Bitget Hack of $351 Million: What to Check at Your Crypto Exchange Now
Bitget reports unauthorised outflows of around $351.6 million and has suspended withdrawals. For existing customers in Europe, that closes the one route MiCA had left them.

Table of Contents
Table of Contents



Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
On the evening of Thursday, September 24, 2026, the crypto exchange Bitget said it detected unauthorised outflows from part of its wallets at 18:31 UTC and suspended withdrawals in response. The figure the company itself gives is around $351.6 million. For a European investor, the most important detail is not the size of the loss but the withdrawal freeze: anyone still holding a residual balance at Bitget cannot reach it right now.
That hits a group already working against the clock. Since July 1, 2026 at the latest, providers without MiCA authorisation have been barred from taking on new business in the European Economic Area. Bitget has exited the EEA market in stages and told existing customers to withdraw their balances. That single remaining route is now temporarily closed.
What happened at Bitget: hot wallets, warm wallets and $351.6 million
A hot wallet is an exchange wallet whose private key stays permanently connected to the internet. It has to be, because withdrawals are meant to settle in seconds. A cold wallet keeps the key offline instead, usually on separated hardware; it is slow, but out of reach for an attacker working over the network. Between the two sits the warm wallet, an intermediate tier with limited but real network access.
Bitget describes its custody setup as a three-tier architecture built from exactly those layers. According to chief executive Gracy Chen, quoted by CoinDesk, only part of the hot and warm wallet tier is affected and the cold wallets are intact. The amounts on-chain observers could see diverged at first: blockchain analysts reported movements of roughly $178 million to $183 million in the opening hours, while the company puts the figure at $351.6 million. A spread like that is normal in the first hours after an incident, because outside observers only see the transactions they have already been able to attribute.
The outflows were spread across fifteen transfers and seven assets on several networks, according to an analysis by CryptoSlate. The largest single block, 44.4 percent, was Ethereum; BNB, AVAX and the stablecoin USDT were among the others affected. Notably, the funds were then consolidated into a single address.
The exchange treats deposits and withdrawals differently: deposits and trading continue to run, the company says, and only withdrawals are paused for the duration of the security review. Bitget announced hourly updates and a full report on the root cause within 24 hours. Neither had appeared by the time this article went to press.
Why the withdrawal freeze hits existing European customers hardest
To a European investor the case may look remote at first, because Bitget is no longer permitted to write new business here. That is precisely what makes the situation more awkward rather than less. When a provider withdraws from the EEA in an orderly fashion, existing customers are usually left with exactly one action: withdraw. If that route is blocked for an indefinite period, the people affected lose the only option regulation had left them.
A second deadline runs alongside, unrelated to the incident. On September 18 Bitget announced it would delist the trading pairs COTI/USDT, SAGA/USDT and RVN/USDT on September 24 at 10:00 UTC. For those three assets, withdrawals run until December 24, 2026, 10:00 UTC, according to the announcement. Anyone still holding positions there has a date in the calendar and a blocked withdrawal route at the same time. That combination is why waiting does not resolve itself here.
In practice: check today whether you are affected at all. Log in, note the balance with the date and time, take a screenshot and file a withdrawal request as soon as the function reopens. A documented balance is the basis for any later claim and for your tax return. Do not respond to emails or direct messages offering help with the withdrawal in this situation: a withdrawal freeze is exactly the moment when fraudsters approach customer lists with supposed recovery services.

