BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Policy

387.5 million dollars at Bitget: the attack ran through a bought-in security product, what to watch now

If you keep a balance on a centralised crypto exchange, the Bitget case has read differently since September 28. The exchange's own keys were not cracked, and no cold wallet was emptied. The

AnonymousCryptoCompass newsroom
September 29, 2026
10 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for policy coverage.

If you keep a balance on a centralised crypto exchange, the Bitget case has read differently since September 28. The exchange's own keys were not cracked, and no cold wallet was emptied. The attacker came in through a security product that Bitget itself had bought, and used that product's privileges to pose as an administrator. On the figures published so far, the damage lies between $387.5 million and $388 million. For you, that means the question of whether an exchange is well secured does not hang on its own technology alone, but on every supplier it lets inside its systems.

This article sets out the attack path, names the documented figures and the schedule under which withdrawals are restarting. It also says which parts of it touch a decision of your own, and which remain corporate news and nothing more.

What Bitget says about the attack path

On the company's account, the attacker exploited a zero-day vulnerability in a third-party security product. Zero-day means a flaw that the software maker did not know about at the time of the attack, so there was neither a patch nor a warning. Through that flaw the attacker obtained valid administrator credentials. With those credentials he wrote forged withdrawal instructions straight into the wallet backend systems, then deleted the traces of those instructions.

The sequence is the real finding. There was no break-in at the key management layer. Bitget chief executive Gracy Chen told The Block that erasing the traces was the most delicate part of the operation, and framed the incident as one that is very serious at this scale, while serious does not amount to existential. Private keys and cold wallets were not compromised on the investigation's current standing. The security firms Mandiant and SlowMist have been engaged to establish what happened.

The timeline of September 24: two test transfers, then 17 transactions

The sequence reads like a test of the alarm thresholds. At 18:31 UTC two tiny transfers went out, 0.184 ETH and 193 TRX. Both sat below the amounts at which the exchange's risk controls fire. Only afterwards came the outflow proper: between 18:58 and 20:09 UTC, 17 large transactions across eight different blockchains, worth roughly $361 million in total.

What stopped it was not the withdrawal control but the ledger reconciliation. At 19:05 UTC the reconciliation system flagged a gap between recorded and actual balances, and Bitget then froze withdrawals across the platform. Seven minutes separated the first large transaction from the alarm; a little over an hour separated the alarm from the end of the outflows.

That two minimal amounts went first is the part that matters most to you as a user. It shows that value thresholds alone are not a defence when an attacker can probe those thresholds beforehand without drawing attention.

Zero-day at the supplier: why an outside flaw hits the entire exchange

A crypto exchange does not only run trading software. It buys in monitoring tools, access management, logging and defence systems, and those tools need far-reaching privileges by their nature in order to do their job. That is exactly where the problem comes from: a product allowed to see everything and to intervene in much of it is worth more as an entry point than any single user account.

For judging an exchange, that shifts the yardstick. A platform can keep its own keys impeccably and still be vulnerable because a supplier had a flaw. This is not a one-off at this exchange but a pattern attackers use across the whole financial sector. For you, nothing about it calls for panic, but one sober consequence follows: the amount you leave sitting on a trading platform should match the amount you could stand not to move for weeks in the worst case.

How to handle custody away from an exchange in practice is covered in the hardware wallet comparison, which looks at devices, prices and the sum above which the effort pays off.

Eight heavy brass valves on a dark wall, seven closed, one turned a quarter open by a gloved hand, with a coin bearing a diamond-shaped symbol below Withdrawals are restarting network by network, not all at once.

The withdrawal schedule: ETH networks open on September 29 at 08:00 UTC

Bitget did not release withdrawals in one go but in stages. The schedule is set out in the exchange's notice and runs as follows:

  • September 28, 08:00 UTC: BTC over the Bitcoin network.
  • September 29, 08:00 UTC:Ethereum over Ethereum itself as well as BSC, Arbitrum, Base and Optimism.
  • September 30, 08:00 UTC: USDT over Ethereum, BSC, Solana and Tron.
  • From October 2, 08:00 UTC: remaining tokens, fiat balances and P2P holdings.

The exchange adds that the pause served a final security review and has no bearing on the availability of user funds; account balances were unchanged, and trading and deposits ran throughout. What you can draw from that: if your balance sits in a token other than BTC, ETH or USDT, nothing moves for you before October 2. The position as of September 26, when the stages were announced, has already been documented by cryptoticker.io.

A $465 million protection fund against $387.5 million of damage

Bitget says it is absorbing the loss in full from its protection fund, which was valued at $465 million on September 25. The fund is to be topped back up to at least $300 million within a week; as a corporate reserve the company cited more than $1.4 billion as of August 31.

