CSIPE

Published

- 17 min read

The Bitget Breach and the Difference Between a Balance and an Exit


Books by the author

Compare all 5

As an Amazon Associate I earn from qualifying purchases. Buying through these links costs you nothing extra and helps pay for the blog.

On 24 September 2026, the number in a Bitget customer’s account and the ability to move that money became two different things. The cryptocurrency exchange detected unauthorised transfers from its online wallets at 18:31 UTC, stopped withdrawals, and kept deposits and trading open. A customer could still see a balance. They could still buy or sell. They could not take their assets out.

That distinction matters more than the headline number. Bitget first estimated the affected assets at $351.6 million, then raised the figure to about $387.5 million after tracing more networks. The company says customer balances remain intact, its protection fund covers the loss, and the weakness has been repaired. Those are useful claims. They still leave every customer with a question that applies to any exchange: how much of your financial life should depend on one company’s promise and one working exit?

You do not need to empty every exchange or learn to guard a metal plate under the floorboards. You need a plan that matches the amount at stake and your ability to look after it. For a small trading balance, leaving funds on an exchange may be a sensible convenience. For savings that would hurt to lose or have frozen for a week, the same arrangement deserves a second door.

What happened, and what remains a company claim

Bitget’s first notice said its systems found unauthorised transfers from part of its hot and warm wallet layers on 24 September. It put the initial loss near $351.6 million, said its cold wallets were unaffected, and paused withdrawals while it reviewed the incident. Independent reporting from CNBC, The Hacker News, and Cointelegraph confirmed the public timeline and the exchange’s statements.

The number moved as the tracing improved. In its 26 September update, Bitget said about $387.5 million had reached attacker-controlled addresses across Ethereum-compatible networks, XRP Ledger, Zcash, and TRON. The extra amount represented assets missing from the first count, according to the company, rather than a fresh round of transfers. Bitget also said Mandiant and SlowMist were helping its investigation and that no further unauthorised transfers were possible.

Bitget’s chief executive told CNBC that an attacker had reached a critical backend wallet system, changed transfer information, and caused the exchange’s signing process to approve the transfers. She said a stolen private key had been ruled out and described North Korean involvement as a preliminary suspicion based on technical clues and similarities to earlier attacks. As of 26 September, that attribution remained an allegation from an investigation in progress. Who carried out the attack is interesting, but it changes little for a customer deciding where to keep next month’s rent.

The exchange has since published a phased withdrawal schedule. It says Bitcoin withdrawals will start on 28 September, selected Ethereum-compatible networks on 29 September, major USDT routes on 30 September, and other tokens, fiat, and peer-to-peer withdrawals on 2 October. Deposits and trading remain available. The firm says the timetable reflects security checks rather than a shortage of customer assets.

That is the fairest account available as of 26 September 2026, but it has a limit. The loss figure, the protection-fund coverage, the cause, and the claim that customer balances are safe all come from Bitget. News organisations can inspect public transfers and question executives; they cannot yet audit the exchange’s complete books or private incident records. A calm reader can hold two thoughts at once: Bitget may make every customer whole, and customers should still treat access as something to verify rather than assume.

A balance is an entry in somebody else’s book

When you keep cryptocurrency on an exchange, the app usually shows what the exchange owes you. The coins do not sit in a little wallet with your name on it. The operator combines customer activity, moves liquidity among online and offline wallets, settles trades internally, and sends a blockchain transaction when someone withdraws. That arrangement makes buying and selling quick. It also means the exchange controls the keys and the exit machinery.

Think of a coat check. Your ticket is a valid claim on the coat, but the ticket is not the coat. Most evenings, that difference is invisible because the attendant hands the coat back in seconds. If the storeroom door jams or the venue stops returns while it counts what is missing, the number on your ticket can remain perfectly accurate while you stand there without your coat.

A Bitget customer looking at an unchanged balance during the withdrawal pause was seeing a claim the company continued to recognise. Bitget says it has enough protection-fund assets to absorb the incident, and it has set dates for reopening. Until a withdrawal is available and completes, however, the customer cannot independently prove that the claim can be turned into an asset under their control. Trading one coin for another inside the same closed account does not test that exit.

This does not make every exchange balance fictitious. Banks, brokerages, payment apps, and gift cards all rely on records maintained by somebody else. The sensible question is what legal protection, operational resilience, insurance or reserve, and practical access sit behind the record. Cryptocurrency exchanges vary widely on those points, especially across countries. A bright balance on a screen tells you only one part of the answer.

The useful lesson from Bitget is therefore narrower than the old slogan about owning your keys. A number is one piece of evidence. A completed withdrawal is another. If you plan to rely on an exchange for a meaningful sum, you should know which evidence you have, how recently you checked it, and what you will do if the door is temporarily closed.

Why exchanges keep some wallets online

An exchange that served every withdrawal from a device locked in a vault would be safe in one sense and nearly unusable in another. Someone would have to fetch the device, verify the request, sign the transfer, and return it to storage. Customers expect withdrawals around the clock, across many networks, often within minutes. Exchanges meet that expectation by keeping part of their assets and transaction machinery ready to work online.