MiCA and the ESMA register: which exchange is allowed to serve you
The European regulation on markets in crypto-assets, MiCA for short, has since 2025 required every provider offering crypto-asset services in the EEA to hold an authorisation as a CASP (crypto-asset service provider). Authorised providers appear in a public register kept by the European securities regulator ESMA. The transitional rules for legacy providers expired EU-wide on July 1, 2026 at the latest, and in Germany already on December 31, 2025.
Correction (September 30, 2026): An earlier version gave July 1, 2026 as the end of the transition period without the German rule. Under Article 143(3) MiCA (Regulation (EU) 2023/1114), the transitional regime applied EU-wide until July 1, 2026 at the latest, and member states could shorten it. Germany did: under section 50(2) no. 3 of the German Crypto Markets Supervision Act (KMAG), the continued authorisation expired on December 31, 2025 at the latest.
Bitget holds no such authorisation and does not appear in that register. The company has applied for a licence in Austria and is building a European entity in Vienna; until a licence is granted, it offers no services in the EEA. What looks like a formality in hindsight is the real difference for you: with an authorised provider you would have a European supervisor to address, reporting duties and documented custody requirements. Without authorisation that whole apparatus is missing, and you depend on the company's assurances.
From that follows the first check, and it reaches beyond this one case. Find out under which company and in which country your provider is actually authorised, and compare that against the ESMA register. If you want a starting point, our overview of regulated crypto exchanges for European investors lists the providers that have cleared this hurdle. The obligations those companies face under the MiCA licensing regime are a separate subject we have set out elsewhere.
One misunderstanding comes up often: a MiCA authorisation is no shield against hacks. It obliges the provider to meet organisational requirements and to segregate client assets, and it gives you a regulated counterparty if something goes wrong. It does not prevent the technical break-in.
Hold your balance yourself: the devices comparedThree wallet tiers at an exchange: what actually protects your balance
When you hold coins in an exchange account, you do not own coins on the blockchain. You own a claim against the company. The exchange runs an internal ledger of your balance and keeps all customer holdings pooled in its own wallets. That distinction matters the moment the exchange's holdings fall below the sum of the claims against it.
Splitting funds into hot, warm and cold is the standard answer to that risk. The large majority of customer holdings is meant to sit offline, while only a working float is kept online, large enough for day-to-day withdrawals. If the split works as intended, a break-in at the hot wallet reaches only that working float. In this case, though, the sum the company names runs into the hundreds of millions, which shows how large that float gets at a major exchange.
From that you can derive a question to put to any provider: does it publish proof of reserves, and can that proof be verified independently? A meaningful attestation names addresses, a cut-off date and a method by which customers can confirm their own balance was included. A press release with a total and no verifiable addresses does not meet that bar.
The protection fund is not deposit insurance: what $464 million in cover means
Bitget points to its own protection fund, which the company says holds more than $464 million and will cover the loss in full. That is a solid commitment only within the frame in which it is meant, and that frame differs fundamentally from what you know from your bank account.
Statutory deposit insurance in the European Union protects bank balances up to 100,000 euros per customer and institution. It rests on a directive, is supervised by the state, and applies whether or not the bank wants to pay. A crypto exchange's protection fund, by contrast, is a voluntary reserve held by the company. The company itself decides on payout, priority and amount. No statutory deposit insurance exists for crypto-assets in the EU, and MiCA does not create one.
This says nothing about Bitget's willingness to pay; it describes the nature of the instrument. A protection fund can absorb a loss in full, and funds in this industry have done so before. What you cannot do is rely on it the way you rely on a bank guarantee.

