Key takeaways
- Bitget detected unauthorised transfers at 18:31 UTC on 24 September, draining roughly $351.6 million from a limited number of hot and warm wallets, and suspended withdrawals.
- The company states cold wallets and most platform assets are unaffected and that user funds are safe. That is a solvency claim, not a guarantee of immediate access.
- CEO Gracy Chen said a preliminary investigation found IP addresses matching VPN patterns associated with a DPRK-linked hacking group.
- The incident pushes September's crypto losses to their highest level of 2026. Separately, the Federal Reserve has proposed capital requirements, a two-day redemption window and new reserve disclosures for stablecoin issuers under the GENIUS Act.
At 18:31 UTC on 24 September, Bitget detected unauthorised transfers leaving its wallets. By the time the movement stopped, roughly $351.6 million had gone. The exchange activated its emergency procedures within minutes and suspended withdrawals.
The company's position is that the breach affected a limited number of hot and warm wallets, that cold wallets and most platform assets are unaffected, and that user funds are safe.
That last phrase is doing a great deal of work, and it is worth taking apart carefully — not because there is reason to doubt it, but because most people read it as meaning something it does not mean.
Hot, warm and cold
Start with why only some wallets were drained.
A hot wallet is connected to the internet. It has to be, because it is what pays out withdrawals automatically, around the clock, without a human approving each one. That connectivity is exactly what makes it reachable by an attacker.
A cold wallet is not connected. Keys are held offline, often in hardware in a vault, and moving funds out requires physical access and multiple human signatures. It is slow and inconvenient, which is the point.
A warm wallet sits between the two — partially automated, with some human control.
Every exchange runs this tiered structure, and the balance between tiers is a business decision. Keep too little in hot wallets and withdrawals queue up, customers complain, and the exchange looks unreliable. Keep too much and a single compromise costs you what this one cost Bitget. There is no configuration that removes the trade-off. There is only where you set the dial.
What "user funds are safe" is actually claiming
It is a statement about solvency, not about access.
The claim is that the exchange holds enough assets, mostly in cold storage, to cover what it owes its customers even after losing $351.6 million. Given the size of a major exchange's reserves, that is entirely plausible.
What it does not claim is that you can withdraw right now. You cannot — withdrawals are suspended. Those are different things, and the gap between them is where people get hurt. A solvent exchange with suspended withdrawals is still an exchange you cannot get your money out of today.
It also does not promise how long the suspension lasts. Suspensions during an active incident are a sensible precaution: until the attack vector is understood and closed, resuming withdrawals risks handing the attacker a second helping. But "sensible" and "short" are not the same word.
On the North Korea attribution
CEO Gracy Chen said a preliminary investigation found IP addresses matching VPN choices associated with a DPRK-linked hacking group.
Treat that with the caution the word "preliminary" invites. IP and VPN fingerprinting is genuinely useful as an early indicator, and North Korean state-linked groups have been responsible for a very large share of exchange thefts in recent years, so the prior is not unreasonable. But attribution based on infrastructure patterns is also the easiest kind to get wrong, and sophisticated attackers know which fingerprints imply which attribution.
The more useful point is what it implies about the adversary. If state-linked groups are the ones taking exchange funds at this scale, the security problem is not sloppy operators being caught out by opportunists. It is well-resourced, persistent teams working full-time against systems that must stay online to function. That is a materially harder problem, and it is why these incidents keep recurring at well-run venues.
What to do if you hold a balance there
Practical, in order.
Do not panic-trade. Trading generally still functions while withdrawals are suspended, and moving into or out of positions on an exchange in the middle of an incident adds a decision you do not need to make under pressure.
Beware the second wave. Every major incident is followed within hours by fake support accounts, fraudulent "recovery" portals and phishing emails referencing the specific event. They will be well-made and they will reference real details. No exchange will ever ask for your seed phrase or private key to restore access. No legitimate recovery process requires it, ever.
Record your balances now. Screenshot your holdings and export your transaction history while the interface is still available. If there is any subsequent process, contemporaneous records are worth having and are far easier to capture today than later.
Then wait. Uncomfortable, and correct. There is no action available to you that improves your position, and most actions available make it worse.
The lesson that keeps not being learned
A balance on an exchange is a claim against that exchange. It is not an asset you control. That sentence has been true through every one of these events, and it stays true no matter how large or reputable the venue is.
None of which means never using exchanges. You need one to buy, sell and trade, and self-custody carries its own risks — lost keys have destroyed more holdings than hacks have. The workable rule is simply to hold on an exchange what you are actively using, and keep the rest where you control the keys. It is unglamorous, it costs you a small amount of convenience, and it has never once looked like the wrong decision afterwards.
