What Happened: Bitget just had one of the worst days any exchange has had in 2026. On September 24, at 18:31 UTC to be exact, something like $351.6 million quietly walked out of the exchange's hot and warm wallets — and for a few tense hours, nobody outside the company knew whether this was another catastrophic key theft or something else entirely.
Turns out it was something else, and weirdly, that's the less scary version of this story.
CEO Gracy Chen came out fairly quickly with an explanation, and it's one of the more memorable lines to come out of a crypto hack this year: the attack, she said, worked "like forging withdrawal slips at a bank." Not a stolen vault key — a forged form that the bank's own staff processed without realizing it was fake. In technical terms, Bitget says its private keys were never touched. Instead, whoever did this got into the backend systems that prepare and approve transactions, and used that access to push through transfer requests that looked legitimate to Bitget's own internal checks.
If you've been following crypto hacks for a while, then you’d understand that a stolen private key is close to a worst-case scenario — the attacker doesn't need anyone's permission after that; they just move funds. What happened here sounds more like someone found a crack in the approval process itself. Still bad, still hugely expensive, but not the same category of doomsday.
Seven different assets ended up affected, with Ethereum taking the biggest hit — about 44.4% of everything stolen. Bitget's cold wallets, where most exchanges keep the bulk of customer funds specifically because they're offline and harder to touch, weren't part of this at all. Chen says they're "fully secure."
So what about the money — is it actually gone for good, or does Bitget eat the loss? This is the part users actually care about, and Bitget's answer so far is that everyone's balance is fine. Chen has said plainly that user funds are safe and that account balances on the platform are accurate. Bitget's User Protection Fund — sitting at north of $464 million — is apparently large enough to absorb the entire $351.6 million loss by itself, no customer haircuts, no socialized losses, none of the messier outcomes we've seen from other exchanges that got hit and didn't have the reserves to cover it.
Withdrawals are paused right now while the security team runs a full review — that's standard after something like this — but deposits and trading are still working normally. No firm date yet on when withdrawals come back, just a promise of a full incident report within 24 hours of the breach being caught.
Zoom out for a second and this hack does something interesting to the year's numbers. Before Bitget got hit, September 2026 had already racked up about $342 million in losses across 17 separate incidents — a rough month, but not a record one. Add Bitget's $351.6 million on top and September blows past $684 million total, overtaking April (roughly $646.9 million, mostly from the Drift and KelpDAO exploits) as the single costliest month for crypto theft this year.
There's a pattern worth noticing here too. Most of 2026's big losses have come out of DeFi — smart contract bugs, bridge exploits, oracle manipulation, that whole category. Bitget is a reminder that centralized exchanges are still very much in the crosshairs, and that attackers aren't only chasing raw private keys anymore — they're probing the boring, unglamorous operational plumbing around how transactions get approved, which turns out to be just as exploitable if nobody's looking closely enough.
What we don't know yet: exactly how the attackers got into that approval layer in the first place. Was it a compromised internal credential? A flaw in the signing infrastructure? Something upstream, like a vendor tool Bitget relies on? Bitget hasn't said, and until that promised incident report drops, everything beyond "it wasn't the keys" is guesswork.
For now, if you're a Bitget user: your balance is intact, you can deposit and trade, you just can't withdraw yet. For everyone else watching from the sidelines, this is shaping up to be one of the year's more consequential exchange breaches — not because of how the money disappeared, but because of what it says about where the next weak point in exchange security might actually be.
CandyPulse will follow up once Bitget's full report is out and withdrawals reopen.
Sources:
* Bitget's $351.6 million hack pushes September crypto losses to 2026 high
* Bitget's $352 million hack happened via spoofed transfers, not private keys, CEO Gray Chen says
* Crypto exchange Bitget says $352 million affected in a hack, claims user funds are 'safe'