A hot wallet is connected closely enough to online systems to send assets quickly. A cold wallet is kept further away, with signing keys or approval steps that are harder to reach through an ordinary network attack. A warm layer sits somewhere between those ends. The labels sound precise, but each company chooses its own architecture, controls, and thresholds. One firm’s warm wallet may have very different protections from another firm’s.

The trade is the same as keeping cash in a shop till. The shop needs enough at the counter to give change, while the bulk belongs in a safer place. Too little at the counter and normal business stalls. Too much and one breach reaches a larger pile. The till also needs rules about who can open it, which payments look unusual, and when a second person must approve a large movement.

Bitget says its cold wallets stayed safe while parts of the hot and warm layers were affected. CNBC reported the company’s view that the attacker reached a backend system and made the signing process approve false transfer information. If that account holds, the incident was not simply a thief guessing a password. The machinery that was supposed to turn an approved instruction into a transfer accepted an instruction it should have rejected.

That mechanism explains why your personal password was not the centre of this incident. Changing it may still be sensible if you reused it, entered it on a suspicious page, or have doubts about your own account. A platform-side wallet failure is not repaired by millions of customers all changing good, unique passwords. Account hygiene protects the door to your account; it cannot redesign the exchange’s vault.

What a protection fund can and cannot prove

Bitget says its User Protection Fund held more than $464 million when the incident happened and will cover the platform-wide loss. On the figures published by 26 September, that amount exceeds the revised $387.5 million estimate. The statement gives customers a plausible source for making balances whole, which is better than an unexplained promise.

A fund figure still needs context. The value may move with the assets held inside it. The fund may be governed by company terms rather than a public deposit-guarantee scheme. Coverage of an exchange loss does not necessarily mean an individual has a direct legal claim to a specific slice of the fund. Timing matters too: an operator can have assets and still need days to check systems before it allows money to leave.

Proof of reserves answers a related but different question. It can help show that an exchange controls certain on-chain assets at a point in time and, when liabilities are included properly, that those assets line up with customer claims. It does not show every liability, every private agreement, or the safety of the software that moves funds tomorrow. It also cannot guarantee that a withdrawal system will stay open during an incident.

Picture three receipts on a kitchen table. One says what the exchange owes customers. One shows assets the exchange can prove it controls. The third explains the extra resources and rules available after a loss. You want the three to agree, and you want an exit that works. No single receipt replaces the others.

For this Bitget incident, the protection-fund claim is encouraging, the phased reopening is concrete, and the rising loss estimate is a reminder to wait for a final account. The company promised more investigation detail. The responsible position on 26 September is to watch what it actually publishes, whether withdrawals reopen on the stated schedule, and whether customers can complete ordinary transfers without special treatment.

The danger after the breach may arrive in your inbox

A widely reported exchange breach creates a perfect script for criminals who had nothing to do with the original attack. Customers expect urgent updates, frozen withdrawals, identity checks, and unfamiliar wallet addresses. A fake support agent can borrow every one of those details. The message sounds convincing precisely because the real incident happened.

The likely bait is easy to imagine: move your balance to a “safe” address before withdrawals close, connect a wallet for reimbursement, pay a fee to enter the recovery queue, or enter a seed phrase so support can restore access. Bitget says users do not need to take action before the phased reopening and that availability will appear inside its platform. That means an unsolicited person asking you to move first is contradicting the exchange’s published instruction.

Cryptocurrency transfers are especially useful to scammers because there is usually no card company that can reverse a payment. The US Federal Trade Commission warns that unexpected demands for cryptocurrency and promises to recover lost funds are common scam patterns. Its separate guidance on refund and recovery scams gives a plain rule: do not pay someone who contacts you and claims they can recover your money.

Use the app or a bookmark you created before the incident. Do not follow a sign-in link from an email, direct message, search advert, or reply under a social-media post. If the official app shows no action, you have permission to do nothing. A real support team does not need your wallet seed phrase, and nobody needs a transfer from you to “verify” that you own your account.

This is one place where a pause helps. Criminals need you to act before you compare the request with an independent source. Give yourself ten minutes, open the official status page separately, and ask what the sender gains if you comply. Anyone who insists that the delay will cost you everything has supplied the strongest reason to stop.

Decide what belongs on an exchange

The right storage choice depends on purpose. Money you actively trade needs to be near the market. Long-term savings do not need the same convenience. A tiny experimental amount may not justify learning another wallet. A sum that pays your mortgage for six months deserves more thought than a forgotten loyalty balance.

Start with the job each holding performs. If you plan to trade it this week, exchange custody may be the price of convenience. If you plan to hold it for several years, keeping all of it behind one company’s account, wallet system, legal terms, and withdrawal switch concentrates four different risks in one place. Splitting the roles can reduce the damage from any single failure.

Self-custody moves the keys to you. That removes the exchange’s ability to freeze your withdrawal, but it also removes the help desk’s ability to reset a lost recovery phrase. Send to the wrong address, approve a malicious transaction, lose every backup, or reveal the seed phrase, and there may be no rescue. The option deserves respect rather than romance.