This incident pushes September's crypto losses to their highest level of 2026, which is the context worth holding onto. This is not an isolated event. It is the latest instance of a recurring pattern.
Meanwhile, the Fed moved on stablecoins
Largely buried by the hack, the Federal Reserve advanced proposals implementing the GENIUS Act for stablecoin issuers. The proposal would set capital requirements, establish a two-day redemption window, and impose new reserve disclosure obligations.
The two-day redemption window is the provision to watch. It would require issuers to honour redemptions within a defined period — turning what is currently a commercial promise into a regulatory obligation. For anyone holding stablecoins, that is a more meaningful protection than any attestation report, because it is enforceable.
Capital requirements do something similar from the other direction: they mean an issuer must hold a buffer of its own money against the reserves backing its tokens, so a shortfall does not immediately become the holder's problem. These are unglamorous, bank-style rules, and their arrival is the clearest sign yet that US regulators intend to treat large stablecoin issuers as financial infrastructure rather than as software companies.
And New York went after Polymarket
One more, worth noting for anyone using prediction markets. New York State has sued Polymarket, alleging it operates an illegal gambling business, and is seeking to block it from operating without a gambling licence as well as to recover allegedly illegal gains.
This is a state-level action about licensing rather than a federal judgement on whether prediction markets are legitimate. But it is a reminder that the regulatory position of these platforms is unsettled in the US, and that unsettled regulatory positions have a way of becoming sudden access restrictions for users in particular states.
The short version
An exchange lost $351.6 million and paused withdrawals. It says user funds are safe, and that is probably true as a statement about solvency while telling you nothing about when you can withdraw. The attacker may be state-linked, which makes this a structural problem rather than a one-off failure.
Bitcoin is around $84,600 and barely moved on the news, which tells you the market has priced exchange incidents as routine. That is either maturity or complacency, and reasonable people disagree about which.
Frequently asked questions
If Bitget says user funds are safe, why can't I withdraw?
Because those are different claims. "Funds are safe" is a statement about solvency — that the exchange holds enough assets, mostly in cold storage, to cover what it owes customers despite the loss. Withdrawals are suspended as a security precaution while the attack vector is investigated and closed, since resuming too early risks a second theft. A solvent exchange with paused withdrawals is still one you cannot withdraw from today.
What is the difference between a hot wallet and a cold wallet?
A hot wallet is connected to the internet so it can process withdrawals automatically around the clock, which is precisely what makes it reachable by attackers. A cold wallet keeps keys offline, often in hardware in a vault, requiring physical access and multiple human signatures to move funds. Every exchange balances the two: too little in hot wallets means slow withdrawals, too much means a single breach is catastrophic.
Should I move everything off exchanges after this?
Not necessarily, and the honest trade-off cuts both ways. Self-custody removes exchange risk but introduces key-management risk, and lost keys have destroyed more holdings historically than hacks have. The workable approach for most people is to keep on an exchange only what you are actively trading, and hold the rest where you control the keys.
How reliable is the North Korea attribution?
It is preliminary, based on IP addresses matching VPN patterns associated with a DPRK-linked group. That is a legitimate early indicator and the prior is reasonable given how much exchange theft has been attributed to state-linked groups recently. But infrastructure-based attribution is also among the easiest to get wrong, and capable attackers know which fingerprints point where. Treat it as a working hypothesis.
What does the Fed's stablecoin proposal change?
It would implement the GENIUS Act by setting capital requirements for issuers, establishing a two-day redemption window, and requiring new reserve disclosures. The redemption window is the most consequential for holders, since it converts a commercial promise to honour redemptions into an enforceable regulatory obligation. Capital requirements mean issuers hold their own buffer against the reserves backing tokens.
Sources
- Bitget confirms $352M security breach, suspends withdrawals
- Bitget's $351.6 million hack pushes September crypto losses to 2026 high
- Bitget CEO suspects North Korea behind $352M hack, citing IP clues
- Fed proposes new capital, redemption rules for stablecoin issuers
- New York sues Polymarket, alleging it is running an illegal gambling operation
Not financial advice. Crypto assets are volatile and unregulated in many jurisdictions. In India, gains are taxed at 30% with 1% TDS on transfers. Do your own research and never invest money you cannot afford to lose.
Editorial note: Crypto Shakti uses an AI-assisted research and drafting workflow. Every article is grounded in the linked primary sources and live market data captured at publication time.