Self-custody and hardware wallets: when moving off an exchange account pays
Self-custody means you hold the private key to your coins yourself and nobody else can dispose of them. A hardware wallet is a small device that generates that key and keeps it permanently separated from your computer; transfers are confirmed on the device and the key never leaves it. The seed phrase is the sequence of words from which the key can be restored, and therefore the actual access to your assets.
The advantage is obvious: a break-in at an exchange does not reach holdings that sit on your own device. The downside is often underestimated. Self-custody comes with no recovery hotline. A lost or photographed seed means permanent loss, and in August 2026 a flaw in the key generation of certain offline devices showed that this route carries risks of its own.
A workable rule of thumb separates funds by purpose. Amounts you actively trade may sit at a regulated exchange, because you need to be able to act quickly there. Anything you intend to hold for months, and whose loss would hurt, belongs on your own hardware. If you are moving funds for the first time, read up in our hardware wallet comparison first and send a small test amount before you move the rest.
One element of diligence costs nothing and is regularly forgotten: write the seed phrase down by hand, keep it separate from the device, and never store it as a photo, a text file or in cloud storage. Total losses in self-custody rarely trace back to an attack on the device. Usually a copy of the seed existed somewhere that somebody else could reach.
Tax and the holding period: what a frozen balance means for your return
A withdrawal freeze is, for tax purposes, a non-event to begin with. As long as your coins sit in the account and merely cannot be moved, you have neither sold nor swapped, and no disposal has taken place. In Germany the one-year holding period under section 23 of the Income Tax Act keeps running during this time, because it attaches to acquisition and disposal, not to availability.
It looks different once a blocked balance turns into an actual loss. Whether and how a loss from stolen or no longer withdrawable crypto-assets can be claimed for tax has not been settled in Germany and depends on the individual case. The federal finance ministry did not take a clear position on theft losses in its guidance on crypto-assets. What follows for you is above all a duty to document on your own account: secure account statements, transaction lists and the provider's notices with dates while you still have access to your account.
If you already run a portfolio tool, record the event there as a separate item rather than keeping it in your head. Our overview of crypto tax software and portfolio trackers shows which programmes produce records in a form a tax office accepts. For larger amounts a tax adviser is the cheaper option, because a wrongly stated loss position triggers questions later.
September 2026 in the hack ledger: Liquid Network, Bitget and the year's total
The incident does not stand alone. On figures CryptoSlate compiles from DeFiLlama, losses from attacks in September 2026 already stood at roughly $342 million before the Bitget incident. With the loss now reported, the month adds up to more than $684 million, surpassing the previous high for the year set in April at $646.9 million.
The largest single item before that came in early September from the Liquid Network at around $320 million, where the attackers stated they had acted as white hats. Smaller incidents followed, among them an attack on a hot wallet belonging to the provider Duelbits worth about $7 million. For context, a monthly tally depends heavily on a few large individual cases, and no trend for the coming quarter can be read from it.
For judging your own risk, another observation is more useful anyway. The large losses of this year arose overwhelmingly where assets sat pooled with a single custodian. That holds for the orderly cases too: both the shutdown of BitMEX on September 23 and the announced closure of CoinEx at the end of the year put customers in the same position, having to pull balances under time pressure off a platform they could no longer choose. Bitcoin itself barely reacted to the news that evening; the market now treats a break-in at a single exchange as an event belonging to that exchange.
Checking the Bitget hack: what to take away
- Establish today whether you are affected, and document the position. Log in, note balances with date and time, save the transaction list and the provider's notices, and file the withdrawal request as soon as the function reopens. For the three trading pairs delisted on September 24, the withdrawal window closes on December 24, 2026. Keep the records in the form a tax office will later want to see — the tools for that are in our comparison of crypto tax software.
- Check the authorisation of every exchange you use. Find out which company in which country is liable for your account, and match it against the ESMA register. A provider without CASP authorisation may not serve you in the EEA, and in a dispute you have no European supervisor to turn to. The houses that have cleared this hurdle are in our overview of regulated crypto exchanges.
- Separate trading holdings from long-term holdings. What you move around may sit at the exchange; what you hold for months belongs on your own hardware, with the seed phrase written by hand and kept apart from the device, and a small test amount sent before the first large transfer. The devices and how they differ are in our hardware wallet comparison.
A final note that applies at the time of writing: Bitget reported the incident itself, quantified the loss and promised cover from its own protection fund. Whether withdrawals reopen quickly, and whether the promised root-cause report answers the open questions, could not be foreseen as this article went to press. Until then the sober rule this evening has confirmed again applies to you: a balance at an exchange is a claim against a company, and its worth depends on that company being able and permitted to pay.
(As of September 24, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- Crypto Exchange Protection Funds Recalculated: What Really Covers Your Balance After the Bitget Hack
- Crypto Exchange Shutting Down: What to Do Before the Deadline Passes
- Bitget Withdrawals Resume on September 28: What to Check on a Residual Balance Now
- ESMA puts reverse solicitation on its 2027 watch list: what investors need to know about exchanges without an EU licence
- Crypto Withdrawal to Your Own Wallet: Ten Providers Checked, Three Will Not Let Your Coins Out
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
May 18, 2026 8:15 AM

