TL;DR
On September 24, 2026, attackers drained roughly $388 million from Bitget's hot and warm wallets. According to Bitget, they did not crack any private keys: they exploited a flaw in a third-party security product, stole internal credentials, and used them to send forged withdrawal commands that slipped past the exchange's risk checks. Cold wallets were untouched, customer balances are reported intact, and withdrawals have been reopening in phases since September 28.
Bitget is the third major breach in two months, after the Liquid Network bridge exploit (about 4,000 BTC, September 6) and the Coldcard hardware wallet drain (about $116 million, from July 30). Each failed at a different layer — exchange operations, bridge software, and wallet firmware — so no single storage choice removes custody risk on its own.
Key Takeaways
- Bitget detected unauthorized transfers at 18:31 UTC on September 24, 2026; the loss estimate rose from $351.6 million to about $388 million after reconciliation.
- The entry point was a third-party security product, not stolen private keys. Forged commands bypassed internal risk controls.
- Withdrawals restarted in phases from September 28, beginning with bitcoin; Bitget points to a User Protection Fund of more than $464 million.
- Liquid Network and Coldcard show the same lesson from different angles: risk sits in operations, bridges, and firmware, not only in "exchange versus wallet."
- Practical defense is layered: keep only trading balances on exchanges, verify how your wallet generated its seed, and treat wrapped assets as carrying bridge risk.
"Not your keys, not your coins" is usually where a hack conversation ends. September 2026 makes that slogan look incomplete. One major exchange lost hundreds of millions without a single private key leaking, a Bitcoin sidechain lost almost its entire reserve to a software bug, and owners of a well-regarded hardware wallet were drained because of randomness generated years earlier. Here is what happened at Bitget, how it compares with the other two breaches, and what each one actually teaches about where your crypto is exposed.
What Happened at Bitget
At 18:31 UTC on September 24, 2026, Bitget's security system detected unauthorized transfers involving certain hot wallets and warm wallets, according to the exchange's official security incident page. Bitget says the incident has been contained and that cold wallets, which hold the majority of platform assets, were not affected.
The stolen assets spanned Ethereum and multiple EVM networks, the XRP Ledger, Zcash, and TRON, including XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX, and TRX. Bitget first put the loss at $351.6 million, then revised it to approximately $388 million after reconciliation — source: Bitcoin.com News.
In a September 28 statement attributed to CEO Gracy Chen, Bitget described the breach as the first attack of this nature on its exchange infrastructure in eight years, adding that the record "does not diminish the seriousness of the incident."
How the Attack Worked: Credentials, Not Keys
Bitget's investigation found that the attacker exploited a vulnerability in a third-party security product to steal internal network access credentials. With that access, the attacker forged withdrawal commands to the wallet system and deceived it into executing abnormal transfers that bypassed risk checks. Bitget states that private keys were not compromised.
The distinction matters. Most people picture an exchange hack as someone stealing the keys to a wallet. Here, the keys stayed safe, and the attacker instead impersonated the people and systems allowed to use them. The weakest point was the operational layer around the wallets: the tools an exchange trusts, the credentials those tools hold, and the checks that are supposed to catch unusual withdrawals.
That is also why a cold wallet split helped. The funds an attacker could reach were limited to the hot and warm wallets connected to daily operations, while the larger reserves in cold storage stayed out of reach.
Where Bitget Users Stand Now
Withdrawals have resumed in phases since September 28, according to Bitget's incident page, with the company saying the same approach applies to all users without preference — source: Bitget Support Center. By 9:00 UTC on September 28, Bitget had processed 9,585 bitcoin withdrawals totaling 4,098 BTC, according to Bitcoin.com News.
USDT withdrawals have since reopened across Ethereum, BSC, Solana, and Tron, with other token, fiat, and P2P withdrawals planned for October 2, and Mandiant and SlowMist assisting the investigation, according to CoinCodex. Bitget also points to its User Protection Fund, reported at more than $464 million, as the backstop for customer balances.
If you hold funds on Bitget, rely only on the official incident page and support center for timelines. Large incidents attract fake "refund" and "recovery" links, and no legitimate exchange will ask for your password, 2FA code, or seed phrase to restore a balance.
Bitget, Liquid Network, and Coldcard: Three Breaches, Three Layers
| Bitget | Liquid Network | Coldcard | |
|---|---|---|---|
| Type | Centralized exchange | Bitcoin sidechain bridge | Hardware wallet |
| Date | September 24, 2026 | September 6, 2026 | From July 30, 2026 |
| Size | About $388 million | About 4,000 BTC (~$320 million) | About 1,816 BTC (~$116 million) |
| Failure point | Stolen credentials via a third-party security product | Bug in bridge infrastructure | Weak randomness in 2021 firmware seed generation |
| Status (latest reports) | Withdrawals reopening in phases | 3,400 BTC returned; ~598 BTC outstanding as of September 8 | Funds pooled at attacker addresses; affected seeds must be migrated |
Liquid Network: when a wrapped asset loses its backing
On September 6, 2026, attackers withdrew about 4,000 BTC, worth roughly $320 million, from the federation wallet that backs Liquid's L-BTC token, leaving just 197 BTC in reserve. The group described itself as white-hat hackers and, after Blockstream patched the affected bridge nodes, returned 3,400 BTC, while about 598 BTC, worth around $47 million, remained outstanding — source: CoinDesk.
