Crypto Exchange Protection Funds Recalculated: What Really Covers Your Balance After the Bitget Hack
The $351.6 million attack on Bitget would eat up three quarters of the exchange's in-house protection fund. We retrieved the protection promises of several exchanges ourselves and measured them against deposit insurance and MiCA liability.

Table of Contents
Table of Contents



Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
When a crypto exchange loses money, no government steps in. What protects your balance there is first a voluntary promise by the exchange, and second a liability rule from the European crypto regulation. The exchange can change the first one tomorrow; the second applies only if the exchange is authorised. The attack on Bitget during the night leading into September 25, 2026 is putting both on display.
So rather than rewrite what is being reported about the incident, we retrieved the protection promises ourselves and ran the numbers. This analysis was compiled by cryptoticker.io on September 25, 2026. The finding in one sentence: the largest in-house protection fund in the industry covers the damage from this single incident only 1.32 times over, and it is held in exactly the currency that falls along with the market in a crisis.
The Bitget hack of September 24, 2026: $351.6 million and suspended withdrawals
The exchange Bitget has confirmed that around $351.6 million flowed out of its hot and warm wallets on September 24, 2026. The company gives 18:31 UTC as the time of detection. According to chief executive Gracy Chen, no private keys were compromised; the attackers are said to have taken over a wallet backend, faked transaction data and thereby triggered the internal approval process. Withdrawals have been suspended since then, and the company describes its cold holdings as untouched. Chen has publicly voiced the suspicion that North Korean attackers were behind it, pointing to IP traces.
A hot wallet is a wallet whose keys sit on a system connected to the internet, so that withdrawals can run automatically. A warm wallet sits in between: it is not permanently online, but it is faster to reach than cold storage. Exchanges keep only a fraction of customer holdings there. That fraction is precisely what was hit here.
For you as a customer, the interesting question is not how the attack worked technically. It is this: who replaces the money when an exchange loses it, and what is that claim based on?
What a crypto exchange protection fund is, and what it is not in legal terms
A protection fund, often called an insurance fund or a safety fund, is a stock of coins that an exchange sets aside to compensate customers in a platform-wide loss event. It is a self-imposed commitment, not a statutory protection scheme. Nobody audits it, nobody prescribes its size, and no authority pays out when it is empty.
This is where retail investors regularly mix something up. Anyone coming from a current account knows deposit insurance up to 100,000 euros and mentally transfers it to the exchange account. That transfer does not hold, for a reason written into the statute and set out further below.
How robust such a fund is comes down to three figures: its size measured against a realistic loss event, the currency it is held in, and the conditions under which it pays out. The first two can be calculated. The third sits in the exchange's fine print.
Our analysis: 5,500 bitcoin in the protection fund, valued at the September 25 price
The public fund page puts the holding at 5,500 BTC and carries that figure in the page title as well. The value shown next to it read "The fund is currently valued at $0" at the time of our retrieval, plainly a display error on the page, since the holding itself is quantified in the same line. For valuation, the page refers to the opening price at 2:00 (UTC+2) of the respective day.
Because the page does not output the dollar value, we derived it ourselves. The bitcoin price stood at $84,462.
- Fund value today: 5,500 BTC times $84,462 comes to roughly $464.5 million. That matches the $464 million the chief executive has cited publicly and confirms the composition.
- Share taken by this one loss: $351.6 million out of $464.5 million is 75.7 percent of the fund.
- What would be left on paper: around $112.9 million, or about 1,337 BTC.
- Coverage ratio: 1.32 times the loss. A second incident of this magnitude would no longer be covered.
These figures are not a forecast and say nothing about the solvency of the company, which by its own account is bearing the loss in full and describes customer balances as correct. They describe only how much buffer the publicly stated protection promise has left after this single event.

