security review. By September 28, Bitget had reopened Bitcoin withdrawals as the first phase of its recovery process.
The User Protection Fund Covered the Loss
Bitget’s primary response to concerned users centered on its User Protection Fund. At the time of the incident, the fund held more than $464 million — enough to cover the full estimated loss. Chen stated that customer account balances were unaffected and that the fund would make users whole.
The exchange’s native token BGB dropped sharply when news of the hack first circulated, though it partially recovered by the end of the day.
The North Korea Connection
Blockchain analytics firm Elliptic linked the destination addresses of the stolen funds to laundering patterns associated with hacking groups affiliated with North Korea. According to their analysis, the Bitget incident pushed the regime’s total tracked crypto theft in 2026 past the $1 billion mark — across more than fifty documented attacks.
The timing adds further weight to the finding: the Bitget breach came just weeks after the Liquid Network incident on September 7, in which roughly $320 million was drained from a Bitcoin sidechain used by several exchanges to move funds. Together, the two September hacks inflicted nearly $684 million in losses on the crypto industry, making September the second-costliest month of the year for security incidents.
Context: The Threat Vector Is Shifting
Both September breaches share a notable technical characteristic: in neither case did the attackers steal private keys directly. Instead, the attacks targeted the software infrastructure surrounding those keys — authorization systems, wallet backends, and transaction signing processes. Security experts note this has become one of the defining patterns of 2026: the weakest point in crypto custody is no longer the key itself, but the software layer built around it.
Bitget serves more than 125 million users worldwide and ranks among the top ten crypto exchanges by trading volume. The company is registered in the Seychelles and employs approximately 1,900 people.