Bitget Review 2026: Is Bitget a Good Crypto Exchange? What You Need to Know
Explore the key insights and safety considerations of trading on Bitget. Make informed decisions before you start trading. Read the full review now!
July 2, 2026 8:59 PM

Binance Is Out of the EU: How to Move to a MiCA-Regulated Exchange
Binance has left the EU market. Which exchanges hold a MiCA licence, how to verify an authorisation is real, and how to move your holdings across step by step.
August 11, 2026 9:18 AM

Your Crypto Exchange Is Telling You to Withdraw: How to Spot Phishing After the MiCA Deadline
Unauthorised crypto providers now have to tell their EU customers to withdraw, which leaves fraudsters an easy run with faked requests. Here is how to check in two minutes whether the message is genuine.
September 29, 2026 7:12 PM

MEXC Refunds $340,000: The Attacker's API Key Survived the Account Freeze
During an account takeover at MEXC, an attacker created an API key with withdrawal rights that the exchange did not revoke when it restored the account. Twenty-seven minutes after the withdrawal freeze expired, roughly $340,000 was gone.
August 6, 2026 3:05 PM

MiCA Register 2026: Only 21 of 329 Licences Are Real Exchanges
ESMA publishes the register of MiCA-authorised providers as an open file. We worked through all of it — and the result is not what the phrase “licensed crypto exchange” suggests.
October 2, 2026 7:16 AM

$1.26 Billion in Three Months: Crypto Hacks Hit Their 2026 High
The security firm CertiK counts around $1.26 billion in damage from 247 incidents for the third quarter of 2026. September was the worst month of the year with 99 cases, and this is the background and what it means for your custody.
September 29, 2026 10:14 AM

387.5 million dollars at Bitget: the attack ran through a bought-in security product, what to watch now
Bitget has disclosed how the attackers reached its withdrawal systems on September 24: through a previously unknown flaw in a security product it had bought in. The second stage of the withdrawal schedule opens today at 08:00 UTC, and for the balance you keep on any exchange the case changes the arithmetic.
September 30, 2026 1:23 PM

NEAR Intents Blocks $50 Million From the Bitget Hack: Why THORChain Let the Swaps Through
A cross-chain protocol says it stopped more than $50 million in transfers from the Bitget attack and froze $503,000. The case shows who can halt funds in transit and what that means for your custody.
December 26, 2024 1:08 PM

BGB News: Bitget Token Reaches New ATH Amid Market Momentum
Bitget Token (BGB) defies the market downtrend, hitting a new ATH of $7.32. What's driving this 368% surge and what the future holds for this top-performing cryptocurrency?
September 4, 2026 4:39 AM

Source of Funds at a Crypto Exchange: Why a Deposit Can Freeze Your Account for 15 Days
OKX chief Star Xu described on September 2 what an unusual deposit sets off: reviews of 15 days and longer, during which balances and account functions can be restricted. What that means for investors in Germany, and which documents you should keep to hand.
August 21, 2026 4:17 PM

Crypto Withdrawals to Your Own Wallet: Why Exchanges Demand Proof of Address Ownership Above €1,000
Above €1,000 your provider has to establish whether the destination address really belongs to you. Article 14(5) of the transfer of funds regulation, five permitted methods, and the reason a withdrawal stalls without this step.
December 26, 2025 1:50 PM

Breaking: Trust Wallet Chrome Extension Hack Drains $7M, Full Reimbursements Promised
A supply-chain attack hit Trust Wallet’s Chrome extension, draining $7M from users. Binance’s CZ says all victims will be reimbursed.
September 30, 2026 5:03 PM

Bitget after the hack: withdrawals are back and the Protection Fund is above $300 million
Six days after the attack, Bitget is back with strong numbers: withdrawals for Bitcoin, Ether and USDT are running again, the Protection Fund was refilled two days ahead of its own deadline, and the proof of reserves shows 131 percent coverage.
August 13, 2026 4:59 PM

Trezor Data Breach: First 13,689 Customers, Then Roughly 67,000 More Exposed
A breach at Trezor shipping partner ShipMonk exposed names, phone numbers and home addresses of 13,689 customers in August; in September Trezor reported roughly 67,000 more in the US. Devices are safe, phishing risk is not.
September 29, 2026 10:28 PM

