Shortly afterward, platform CEO Gracy Chen confirmed in an official notice that attackers had withdrawn approximately $351.6 million in crypto assets. Further on-chain tracking later raised the estimate to approximately $387.5 million after assets on the Zcash and Tron networks were included.
According to Chen, the attackers gained access to part of the exchange’s hot- and warm-wallet infrastructure, while the cold wallets holding most of Bitget’s assets remained secure.
Bitget also pledged to compensate affected customers in full, referring to the more than $464 million held in its User Protection Fund at the time of the initial announcement. Deposits and trading continued to operate, while withdrawals were temporarily suspended during the security review. Bitget later said the vulnerability had been fixed and withdrawals would be restored gradually.
The head of Bitget said the company would continue publishing updates through its official channels and remain active in the market rather than shutting down like other exchanges that have recently ceased operations.
Bitget’s preliminary investigation found no evidence that private keys had been exposed. The exchange therefore began examining more sophisticated scenarios, including an attacker infiltrating the team, as in the Drift incident earlier this year, or compromising third-party infrastructure, as in the $1.4 billion Bybit hack in 2025. According to Chen, the most likely explanation at this stage is that the attackers breached the wallet service’s backend system and used it to forge withdrawal requests.
Notably, the attackers appear to have chosen a time when Bitget was marking the month of its eighth anniversary.
On-chain data shows that the stolen assets included XRP, ETH, BNB, AVAX, ZEC, TRX and several stablecoins. The attacker quickly converted assets taken on EVM-compatible networks into ETH, reducing the opportunity for stablecoin issuers to freeze part of the funds.
One analyst pointed to a possible link between the XRP stolen from Bitget and the July attack on AFX Trade, suggesting that the North Korean Lazarus Group may have been involved in both incidents. This attribution remains preliminary and is not a final investigative finding.
Bitget’s BGB token fell by approximately 5% after news of the breach became public.

With losses estimated at approximately $387.5 million, the Bitget incident moved to the top of the list of cryptocurrency attacks in 2026 by the reported gross value of stolen assets. It exceeded the approximately $320 million withdrawn from Liquid Network, around 85% of which was later returned, as well as the roughly $285–295 million Drift Protocol breach and the approximately $292–293 million Kelp DAO exploit.
According to Blockaid, the first half of 2026 recorded the highest number of cryptocurrency attacks the company had ever tracked in a six-month period, with losses exceeding $1 billion. The increase coincided with the emergence of more capable AI models that can help identify previously undiscovered vulnerabilities, although AI should not be treated as the confirmed cause of every such incident.
Users comparing custodial trading platforms can consult the FORECK.INFO crypto exchange rankings, which consider security history, legal status, fees, liquidity, available markets, deposit and withdrawal options, editorial assessments and user reviews. A ranking cannot guarantee safety, so users should separately verify the current withdrawal status and official incident updates before depositing funds.