Bitget says attackers used credentials exposed by a vulnerability in a third-party security product to send unauthorized withdrawal instructions from hot and warm wallets on September 24, 2026. The exchange revised its estimate from about $351.6 million to $387.5 million after adding Zcash and TRON transfers to its accounting; it said that change reflected a fuller count of the same incident, not a second wave of theft. Mandiant’s September 28 report offers a preliminary account of the intrusion, but its investigation was still ongoing. The $387.5 million figure is an estimate of transfers, not a verified final net loss after recoveries.
What Bitget says happened
Bitget says its security system detected unauthorized transfers involving hot and warm wallets at 18:31 UTC on September 24, 2026. It says it activated its emergency response and suspended withdrawals as a precaution. The exchange reports that cold wallets were unaffected.
According to Bitget, a vulnerability in a third-party security product exposed internal network credentials. The attackers allegedly used those credentials to forge withdrawal instructions that the wallet system processed while bypassing risk checks. Bitget says it patched the vulnerability and notified the product vendor.
Mandiant’s preliminary status report, dated September 28, describes privileged access to two third-party security appliances, identified as appliances A and B. It says the attacker deployed a web shell on appliance B, established command-and-control access, then moved laterally to Bitget’s production wallet job server and deployed malicious packages. Mandiant said its investigation was ongoing.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problems#1 Best Overall
On September 30, Bitget said Mandiant and SlowMist had completed independent investigations and that their findings broadly aligned with the attack path it had disclosed. BleepingComputer’s September 30 report attributed to SlowMist the finding that malicious activity appeared in available logs as far back as August 31, and that a customized withdrawal tool was used. That reported log date is not the date Bitget says the unauthorized transfers occurred.
Why the reported amount changed
Bitget’s first public estimate was approximately $351.6 million. On September 25, it revised that estimate to approximately $387.5 million after including transfers involving Zcash and TRON. Bitget said the revision was a more complete accounting of the same event, rather than evidence of additional unauthorized transfers.
Rank #2
- Ideal for Gifting
- Ideal for a bookworm
- Compact for travelling
| Figure | What it represents | Attribution and qualification |
|---|---|---|
| Approximately $351.6 million | Initial estimate of affected funds | Bitget’s initial estimate, as described in its September 25 update. |
| Approximately $387.5 million | Revised estimate after Zcash and TRON were included | Bitget’s September 25 estimate. Bitget said the change reflected fuller transfer accounting, not new unauthorized transfers. |
| US$351.6 million to US$387.5 million | Range for the initial loss estimate | Mandiant’s September 28 preliminary report; its investigation was ongoing. |
These figures describe estimates of affected transfers, not a final independently audited net loss. Bitget says freezing and recovery efforts remain underway, and Mandiant’s preliminary report does not establish a final amount lost after any recoveries.
What the incident means for Bitget customers
Bitget says the incident affected hot and warm wallet infrastructure, while cold wallets holding most platform assets were unaffected. The exchange also says private keys were not compromised. Mandiant’s preliminary report says it did not observe evidence that private keys had been compromised; that is a preliminary finding, not a final certification of every aspect of the incident.
Recommended Free Tools
Rank #3
Bitget says customer account balances remained accurate and that its Protection Fund would cover the financial impact. Those are the exchange’s assurances. Mandiant’s report confirms the range of Bitget’s estimate but does not independently establish the final impact on customers or the outcome of compensation.
- Review your account balance and transaction history through Bitget’s official app or website, and check whether any withdrawals or account changes require your attention.
- Use Bitget’s official incident communications for updates on account status and recovery. Do not rely on unsolicited messages claiming to offer reimbursement or recovery assistance.
- Distinguish an exchange account balance from control of the exchange’s underlying wallets: the incident concerned Bitget’s wallet infrastructure, while Bitget says customer balances remained accurate.
How much has been frozen or recovered?
Bitget says freezing and recovery are ongoing and directs readers to its live tracking dashboard because the totals may change. The public materials summarized here do not establish a fixed final amount frozen or recovered. A changing recovery total should not be treated as a finalized reimbursement figure or subtracted from the estimate as though the net loss were independently settled.
Quick Recap
Best Value
- It can be a gift option
- Comes with secure packaging
- Helpful in various ways
Rank #4
What is still unknown
- The reviewed public reports do not name the third-party security product vendors or provide vulnerability identifiers such as CVE numbers. Bitget has described a vulnerability, but the available reports do not provide enough detail to independently verify its technical classification or identify the products involved.
- Mandiant’s September 28 account is preliminary and explicitly says its investigation was ongoing.
- The final amount frozen, recovered, or left unrecovered is not established in the public material described here.
- Claims linking the incident to North Korean actors have been attributed to Bitget and reporting. Mandiant’s cited preliminary status report does not establish that attribution as a conclusion.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