Customers Pull $463 Million From Bitget: The Consequences for Reserves and Custody
After the attack of September 24, customers pulled around $463 million out of Bitget within a day, the largest single-day outflow since DefiLlama began tracking reserves. The user protection fund fell from $464 million to below $200 million in the process.
September 25, 2026 7:11 AM

EU Supervisors Rate Quantum Risk as High: What to Check on Crypto Custody and Exchange Choice
EBA, EIOPA and ESMA name quantum computers explicitly as a threat to blockchain cryptography in their autumn risk picture of September 23. What the paper says, which migration deadlines run to 2030, and three things you can check about your custody.
August 21, 2026 1:13 AM

Proof of Reserves Explained: How to Check an Exchange Attestation Yourself
A proof of reserves shows that a crypto exchange controlled customer balances on a given reporting date. Here is how to recalculate your own holding in the Merkle tree, and why the attestation says nothing about solvency.
April 21, 2026 11:15 AM

Breaking: Arbitrum Security Council Freezes $71M in ETH Linked to KelpDAO Exploit
The Arbitrum Security Council has frozen 30,766 ETH tied to the KelpDAO hack, sparking a fierce debate over decentralization and emergency powers in DeFi.
September 13, 2026 4:33 AM

Your Volksbank's Crypto Licence: Why You Have to Check Custody Separately
14 of the 16 newest CASP entries in the ESMA register were German cooperative banks, and each one carries order execution only. Our count of the BaFin database shows that not one of the 21 cooperative institutions is registered as a crypto custodian.
September 7, 2026 7:26 PM

Stolen Keys Beat Code Flaws: Why the Private Key Is the Way In for 2026 Crypto Hacks
Compromised private keys overtook smart contract code flaws as the most common attack route for the first time in 2026. What sits behind the shift, and how to check your own setup for its single point of failure.
April 1, 2026 1:06 PM

Major Security Breach: Ethereum Blockchain "Hacked" Following 2026 Roadmap Update
Reports of a fundamental compromise of the Ethereum blockchain sent shockwaves through the DeFi ecosystem today, sparking a massive sell-off before the truth emerged.
September 24, 2026 10:11 PM

Bitcoin Price Prediction: What to Check on Levels, Holding Period and Leverage Before the October 28 Rate Decision
Bitcoin is trading at around $83,800, a third below its October 2025 high, while the sentiment index reads greed. Which dates, levels and deadlines over the coming weeks really decide your net gain, and which of them you steer yourself.
September 10, 2026 9:13 AM

Trezor Hack Scare: That STM32 Entropy Email Is a Phishing Attack
Trezor users received a fake STM32 entropy warning sent from a real Trezor address. Here is what happened and what to do if you clicked.
August 5, 2026 10:33 PM

$130 Million Gone Because the Randomness Was Predictable: Which Hardware Wallet You Can Still Buy
The Coldcard flaw proved the most respected wallet is not the safest. Which vendor has which track record – and why now is the wrong moment to pause your savings plan.
September 8, 2026 7:33 AM

Withdrawal Whitelist at the Crypto Exchange: How to Lock the Withdrawal Path Against Foreign Addresses
A withdrawal whitelist lets balances leave only to addresses approved in advance, and it works even when password and second factor are compromised. On September 8, 2026 we checked which of thirteen providers document the function publicly.
June 18, 2025 12:05 PM

BREAKING: Israeli-Linked Hackers Allegedly Wipe Out Nobitex Exchange
Nobitex, Iran’s top crypto exchange, has reportedly lost $48.65 million in a massive hack. Linked to Israeli cyber group Predatory Sparrow, the attack allegedly wiped out 95% of the platform’s assets.
September 27, 2026 4:20 PM

Bybit's Counterparty List Runs to Over 50 Names: What to Check on Balances, Withdrawals and Custody
Bybit has published a list of more than 50 platforms, services and organisations whose involvement can, under its own rules, lead to an account freeze. What decides the outcome is not your next trade but the payment history you already have.
More from CryptoTicker