A protection fund is not a deposit guarantee scheme. It is a voluntary reserve whose use the exchange decides on itself, and it is subject to no state supervision that could force a payout when it matters. That sets it apart fundamentally from the statutory deposit guarantee on a bank account, which in the EU covers up to 100,000 euros per customer and institution and expressly does not extend to crypto assets. How large the funds of the bigger trading venues actually are, and how they compare with trading volume, was compiled by cryptoticker.io in a count of its own on September 25.

The loss figure has grown over the course of the week. Our first report on September 24 still put it at $351 million, because only part of the outflows had been attributed at that point; that is how cryptoticker.io framed it on the day of the incident. On the figures given on September 28, the value lies between $387.5 million and $388 million. Upward revisions of this kind are the norm in the first days of an exchange incident, and they are a reason not to treat early numbers as final.

MiCA and custody: what a licence requires in Germany

Since the European crypto regulation MiCA applies in full, any provider offering custody, trading or exchange to customers in the EU needs authorisation as a crypto-asset service provider. For custody, the regulation requires among other things that customer holdings be kept separate from the provider's own assets, and that the provider be liable for the loss of crypto assets held in custody where the circumstances are attributable to it. The individual duties that hang on this, and the deadlines the supervisor has set, are broken down in our overview of the MiCA licence.

In practice that means this for you: whether you can invoke that liability in a loss depends on which company your contract was concluded with. Between an EU-regulated arm of a provider and its international entity there are often entirely different legal systems at trading venues. The terms of use state which company is your counterparty and which law applies. It is worth looking that up once, before it matters.

Dark metal balance scale, a heavy bar low on the left, several small coins bearing the Bitcoin symbol high on the right, beside a closed metal cash box A protection fund only weighs heavy for as long as it carries the loss.

Self-custody against exchange custody: the trade-off after the incident

The case is no argument for avoiding every exchange. It is an argument for making the split deliberately. On a trading platform your balance sits where you can sell or swap it quickly, and where someone else answers for the technology in a loss. In your own custody it sits where no external system access can move it, and where a lost recovery phrase is final.

A workable rule of thumb: the amount on the exchange matches what you actually intend to trade in the coming weeks, plus a buffer. Everything above that belongs in custody you control yourself. Where that line falls depends on how often you trade, not on a figure that holds for everyone. Someone who rebalances every two days needs a different split from someone who adds twice a year.

Two things cost most in this trade-off, in our experience: convenience, and the assumption that an incident always hits the other platform. The 17 transactions of September 24 took 71 minutes. In that window no user could have reacted, not even the most attentive one.

Holding period and tax: a withdrawal freeze changes nothing under Section 23 EStG

One question comes up with every withdrawal freeze: does the one-year holding period keep running when you cannot reach your coins? It keeps running. What counts for the period under Section 23 of the German Income Tax Act is the span between acquisition and disposal, not whether you could dispose of the asset in the meantime. Access blocked for technical reasons is not a disposal and therefore interrupts nothing.

Conversely, an incident of this kind does not create an automatic loss you could claim either, as long as your account balance is unchanged and the exchange pays out. A loss that counts for tax presupposes an actual outflow of assets. Should an exchange permanently fail to pay out, the position is a different one and belongs in the hands of a tax adviser, because the question then becomes when a failure counts as final.

In any case, keep your transaction records outside the platform. When an exchange restricts access, experience shows it is the tax documents that become unreachable first.

What is still open

Bitget has announced a formal investigation report. Until then it remains open which security product was involved and whether the underlying flaw has since been closed, because that determines whether other platforms carry the same risk. It is equally open whether the protection fund is refilled within the announced timeframe. And the attribution of the perpetrators remains open; the company said only that in its assessment this is the same group it had already suspected before.

Until those points are documented, the position set out in this article stands. We will update it once the investigation report is available.

Bitget hack: the key points for your decision

  1. Check which token your balance sits in. BTC has been withdrawable since September 28, ETH and the EVM networks since 08:00 UTC today, USDT from September 30, everything else only from October 2. That determines whether there is anything you can do at all. Where to move if in doubt is shown in the overview of crypto exchanges.
  2. Set the threshold above which a balance leaves the exchange. Take your bearings from how often you trade, not from the current price. Which devices come into question and what they cost is set out in the hardware wallet comparison.
  3. Look up who your counterparty is. The terms of use name the company and the applicable law. If the contract sits outside the EU, the MiCA duties do not apply for you; the alternatives with European authorisation are listed under regulated crypto exchanges.

(As of September 29, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)