
Behind the story ⚡ (AI telemetry)Click to expand
See how six named AI agents in the 24markets flow handled intake, verification, writing, review, and visuals for this story. The agents are system roles, not people, journalists, or responsible editors.
Sigrid ⚖️(Intake agent)
Caught the story from «ForexLive» and cleared it for the desk based on market relevance.
Eskil 🔍(Research agent)
Ran research and cross-checked claims against 3 independent sources.
Ingrid ✍️(Writing agent)
Drafted the article in a clear editorial style, wrote the TL;DR, and structured the body.
Torbjørn ⚖️(Review agent)
“Solid piece — credible sources, clear language, and a strong angle.”
Vidar 📷(Image agent)
Generated the hero image and in-article illustrations.
Prompt: Wide editorial photo of a cybersecurity operations center at night, rows of monitors displaying blockchain transaction graphs and wallet flow diagrams, two analysts in silhouette studying screens intently, cool steel-blue fluorescent lighting casting sharp reflections on glass panels, photorealistic, magazine cover quality, documentary style, no logos or glowing coin imagery.
Nora ⚡(Publishing agent)
Prepared the story for publication with metadata, sources, and market disclaimer.
Crypto exchange Bitget has been hit by what could become the biggest hack in the industry this year. According to the company's own security notice, its systems detected unauthorized transfers from parts of the exchange's "hot" and "warm" wallet layers at 18:31 UTC on September 24. CEO Gracy Chen states that the total loss is estimated at around $351.6 million, according to ForexLive (investinglive.com).
Frozen withdrawals, normal trading
Bitget operates with a three-tier wallet structure: cold wallets kept offline, plus warm and hot wallets used for day-to-day withdrawal operations. Chen says the breach was limited to the latter two layers, while the offline cold reserves were unaffected.
As a direct consequence, the exchange has halted all withdrawals for every user, including those whose funds were untouched by the attack. Deposits and trading on the spot and futures markets continue uninterrupted, according to the company.
Bitget has promised hourly updates and a full incident report with root-cause analysis within 24 hours. The company says it has notified law enforcement authorities and blockchain security firms, and flagged the recipient addresses as suspicious.
Coins left on an exchange are only as safe as that exchange's security and its ability to absorb losses
How the attack unfolded
External blockchain analysts picked up on the movements before Bitget itself released information. Arkham Intelligence analyst Emmett Gallic described how funds from several Bitget-labeled wallets across various blockchains were consolidated into a single address, with early estimates of $174-183 million — roughly half the confirmed figure.
According to on-chain data, the attack began with a test transfer of 0.84 ETH at 18:31 UTC, before a wallet labeled "Bitget 6" drained around 34.75 million USDT just minutes later. Rapid transfers across multiple blockchains followed, including nearly $19.7 million in USDT0 on Arbitrum, which was swapped for 7,111 ether over about six minutes — at a price up to 5 percent above market rate.
The fact that the attacker paid such a premium for speed suggests that time mattered more than price. Stablecoins like Tether can be frozen by the issuer, while ether has no central issuer able to block transfers. Analysts have previously observed this pattern in the initial phases of other exchange hacks. A second wallet, labeled "Bitget 35", sent an additional 15,362 ETH across several transactions, with withdrawals continuing until at least 21:23 UTC.
The stolen funds include ether, USDT, USDC, AVAX, BNB, and even the gold token Tether Gold (XAUT) — including a single withdrawal of 3,000 XAUT worth around $12.8 million.
The world's most expensive hacker month of 2026
The Bitget hack comes on top of an already heavy month for crypto security. According to DeFiLlama, around $331 million in losses across 17 incidents had been recorded in September before the Fetch.ai attack on September 19, with most of that coming from an attack of around $320 million on Liquid Network. The attackers there claimed to be "white hat" hackers.
CryptoSlate estimates that Bitget's loss pushes September's total crypto hack losses above $684 million, making the month more costly than April, which was previously the most expensive month of 2026. The figure could change if funds are recovered. Social media claims that North Korea is behind the attack have not been confirmed, and Bitget has refrained from speculating on the perpetrator.
Fund coverage without independent verification
Chen says Bitget's user protection fund, which according to the company contains over $464 million, covers the entire loss with a comfortable margin. The fund was originally established in 2022 with a minimum requirement of $300 million and is backed primarily by a reserve of 5,500 bitcoin held separately from customer deposits. In August 2026, the fund's average value stood at $382 million, with a peak of $441.5 million and a low of $345.3 million during the same month.
It is worth noting that the fund's actual composition has not been independently verified beyond Bitget's own Merkle-tree-based "proof of reserves" reports, which are cryptographic snapshots and not full audits under accounting law. Because the fund is largely denominated in bitcoin, its real value fluctuates with the crypto market.
Market distinguishes between Bitget and the industry
Bitget's own token, BGB, fell around 5 percent after news of the hack began spreading late in the US trading session. The broader crypto market, by contrast, is up nearly 10 percent over the past week, suggesting the market largely views this as a company-specific problem for Bitget rather than a threat to the entire sector.
The attacker's rapid ether purchases on Arbitrum caused a brief, localized price distortion in the WETH/USDC pool of around $2,870 — a disturbance without genuine market demand behind it. The biggest risk to market sentiment going forward is likely time: if the withdrawal freeze persists, the chances increase that doubt will spread to other centralized exchanges.
What happens now
The next thing to watch is the incident report Bitget has promised within 24 hours, which is meant to explain how the breach occurred. A swift reopening of withdrawals with a clear explanation of the cause would strengthen Bitget's assurances, while a prolonged freeze or an upward revision of the loss figure would weaken them further.
The path the stolen ether funds take will also be decisive: if they are routed through anonymization tools like Tornado Cash, recovery becomes significantly less likely. For users with funds on Bitget, it may be advisable to wait for the promised report before drawing conclusions about how safe their funds actually are.
This article was written using large language models under editorial supervision by Aprex. Content is source-verified and auditable. Read our method →