Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > Bitget Gets Hacked, Reports $351 Million Crypto Loss as Stolen Funds Convert to ETH

Bitget Gets Hacked, Reports $351 Million Crypto Loss as Stolen Funds Convert to ETH

By: Morgan Cipher — Senior Privacy Journalist

Last updated: September 26, 2026

Human Written
Bitget Gets Hacked, Reports $351 Million Crypto Loss as Stolen Funds Convert to ETH
  • Bitget reported unauthorized transfers worth about $351.6 million from parts of its hot and warm wallet infrastructure.

  • A track on the attacker showed they converted much of the stolen EVM-based assets into about 67,982 ETH.

  • Bitget suspended withdrawals during its investigation and says its cold wallets and User Protection Fund remain secure.

Bitget cryptocurrency exchange has revealed unauthorized transactions, nearly $351.6 million, from some of the funds on its wallet platform. According to on-chain data, the unauthorized person has swapped many crypto assets belonging to the EVM platform to Ethereum. 

Lookonchain noted that the unauthorized person swapped approximately 67,982 ETH, equivalent to around $183 million. Currently, Bitget has halted all withdrawals from its portals to streamline the investigation of the situation.

Bitget Detects Unauthorized Wallet Transfers

The security systems of Bitget detected unusual transfers at 18:31 UTC on September 24. The exchange quickly activated its emergency response process after identifying the activity. The company said the incident affected part of its hot and warm wallet layers. Its cold wallets remained secure, according to the initial security notice.

Bitget uses a three-tier wallet structure for asset management. Hot wallets connect to online systems, while warm wallets provide another layer between online operations and cold storage. The firm has not revealed the entire method of the attack.

In any case, Bitget stated that it has excluded the theory about the violation of private keys. The exchange identified and flagged the addresses that took part in the dubious transfers, using its approach. It also reported to law enforcement authorities and several security companies about the situation.

At the same time, Bitget has suspended withdrawals temporarily. Deposits and trading transactions are still available even though the company is busy with security checks. It said that it was planning to share a comprehensive report on the incidents. That report will include the discovery of the cause and the corrective steps it will take after the investigation.

Attacker Converts Stolen Assets into ETH

The movement of the stolen funds has added another layer to the incident. Lookonchain tracked the attacker as the wallet moved assets from several EVM-compatible networks. The attacker swapped a large portion of those assets into ETH. The resulting balance reached about 67,982 ETH, with a reported value near $183 million.

That conversion changes the composition of the stolen funds. Rather than using many different currencies, the criminal chooses to use one dominant crypto coin for a large part of the value. On-chain analysts can see this happening in the public blockchain, since the blockchain reveals wallet transfers. Investigators can therefore monitor the addresses associated with the breach and track subsequent transactions.

Nonetheless, tracking the funds will not lead to identification of the criminal or group. While the blockchain shows the movement of the assets, it does not necessarily give information on the owner of the receiving wallet. The stolen assets reportedly included cryptocurrencies from several networks. XRP formed one of the largest portions of the reported loss, while ETH and stablecoins also featured among the affected assets.

The rapid conversion also creates challenges for investigators. Attackers can move assets between networks and swap tokens through decentralized exchanges. However, each transaction leaves a public record. Security companies can use those records to flag addresses, follow fund movements, and help exchanges or authorities identify suspicious transfers.

Bitget Says User Funds Remain Protected

Bitget has stressed that the incident did not affect its entire wallet system. The company said its cold wallets remain secure and that user funds remain protected. The exchange also pointed to its User Protection Fund. Bitget says the fund currently holds more than $464 million, which exceeds the estimated $351.6 million loss.

That fund could cover the reported loss under the current protection arrangements of Bitget. The company has also said customer account balances remain accurate. Still, the temporary withdrawal suspension affects users who need to move assets away from the exchange. Bitget says it will restore withdrawals after the security review reaches a safe stage.

The company has kept deposits and trading services available. It later issued a separate notice about some Onchain trading services, which it temporarily suspended during the wider security review. Bitget has also said its self-custodial Bitget Wallet operates separately from the affected exchange infrastructure. Reports indicate that the wallet service did not suffer the same incident.

The differences between these cases are important, given that the breach of certain hot wallets does not mean that all assets on a particular exchange are in danger. The losses, however, indicate that the incident is important for the broader crypto industry. Exchanges work with a large number of digital assets within systems and must keep the balance between safety and speed of transactions.

Investigation Continues as Fund Movements Remain Under Watch

Bitget has not yet published its complete technical explanation for the breach. The company has said investigators need more time before they can confirm the exact attack vector. That approach leaves several questions open. Investigators still need to establish how the attacker entered the affected infrastructure and how the system authorized the transfers.

Bitget has ruled out private-key compromise in its preliminary assessment. However, the exchange has not released the complete evidence behind that conclusion. The investigation also involves external security firms and law enforcement agencies.

Law enforcement agencies have also taken part in broader efforts to track and seize assets linked to cybercrime, including the INTERPOL operation seizing $1.7 million in cybercrime assets across the MENA region. Their work can help trace the stolen assets and examine the systems involved.

On-chain monitoring will remain important during that process. Investigators can watch the wallets of the attacker for further swaps, transfers, or attempts to move funds through other networks.

For now, Bitget continues its security review while the cryptocurrency industry tracks the stolen funds. The reported conversion of 67,982 ETH gives investigators a clear pool of assets to monitor.

The incident also highlights the risks surrounding hot and warm wallet infrastructure. Exchanges must protect online systems while allowing users to trade and move assets quickly. Bitget says its emergency response remains active. The company expects to provide further updates as investigators establish the root cause and complete the security assessment.

Share this article

You might also like

Cloudflare Fixes Container Flaw that Exposed Data From Other Customers

Cloudflare Fixes Container Flaw that Exposed Data From Other Customers

A flaw in Cloudflare Containers lets one customer’s container pull up leftover data from someone else’s old workload. Researchers recovered…

September 26, 2026
MacSync Malware Uses iCloud Calendars to Hide Commands on Mac Devices

MacSync Malware Uses iCloud Calendars to Hide Commands on Mac Devices

A newer version of MacSync malware hides attack commands inside public iCloud calendar events. The malware now carries a backdoor…

September 26, 2026
Elliptic Launches AI Tool to Help Police Investigate Crypto Wallets

Elliptic Launches AI Security Tool to Help Global Police Investigate Crypto Crime

Elliptic’s new tool, called Pulse, studies a crypto wallet address or transaction ID and gives officers a plain summary within…

September 26, 2026

About the Author

Morgan Cipher

Morgan Cipher

Senior Privacy Journalist

Morgan combines a journalist’s curiosity with a security specialist’s precision. His reporting on data breaches, privacy laws, and encryption tech has been featured in several tech publications. At TorWire, he focuses on real-world threats and how to counter them, always with an eye on what’s next in digital privacy.

Comments (0)

No comments.