The design flaw: a bitcoin protection fund shrinks when it is needed
The second finding of our calculation weighs heavier than the first. The fund is held in bitcoin, so its protective value swings with the price. At the time of our retrieval, bitcoin was trading 33.0 percent below its record high of $126,080 set on October 6, 2025.
The same holding of 5,500 BTC would have been worth around $693.4 million at that record. Today it is $464.5 million. The protective effect has shrunk by roughly $228.9 million without a single coin leaving the fund.
This is systematic and affects every exchange that holds its insurance fund in cryptocurrencies. Loss events cluster in turbulent market phases, and turbulent market phases are exactly when such a fund is worth least. Our calculation also shows where the limit sits: below a bitcoin price of around $63,900, 5,500 BTC would no longer have covered the September 24 loss. That price level has already been within reach this year.
Anyone picking an exchange by its protection fund should therefore never read the holding in dollars, but in coins, and hold it against a realistic loss event. Which providers disclose their safeguards, and how they are supervised, can be checked before opening an account.
Regulated crypto exchanges comparedDeposit insurance up to 100,000 euros: why the German deposit guarantee act does not cover crypto assets
Statutory deposit insurance is the benchmark almost everyone carries in their head. In Germany it sits in the Einlagensicherungsgesetz, EinSiG for short. Under section 2(3) EinSiG, deposits are "credit balances, including fixed-term and savings deposits" that arise from amounts held in an account and "are repayable by the CRR credit institution under the applicable statutory and contractual terms". The coverage limit under section 8(1) EinSiG is 100,000 euros per depositor.
Two features of that definition rule out your exchange account. First, a CRR credit institution has to stand behind it, meaning a bank with the corresponding licence. A crypto exchange is generally not one. Second, the subject is money balances repayable at face value. Bitcoin, ether and solana are not money balances and have no face value.
In practice that means: if you hold euros in a settlement account run by a licensed partner bank, deposit insurance can apply to that euro amount. It does not apply to the coins sitting beside it, not even pro rata. This is not a gap somebody forgot to close, it is how the statute is built.
MiCA Article 75: the liability an authorised crypto exchange cannot contract away
Since the European regulation on markets in crypto-assets came into force, something else has taken the place of deposit insurance, and it is often overlooked in practice: a direct liability on the part of the custodian.
Article 75(7) MiCA requires crypto-asset service providers to segregate client holdings from their own and to keep them legally separate from their own assets. Paragraph 8 goes further: the provider is liable to its clients for the loss of crypto-assets or of the means of access to them where the incident is attributable to the provider. That liability is capped at the market value of the lost crypto-asset at the time of the loss. Excluded are events where the provider demonstrates that they occurred independently of its service, such as disruptions of the underlying blockchain itself.
The decisive difference from a protection fund: this liability is not a goodwill gesture. An authorised custodian cannot limit it towards clients through its terms and conditions where the loss goes back to operational incidents, malfunctions or attacks connected to its service. An attack that runs through the provider's own wallet backend, as in the Bitget case, falls squarely within the provider's sphere of responsibility on this reading.
What counts as custody was described by BaFin in its guidance note on crypto-asset services under MiCAR of January 3, 2025: the safekeeping or control of crypto-assets, or of the means of access to them, on behalf of clients, Article 3(1)(17) MiCAR. Which obligations this brings for providers is something we have broken down in our overview of the MiCA licensing duties.

