# Bitget Hack Left 30 Minutes Before $290 Million in Assets Moved

By Simon Yoon

Canonical URL: https://www.tokenpost.com/news/technology/24949
Published: 2026-09-28T14:35:09.000Z
Updated: 2026-09-28T14:35:09.000Z
Section: Technology

> Unauthorized transfers began at 2:31 p.m. ET on Sept. 24, while two major waves followed at 3:01 p.m. and 3:16 p.m.

Bitget detected unauthorized transfers roughly 30 minutes before approximately $290 million moved from its hot and warm wallets in two major waves on Sept. 24, extending the exchange’s reported loss from the security breach.

The first wave began at 3:01 p.m. ET (19:01 UTC), when hot wallets sent $87.6 million across seven transfers on five networks in 15 seconds. A second wave started at 3:16 p.m. ET (19:16 UTC), sending $202.8 million from warm wallets across five networks in nine seconds.

Bitget’s systems detected the unauthorized activity at 2:31 p.m. ET (18:31 UTC), and the exchange said it activated emergency protocols immediately. The two waves represented 24 seconds of signing activity and totaled roughly $290 million.

Bitget initially estimated that $351.6 million had been affected, then raised the figure to approximately $387.5 million after adding Zcash and TRON transactions. The exchange said a compromised backend wallet-infrastructure system was used to spoof transaction data, while cold wallets were unaffected.

Transfers continued until 5:23 p.m. ET (21:23 UTC). Bitget said withdrawals were temporarily suspended, deposits and trading remained operational, and its Protection Fund covered the financial impact. The exchange said the vulnerability was remediated, with Mandiant and SlowMist assisting the investigation.