A normal household can use a middle path. Keep the amount needed for near-term activity on a reputable exchange. Move longer-term holdings only after learning the wallet with a small test amount, backing up the recovery material offline, and proving you can restore it. Another person in the household should know that the holding exists and how to find the instructions in an emergency, without leaving the secret itself in an exposed note or email.

You are also allowed to decide that self-custody is too much responsibility. In that case, spread meaningful holdings across arrangements with different failure paths, favour providers with clear legal standing where you live, and keep ordinary cash outside crypto for ordinary bills. Diversification here means more than owning several tokens inside the same account. If one login and one withdrawal switch controls all of them, you still have one door.

A practical plan for Bitget customers

The incident calls for a measured sequence, not a midnight scramble. The goal is to protect your account now, verify the promised exit when it opens, and make a storage decision after the pressure has passed. Write down what you observe as you go. A dated screenshot or transaction identifier is more useful than a memory of what the app seemed to show.

  1. Enter through a trusted route. Open the Bitget app you already use or type a saved official address. Check the announcement inside that route. Ignore direct messages, replies, search adverts, and emails that ask you to use a different login page.

  2. Record your position. Save the date, the assets shown, the balances, and the withdrawal status for the networks you use. This is a personal receipt, not proof of the exchange’s reserves. It gives you a clean record if your displayed balance or account status changes.

  3. Secure your own account. Confirm that your password is unique and your second factor still works. CISA recommends multifactor authentication, especially for financial accounts. Prefer a security key or another phishing-resistant method where the service supports it; keep recovery codes offline and away from the device you normally use.

  4. Wait for the matching route. Bitget’s 26 September schedule reopens different assets and networks on different dates. A USDT withdrawal over Ethereum and a USDT withdrawal over Tron are different routes. Check the exact coin and network inside the official app rather than assuming that one successful reopening covers everything.

  5. Send a small test first. Once your route is available, send an amount you can comfortably verify to an address you control. Compare the first and last characters, confirm the network, and wait for the receiving wallet to show the transfer. A small network fee is cheaper than discovering a copied address or wrong chain with the full amount.

  6. Move only what your plan calls for. A successful test proves that route worked at that moment. It does not require you to empty the account, nor does it guarantee every later transfer. Decide in advance what remains for trading, what moves to longer-term storage, and what should become ordinary cash for near-term bills.

  7. Keep the withdrawal receipt. Save the transaction identifier, destination, amount, network, time, and the receiving confirmation. If a transfer stalls, use official support from inside the service and provide the reference without sharing passwords, one-time codes, private keys, or a seed phrase.

If the route misses its published date, record that too. Do not pay a stranger for priority access and do not send funds to an address offered in a social-media reply. Ask official support for a written status, then decide whether the delay changes how much you will leave there once access returns.

What does not help

Panic-selling inside the exchange does not solve a closed exit. You may turn one asset into another while remaining dependent on the same account and withdrawal system. A hurried trade can add price loss and fees without reducing custody risk. If your concern is access, test access when the official route reopens.

Moving everything to a new wallet you have never restored creates a different single point of failure. A wallet setup completed under pressure is where recovery phrases get photographed, cloud-synced, mistyped, or handed to fake support. Practise with a small amount. Prove the backup. Then increase the sum.

Spreading funds across several coins on one exchange does not diversify the custodian. The Bitget event affected multiple assets and networks because the common failure sat in the system that handled transfers. Different labels in the app can still lead through the same back office.

Changing a strong, unique password every time a platform reports an infrastructure incident can provide a feeling of motion without addressing the actual fault. Check your account for unfamiliar devices, sessions, API keys, addresses, and security-setting changes. Change the password when there is a reason, especially reuse or suspected phishing. Keep your attention for the controls that match the failure.

Finally, a famous attacker name should not drive your household decision. Bitget’s North Korea attribution remained preliminary on 26 September. Whether the culprit was a state unit, a criminal group, or somebody else, the customer lesson stays the same: an exchange needs to prevent false transfers, absorb losses it fails to prevent, communicate honestly, and return assets through a working exit.

The receipt that matters

Bitget’s response now has several measurable promises. The company has published a revised loss estimate, named outside investigators, said the weakness is fixed, committed its protection fund, and dated a phased return of withdrawals. Customers can judge those promises by what happens next rather than by choosing between blind trust and instant panic.

For an ordinary user, the cleanest test is modest. Does the balance remain correct? Does the precise withdrawal route reopen when promised? Does a small transfer arrive in the wallet or account you chose? Does the exchange publish a final explanation that matches the changing figures and the observed recovery? Each answer adds a receipt.

Then make the longer decision while nothing is flashing red. Keep trading money where you trade. Give long-term savings an exit plan that you have tested. Protect the account with a unique password and a strong second factor. Keep enough ordinary money outside crypto that a paused withdrawal does not become a household emergency.

You do not need to predict the next exchange breach. You need to know which balance depends on somebody else’s door, how much inconvenience you can tolerate if that door closes, and where you will move after it opens again. That is a calmer kind of security, and it works long after this headline fades.

If you want practical security guidance without a daily alarm bell, the newsletter is one email per month. The signup lives on this site.

Sources