Key Highlights
- Bitget confirmed a $351.6 million exploit from its hot wallets on September 24, 2026, with on-chain data showing the first unauthorized transfer at 18:31:11 UTC and major outflows continuing for nearly three hours before the public notice.
- The attacker rapidly converted freezable stablecoins (USDT, USDC, Tether Gold) into ether via a router contract, paying up to 5% above spot price, suggesting a deliberate race against issuer freeze functions.
- CEO Gracy Chen stated user funds are safe and the loss is covered by Bitget’s $464 million User Protection Fund, while withdrawals remain suspended pending a full incident report due within 24 hours.
Timeline Reveals Hours-Long Gap Between Detection and Containment
Bitget chief executive Gracy Chen confirmed on Thursday night that attackers drained roughly $351.6 million from the exchange’s hot wallets, suspending customer withdrawals while an investigation proceeds. Chen published the notice at 21:30 UTC on September 24, 2026, stating: “At 18:31 UTC on September 24, 2026, Bitget’s security systems detected unauthorized transfers from some of our hot wallets. Our security team activated emergency response protocols immediately.”
On-chain data corroborates the 18:31 detection timestamp but paints a more granular picture of the subsequent three hours. At 18:31:11 UTC, a wallet labeled “Bitget 6” on Etherscan, Arbiscan, and BscScan sent 0.84 ether to a newly created address — a test transaction that typically precedes large transfers and marks the first movement of the breach. The outflows accelerated rapidly: by 18:58:59, the same wallet moved 34,751,168 USDT; at 19:01:20 on Arbitrum, 19,668,851 USDT0; at 19:01:23, 12,852,046 USDC; and at 19:01:35, 7,130.86 ether. A second wallet, “Bitget 35,” added 15,362 ether across three transfers, followed by another 223.2 ether at 21:23:11 — two hours and 52 minutes after detection and just seven minutes before Chen’s public notice.
Across Ethereum and Arbitrum alone, $133.4 million exited Bitget-labeled wallets, plus 3,000 Tether Gold tokens worth approximately $12.8 million from a third address. The remainder of the $351.6 million moved on other chains. Chen emphasized that cold storage was never touched and described a three-tier wallet architecture in which “the breach contained only a portion of the hot wallet and warm wallet layers.” However, the extended window between detection and containment allowed substantial value to leave the exchange’s control.
Attacker Strategy Signals Intent to Outrun Freeze Functions
The composition of stolen assets and the speed of conversion provide the clearest signal of the attacker’s intent. Tether can freeze USDT, Circle can freeze USDC, and Tether can freeze its gold token — but ether cannot be frozen by any central party. Within six minutes of receiving the stablecoins, the attacker pushed all three asset types into router contract 0x7c96279E, which fanned them across Uniswap V3 pools and the Uniswap V4 PoolManager, converting everything into ether.
Pseudonymous analyst DCF GOD, who identified the Arbitrum leg before Bitget’s public statement, noted the buyer was “paying up to +5% over spot” and drove one pool to $2,870 against a spot price near $2,688. “which makes no sense if someone was just trying to buy eth,” he wrote. The premium paid aligns with a seller racing issuer freeze functions rather than a typical market participant. The resulting ether — approximately 24,590 ETH — now sits in three previously inactive wallets: 10,000 ETH at 20:13, another 10,000 at 20:19, and 4,590 more at 21:41:11. That final transfer occurred ten minutes after Chen’s notice and one minute after Bitget’s official account stated it had “identified and flagged the relevant transfer addresses.”
Exchange Response and Industry Context
“User funds are safe,” Chen wrote. “The full amount of this loss falls within the coverage of Bitget’s User Protection Fund, which currently holds over $464 million.” She added that deposits and trading continue normally and promised a full incident report within 24 hours: “We will not speculate on the attack vector until the investigation is complete.”
That restraint reflects a pattern security experts recognize across recent major exchange breaches. Ido Sofer, founder and CEO of key management firm Sodot, described the dynamic on the On The Margin podcast: “Those are off-chain hacks that led to on-chain loss of funds. Developer credentials, deployment keys, API keys that are being stolen. And that provided access to moving funds on chain.” His blunter assessment: “There will be hacks. The question is, is it gonna be in your company or not?”
Bitget’s $464 million protection fund against a $351.6 million loss provides a thin but real cushion. The exchange has published proof-of-reserves attestations for 45 consecutive months, most recently reporting a 122% reserve ratio for August. The immediate test is whether withdrawals reopen without disruption.
Why This Matters
This incident represents the largest exchange loss since the Bybit breach and follows a series of high-profile security failures including the $130 million Coldcard theft and a $137 million November exploit that reshaped DeFi’s yield infrastructure. The attack underscores a persistent industry vulnerability: custodial exchanges remain prime targets where compromised off-chain credentials — developer keys, API access, deployment infrastructure — translate directly into on-chain asset drainage. The attacker’s sophisticated conversion strategy, deliberately overpaying to swap freezable assets for censorship-resistant ether before issuers could intervene, demonstrates an evolving playbook that prioritizes speed and asset selection over stealth. For the broader market, the episode tests whether exchange-backed protection funds can credibly absorb nine-figure losses without contagion, and whether proof-of-reserves attestations translate into operational resilience when withdrawals are suspended. The 24,590 ether now parked in three fresh wallets remains a live threat vector; any movement will signal the next phase of laundering or liquidation.
Frequently Asked Questions
- What assets were stolen and how much is the total loss?
- Approximately $351.6 million was drained from Bitget’s hot wallets across multiple chains. On Ethereum and Arbitrum alone, $133.4 million in USDT, USDC, USDT0, and ether left labeled wallets, plus 3,000 Tether Gold tokens worth ~$12.8 million. The remainder moved on other networks. The attacker converted all freezable stablecoins and gold tokens into ether within minutes.
- Are user funds affected and will withdrawals resume?
- CEO Gracy Chen stated “User funds are safe” and confirmed the loss falls within Bitget’s User Protection Fund, which holds over $464 million. Cold storage was not touched. Deposits and trading continue normally, but withdrawals remain suspended pending investigation. A full incident report is promised within 24 hours from the September 24 notice.
- How did the attacker move the funds and can they be recovered?
- The attacker used a router contract (
0x7c96279E) to swap USDT, USDC, and Tether Gold for ether via Uniswap V3 and V4 pools, paying up to 5% above spot price to execute quickly before issuers could freeze the stablecoins. The resulting ~24,590 ether now sits in three previously unused wallets. Ether cannot be frozen by any central party. Tether and Circle have freeze capabilities for USDT and USDC respectively, but those assets were already converted. Recovery depends on law enforcement action, exchange cooperation, and whether the attacker makes operational security mistakes when moving the ether.