Bitget and MiCA authorisation: what the pending application means for customers in Germany
That liability hangs on a single word: authorised. It applies to providers that hold an authorisation as a crypto-asset service provider in the EU and therefore fall under the supervision of a European authority.
According to its own announcement of July 2, 2026, Bitget has filed an application for authorisation under MiCAR with the Austrian financial market authority through its Bitget EU entity. The company itself writes there that it intends to offer crypto-asset services in the EU "once the required authorisation has been granted and all applicable regulatory steps have been completed", and points out that the timing, scope and outcome of the procedure are subject to assessment by the authority. For existing customers of the global offering, that announcement states, the previous contractual and legal arrangements continue to apply.
What follows for you is a sober reading, and one that implies no accusation against the company: as long as an authorisation is pending, your claim in a loss event rests on a contract with an entity outside the European supervisory framework and on the voluntary fund promise. The non-waivable liability under Article 75 MiCA and access to a European supervisory authority only come with the authorisation. That is the practical difference between an authorised and a non-authorised trading venue, and it only shows once something has gone wrong.
Proof of reserves and 1:1 backing: what other exchanges' attestations show and what they do not
For context, we retrieved the security disclosures of two further providers available to German investors on the same reference date. Both take a different approach to the loss-fund model.
Kraken publishes proof of reserves using the Merkle tree method, reviewed by an independent third party. The coverage ratios shown on the page stood, as of the June 30, 2026 reference date, at 102.9 percent for bitcoin, 100.5 percent for ether, 100.6 percent for solana, 102.3 percent for XRP and 100.3 percent for cardano; for the stablecoins named there, above 105 percent. No loss fund or insurance for customer holdings is mentioned on that page.
Bitpanda cites on its security page a legally binding separation between its own assets and those of its customers, physical 1:1 backing of all user holdings, cold storage and a commitment not to speculate with customer funds. Here too there is no protection fund and no reference to deposit insurance for crypto assets.
What proof of reserves delivers is narrowly bounded, and that belongs in the picture. It shows that the holdings existed on a given date. It says nothing about whether they are encumbered by liabilities, and it replaces no compensation if they are stolen later. The gap is worth noting: the most recent attestation shown on the page was 87 days old on the day of our survey.
Hardware wallets comparedProtection fund or self-custody: the buying route under MiCA and the holding period
No blanket recommendation to pull coins off the exchange follows from these findings. What follows is a split by purpose.
Amounts you actively trade belong on a trading venue, and there the supervisory question is the more important one: does the provider hold a MiCA authorisation, and which authority supervises it? Holdings you intend to keep for longer are exposed to no exchange risk at all on your own hardware wallet. There, however, nobody is liable for you any more either: a lost recovery phrase is lost for good, and Article 75 MiCA does not help, because no custodian is involved.
What the move triggers for tax, and what it does not
One important point, because it is often misunderstood: merely moving your own coins from an exchange to your own wallet is not a taxable event. You are not disposing of anything, you are only changing where it is kept, and the one-year holding period under section 23 of the German income tax act keeps running unchanged. Tax becomes relevant on a sale and on a swap into another cryptocurrency.
In practice that means you have to carry your acquisition data with you. Anyone spreading holdings across several platforms easily loses track of the acquisition date and acquisition cost per lot, and those are exactly what the tax office will want later. Clean documentation is easiest with a tax and portfolio tool that consolidates deposits and withdrawals across platforms. For larger holdings and for borderline questions, that is no substitute for tax advice.
Markers and thresholds: how to measure whether a protection promise holds
So that you do not have to think this through afresh with every provider, here are the checkpoints that came out of our survey.
- Authorisation before fund. Check first whether the provider holds a MiCA authorisation and which authority supervises it. Only then does the non-waivable liability under Article 75 apply. A fund without authorisation is a promise, not a claim.
- Read the fund size in coins, not in dollars. The dollar figure on a provider page is a snapshot of the price. The holding in BTC or ETH is the figure that can be compared.
- Calculate against a realistic loss. Set the fund size against an incident of the magnitude this industry has actually seen. A coverage ratio near 1 is not a buffer.
- Read the payout conditions. Bitget's fund page, for instance, explicitly names platform-wide events as a precondition and reserves the right to review each individual claim. An individual account loss is evidently not covered.
- Check the age of the proof of reserves. A reference date months in the past says little about the situation today.
- Treat euro balances separately. Deposit insurance only comes into consideration for money amounts held at a licensed partner bank.
Method of our survey: six objects, one reference date, three open points
The survey date is September 25, 2026, and all retrievals took place between 12:50 and 13:05 UTC. Six objects were checked: Bitget's public fund page, the same provider's MiCAR announcement, Kraken's proof-of-reserves page, Bitpanda's security page, sections 2 and 8 of the German deposit guarantee act, and BaFin's guidance note on crypto-asset services under MiCAR. The market data comes from a separate retrieval at 12:50 UTC. Method: retrieval of the disclosures in the original, followed by our own conversion of the coin holding into dollars at the spot price and a cross-calculation against the reported loss amount.
Three things remain open. First, the fund's coin holding could not be counted independently on the blockchain; the fund page does link a wallet, but counting the address ourselves was not possible within this survey. The 5,500 BTC are therefore a figure stated by the provider, which we report, not a quantity we counted. Second, the loss amount of $351.6 million is a company statement that had not been conclusively confirmed externally at the time of our retrieval. Third, the full text of the MiCA regulation was not retrievable from our environment; the account of Article 75 rests on a generally available version of the regulatory text and on the BaFin guidance note for the definition of the custody service.
Checking a protection fund: what to take away
- Check today which supervisor your trading venue sits under. Look on your provider's site for the authorisation, the supervisory authority and the registered seat of the entity you have the contract with. If you find a pending procedure rather than a granted licence, you know that liability under Article 75 does not apply yet. A sorted starting point is the overview of regulated crypto exchanges.
- Run the numbers on your provider's protection fund once yourself. Take the stated coin holding, multiply it by today's price and hold the result against a loss in the order of $350 million. If the coverage ratio is near 1, the fund is a signal and not a safety net. How the major trading venues compare on fees, supervision and custody is shown in our comparison of the best crypto exchanges.
- Separate your trading balance from your long-term balance. What you are not moving in the next few weeks does not belong on an exchange account. Moving it to your own hardware wallet triggers no tax and does not interrupt the holding period; store the recovery phrase separately from the device and note the acquisition date and acquisition cost for each lot.
(As of September 25, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- Bitget Hack of $351 Million: What to Check at Your Crypto Exchange Now
- Customers Pull $463 Million From Bitget: The Consequences for Reserves and Custody
- Bitget after the hack: withdrawals are back and the Protection Fund is above $300 million
- 387.5 million dollars at Bitget: the attack ran through a bought-in security product, what to watch now
- Bitget Review 2026: Is Bitget a Good Crypto Exchange? What You Need to Know
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
September 30, 2026 10:24 PM

