# Bitget Reports $388 Million Crypto Theft From Hot and Warm Wallets

By Simon Yoon

Canonical URL: https://www.tokenpost.com/news/technology/25113
Published: 2026-09-29T00:48:59.000Z
Updated: 2026-09-29T00:48:59.000Z
Section: Technology

> The exchange said forged withdrawal commands moved funds from part of its hot and warm wallets, while customer balances and cold wallets were unaffected.

Bitget linked an attack that moved approximately $387.5 million in crypto to a suspected vulnerability in a third-party security product, while saying customer balances, private keys and cold wallets were unaffected.

The unauthorized transfers began at about 6:31 p.m. ET (22:31 UTC) Sept. 24 from part of Bitget’s hot and warm wallet infrastructure. Bitget said its preliminary investigation found that the attacker obtained high-level internal credentials, inserted fraudulent withdrawal commands and bypassed existing risk controls.

Bitget later revised its initial loss estimate of $351.6 million after classifying additional Zcash and TRON transfers. The company said the updated figure, which it has rounded to about $388 million, does not represent further unauthorized transfers after containment.

Bitget isolated affected systems, reset credentials and remediated the suspected vulnerability. It said its Protection Fund will cover the financial impact and launched a recovery program offering eligible participants 5% of funds successfully frozen or recovered.

Bitcoin withdrawals resumed at 4 a.m. ET (8:00 UTC) Sept. 28. Ether withdrawals were scheduled to resume Sept. 29, USDT withdrawals Sept. 30, and other tokens, fiat and peer-to-peer services Oct. 2. Mandiant and SlowMist are assisting with forensic analysis and asset tracing.