The lesson is that a wrapped or bridged asset is only as safe as the reserve and code behind it. Holders of L-BTC never touched the stolen bitcoin, yet their token was briefly far from fully backed.
Coldcard: a five-year-old firmware flaw
Beginning July 30, 2026, attackers exploited a bug in Coldcard firmware version 4.0.1, released in March 2021, that caused some devices to generate seeds with far weaker randomness than intended. Effective key strength dropped from 128 bits to as little as 40 bits, low enough to brute force without physical access. About 1,816 BTC, close to $116 million, was drained from more than 5,200 addresses across four waves — source: TRM Labs.
TRM Labs notes that updating firmware does not protect wallets whose seeds were created under the vulnerable version. Anyone who generated a seed on an affected Coldcard should treat it as compromised and move funds to a new seed. At the time of its assessment, TRM counted 2026 hack losses at over $1.2 billion across 276 incidents, a total recorded before both the Liquid and Bitget breaches.
What These Breaches Teach About Custody
Keep exchange balances to what you are actively trading. Bitget's cold storage held, but users still could not withdraw for days. Assets you are not using belong in a wallet you control. The broader case for limiting exchange exposure is laid out in our article on the CoinEx shutdown and counterparty risk.
Self-custody is only as strong as how your seed was created. Coldcard owners did everything "right" and were still exposed by firmware generating weak randomness. Keep firmware current, follow vendor security notices, and move to a fresh seed when a vendor tells you to. Backup practices still matter; see our guide to backing up and recovering your seed phrase.
Wrapped and bridged tokens add a layer of risk. Holding L-BTC, wrapped BTC, or bridged stablecoins means trusting the reserve, the bridge code, and its operators on top of the underlying asset. That is a reasonable trade for speed or utility, but it should be a conscious one.
Diversify where risk sits, not only what you hold. Splitting holdings across an exchange, a hardware wallet, and on-chain positions spreads exposure across different failure modes. Our explainer on CeFi vs DeFi risks covers how those models fail differently.
Limits of These Lessons
Figures in all three incidents are still moving. Bitget's total was revised once already, Liquid's outstanding balance was reported as of September 8, and TRM describes the Coldcard numbers as preliminary because victims often come forward months later. Treat every number here as a snapshot dated to its source.
Self-custody also carries its own risk. There is no support desk for a lost seed phrase, and phishing, malware, and physical theft target individual holders every day. Moving everything off exchanges reduces counterparty risk but increases the responsibility on you, so the right split depends on how much you hold and how confident you are managing keys.
Frequently Asked Questions
Can I withdraw from Bitget now?
Bitget says withdrawals have resumed in phases since September 28, 2026, starting with bitcoin, with more assets reopening through early October. Availability varies by asset and network, so check Bitget's official incident page and support center for the current schedule before moving funds.
Were Bitget user balances lost in the hack?
Bitget states that customer balances remain intact, that cold wallets were unaffected, and that its User Protection Fund, reported above $464 million, stands behind user assets. The stolen funds came from hot and warm wallets the exchange operates, not from individual user accounts being emptied.
Is a hardware wallet still safer than an exchange after the Coldcard hack?
For long-term holdings, a well-maintained hardware wallet still removes exchange counterparty risk. The Coldcard case shows the device's firmware matters too: seeds created on vulnerable firmware stayed weak even after updates, so owners need to act on vendor security notices and migrate when advised.
What should I do if I hold L-BTC or other bridged assets?
Follow the network operator's official channels. During the Liquid incident, operators asked users not to send bitcoin to peg-in addresses until a restart was confirmed. More generally, size bridged positions with the understanding that the reserve and bridge code are additional points of failure.
How can I spot fake recovery offers after a hack?
Treat any unsolicited message promising refunds, recovery, or compensation as suspicious, especially links shared through direct messages or new social accounts. Legitimate exchanges announce recovery steps on their official sites and never request seed phrases, passwords, or 2FA codes.
Disclaimer
This article is for educational purposes only and is not financial advice. Figures and status updates reflect public reporting and official statements available as of October 1, 2026, and may change as investigations continue. Always confirm current details with the official source before acting.
Sources
- Bitget — Security Incident (September 2026): Hack Timeline, Impact, and Latest Official Updates
- Bitget Support Center — Bitget to Resume Withdrawals in Phases
- Bitcoin.com News — Bitget Restarts Bitcoin Withdrawals as $388M Hack Investigation Widens
- CoinCodex — Bitget Restores USDT Withdrawals After $387.5M Hack
- CoinDesk — Liquid Network Hack: Whitehats Return 3,400 BTC
- TRM Labs — The Largest Hardware Wallet Exploit of 2026: Inside the USD 116 Million Coldcard Hack