$766 Million Lost to Crypto Hacks in One Month: What It Means for Your Custody
CertiK counts around $766.4 million in damage for September 2026, the highest monthly figure of the year. Two incidents carry more than 92 percent of it, and both hit a place where your balance could be sitting too.
September 8, 2026 7:23 AM

Compensation After an Exchange Hack: What Twelve Crypto Providers Really Promise German Customers
After $322 million in losses in a single September week, the question is who replaces stolen coins. On September 8, 2026 we retrieved the security and legal pages of twelve providers and evaluated what is promised there.
September 4, 2026 4:39 AM

Source of Funds at a Crypto Exchange: Why a Deposit Can Freeze Your Account for 15 Days
OKX chief Star Xu described on September 2 what an unusual deposit sets off: reviews of 15 days and longer, during which balances and account functions can be restricted. What that means for investors in Germany, and which documents you should keep to hand.
September 26, 2026 4:14 PM

Bitget Withdrawals Resume on September 28: What to Check on a Residual Balance Now
Bitget is releasing the withdrawals frozen after the September 24 incident in four stages from September 28. For a residual balance held from Germany that is a deadline, not a reason to wait.
August 21, 2026 1:13 AM

Proof of Reserves Explained: How to Check an Exchange Attestation Yourself
A proof of reserves shows that a crypto exchange controlled customer balances on a given reporting date. Here is how to recalculate your own holding in the Merkle tree, and why the attestation says nothing about solvency.
August 21, 2026 4:14 AM

Euro Deposit to a Crypto Exchange Rejected: Why the Transfer Fails and What You Can Do
Since October 9, 2025 your payment service provider matches the payee name against the IBAN on every euro transfer. On deposits to an exchange account that is precisely where the payment most often comes to a halt.
September 29, 2026 7:12 PM

MEXC Refunds $340,000: The Attacker's API Key Survived the Account Freeze
During an account takeover at MEXC, an attacker created an API key with withdrawal rights that the exchange did not revoke when it restored the account. Twenty-seven minutes after the withdrawal freeze expired, roughly $340,000 was gone.
September 16, 2026 1:28 PM

Crypto Withdrawal to Your Own Wallet: Ten Providers Checked, Three Will Not Let Your Coins Out
Seven of ten providers available in Germany offer a payout to a wallet address you control yourself; three do not. Our survey of September 16, 2026, shows how to spot the difference before you buy, and why the question matters right now.
September 22, 2026 1:12 PM

Buying Bitcoin With PayPal in Germany: What Really Works and What It Costs
PayPal runs no crypto service of its own in Germany, but it works as a deposit route at regulated exchanges. What the detour costs, which withdrawal hold follows it and why buyer protection does not apply here.
December 26, 2024 1:08 PM

BGB News: Bitget Token Reaches New ATH Amid Market Momentum
Bitget Token (BGB) defies the market downtrend, hitting a new ATH of $7.32. What's driving this 368% surge and what the future holds for this top-performing cryptocurrency?
October 1, 2026 4:21 AM

Velocity Replaces Drift After the 285 Million Dollar Hack: What Changes for Investors in Germany
The Solana perp DEX Drift is back as Velocity, and since September 29, 2026 a new team has been running it. What the overhaul after the outflow of 285 million dollars means for your deposits, for settlement in USDT and for the legal position in Germany.
September 29, 2026 10:33 AM

