Home / Blog / 24 September 2026
News · Sep 25, 2026 · 3 min read
An exchange's own security systems caught the theft within minutes and its own protection fund says it can cover it in full. Both of those claims are worth taking seriously and worth checking, and neither one is a reason a miner's coins were ever near the wallets in question.
Bitget's security systems flagged unauthorised transfers out of the exchange's hot and warm wallets at 18:31 UTC on 24 September and activated emergency procedures within minutes. Independent blockchain researchers were already posting about unusual outflows before Bitget said anything official, putting the early estimate at $170–183 million.
By the evening, Bitget's own figure was more than double that: $351.6 million. Chief executive Gracy Chen confirmed the total, said cold wallets were untouched, and froze withdrawals while the exchange carried out a security review; deposits and trading stayed open throughout. She declined to describe the attack vector, saying only that a full incident report would follow within 24 hours of detection (CoinDesk).
Chen said the loss "falls within the coverage of Bitget's User Protection Fund," which she put at over $464 million — roughly 132% of the confirmed loss, by TFTC's reading, or about $112 million of headroom. She added: "We will not speculate on the attack vector until the investigation is complete."
Nobody outside Bitget has audited that fund's composition, and it was quoted mid-incident by the same exchange that is the subject of the incident. That does not make it false. It does mean it belongs in the piece as a claim, not as a fact, until an independent number replaces it.
A self-reported number, given out during an active security incident, is a claim worth writing down and worth checking again once the audit lands.
Researchers tracking the stolen funds on-chain found the attacker consolidating assets across several chains — ether, stablecoins, AVAX, BNB and tokenised gold (XAUT) — before swapping the freezable stablecoins into ether, presumably to make the funds harder to trace and freeze (TFTC). Bitget's BGB token fell sharply on the news and had recovered only part of the drop by press time; bitcoin itself was largely unmoved, down a fraction of a percent over the same 24 hours.
That split matters. A hack of this size at an exchange that lists hundreds of tokens says something about that exchange's hot-wallet security. It says very little about bitcoin's own market, which is why our own price and liquidation data over the same window (below) shows nothing resembling a shock.
Before Bitget, September's tally of crypto exploits already stood near $342 million, including roughly $320 million from a separate incident on the Liquid Network. Add the confirmed Bitget figure and the month's total passes $684 million, ahead of April's $646.9 million, which had been the year's worst month until now (CryptoSlate).
That is a record for 2026 specifically, not a claim about crypto's worst month ever — earlier, larger single incidents exist in the record outside this year, and this piece is not comparing against them.
The same week, the CFTC filed a market-structure rulemaking covering custody and settlement standards for crypto trading venues, and the Federal Reserve opened comment on reserve and safekeeping rules for stablecoin issuers under the GENIUS Act. Neither is close to binding: the CFTC's own timeline points to late 2027, and the Fed's proposals carry 60-day comment periods before anything is finalised.
A hot wallet can be emptied in the time it takes a monitoring system to notice. The rulebook that might eventually set a higher bar for exchange custody is being drafted on a multi-year clock. The gap between those two speeds is the story underneath this one.
None of the coins in this story were ever going to be a miner's. The hold model this site runs on assumes a coin is mined, kept, and never handed to an exchange to sit in a hot wallet waiting to be traded — the same argument made from the other direction in our guide on why nobody sells the coins to pay the power bill. A coin that never leaves cold storage cannot appear on the list of assets an attacker moved through six different chains in an afternoon.
Network-side, nothing about this changes the arithmetic. Hashprice held close to $40 per petahash per day through the week the hack was detected, and the next difficulty retarget is still tracking about 3.5% lower, a small tailwind that has nothing to do with any exchange's wallet security. Exchange failures are a real and recurring cost of trading; they are not a mining risk, and the two should not be filed under the same worry.
Firsthand Bitcoin sells and hosts mining hardware, including this machine. No manufacturer, distributor or affiliate programme paid for or reviewed this page and we take no commission on the links above. Historical figures are computed from daily bitcoin price and network hashprice, each day valued at its own prices. Nothing here is investment advice.