ESMA puts reverse solicitation on its 2027 watch list: what investors need to know about exchanges without an EU licence
ESMA presented its work programme for 2027 on September 28, 2026 and made reverse solicitation a supervisory priority. What that means if your coins sit with a provider without EU authorisation, and which three steps make sense now.
August 21, 2026 4:17 PM

Crypto Withdrawals to Your Own Wallet: Why Exchanges Demand Proof of Address Ownership Above €1,000
Above €1,000 your provider has to establish whether the destination address really belongs to you. Article 14(5) of the transfer of funds regulation, five permitted methods, and the reason a withdrawal stalls without this step.
August 21, 2026 10:27 AM

Complaining About a Crypto Exchange: the Deadlines Article 71 MiCAR Sets and Why BaFin Will Not Decide Your Case
Authorised crypto providers have to run a formal complaints procedure, and Delegated Regulation (EU) 2025/294 sets a hard limit of two months for it. Our own analysis of the ESMA list shows at the same time that no complaints link is on file for Germany to this day.
September 19, 2026 7:17 AM

Chainlink Jumps Above $12: What LINK Holders Should Check Now
Chainlink trades at $12.34, 7.4 percent higher than yesterday. What part of the move is the broad market rally, what Chainlink itself contributes, and the three things you should check as a LINK holder.
August 21, 2026 7:38 AM

Crypto Exchange Insolvency: When Your Coins Can Be Segregated and When They Fall Into the Estate
If a custodian goes under, neither the deposit guarantee nor investor compensation covers crypto-assets. Whether the holdings are still yours is decided by the right of segregation under Section 47 of the German Insolvency Code, and you can read up on the condition for it beforehand.
February 18, 2024 11:00 PM

OKX Continues to Impress with its Transparent Growth
Dive into OKX's latest move in enhancing transparency with their 11th PoR report, showcasing a notable growth in their crypto assets. Discover how OKX is setting new standards in the crypto industry.
May 26, 2025 11:00 PM

Inside Bitget: How COO Vugar Usi Zade Is Shaping the Future of Crypto Trading
From Bitget Seed and AI-powered tools to regulatory strategy and mass adoption, COO Vugar Usi Zade reveals how Bitget is building the next era of crypto trading.
July 2, 2026 8:59 PM

Binance Is Out of the EU: How to Move to a MiCA-Regulated Exchange
Binance has left the EU market. Which exchanges hold a MiCA licence, how to verify an authorisation is real, and how to move your holdings across step by step.
September 30, 2026 1:23 PM

NEAR Intents Blocks $50 Million From the Bitget Hack: Why THORChain Let the Swaps Through
A cross-chain protocol says it stopped more than $50 million in transfers from the Bitget attack and froze $503,000. The case shows who can halt funds in transit and what that means for your custody.
September 27, 2026 4:32 AM

Hester Peirce Leaves the SEC: What Now Applies to Your Custody in Germany
The most crypto-friendly voice at the US securities regulator goes on October 2, 2026, and the commission shrinks to two members. For investors in Germany it is still the European rulebook that decides, and there a deadline falls in July 2027.
April 1, 2026 1:06 PM

Major Security Breach: Ethereum Blockchain "Hacked" Following 2026 Roadmap Update
Reports of a fundamental compromise of the Ethereum blockchain sent shockwaves through the DeFi ecosystem today, sparking a massive sell-off before the truth emerged.
July 12, 2024 7:00 AM

Animoca Token Is LIVE: How To Buy MOCA On Bitget?
Here is how the new MOCA token, launched by Animoca Brands and Moca Network is set to revolutionize the Web3 landscape with its unique utilities.
June 18, 2025 12:05 PM

BREAKING: Israeli-Linked Hackers Allegedly Wipe Out Nobitex Exchange
Nobitex, Iran’s top crypto exchange, has reportedly lost $48.65 million in a massive hack. Linked to Israeli cyber group Predatory Sparrow, the attack allegedly wiped out 95% of the platform’s assets.
August 11, 2026 9:18 AM

Your Crypto Exchange Is Telling You to Withdraw: How to Spot Phishing After the MiCA Deadline
Unauthorised crypto providers now have to tell their EU customers to withdraw, which leaves fraudsters an easy run with faked requests. Here is how to check in two minutes whether the message is genuine.
More from CryptoTicker


