
Bitget Hack Drains $351.6M from hot and warm wallets as a fake Bitget Wallet account pushes a phishing-linked revoke approvals scam.
Author: Akshay
25th September 2026 – The Bitget Hack Drains roughly $351.6 million from Bitget Exchange hot and warm wallets on 24 September. Within minutes, a fake account tried to turn the panic into a phishing trap.
High Signal Summary For A Quick Glance
CryptoFish
@Mafisher70
@WatcherGuru I hope that’s the exchange where members of Congress who didnt vote for the Clarity Act keep their crypto! @SenatorCollins @lisamurkowski @HawleyMO
Bitget says ~$351.6 million was drained from some of its hot wallets and that its cold wallets remain secure. The exchange also said user funds are safe and the full loss is covered by its "User Protection Fund," which holds ~$464 million for incidents like these. Withdrawals
05:24 AM·Sep 25, 2026
Kunjukunju
@Kunjukunju1718
@WatcherGuru Hot wallet exploits are a reminder of central risk. Having a clear insurance fund helps, but transparency on the security review gives users a real VOICE in these moments.
Bitget says ~$351.6 million was drained from some of its hot wallets and that its cold wallets remain secure. The exchange also said user funds are safe and the full loss is covered by its "User Protection Fund," which holds ~$464 million for incidents like these. Withdrawals
04:18 AM·Sep 25, 2026
High attention and emotional sentiment detected.
Two separate things happened that night, and mixing them up is exactly how the scam worked. One was a real breach of Bitget’s custodial exchange wallets. The other was a lookalike X account posing as Bitget Wallet.
Bitget CEO Gracy Chen said the exchange’s security systems detected unauthorized transfers at 18:31 UTC on 24 September. According to her official notice, the affected total came to about $351.6 million.
The breach struck Bitget Exchange, the custodial platform, not the self-custodial Bitget Wallet app. That distinction matters, because the two share a brand but hold funds very differently.
Chen said only a portion of the hot and warm wallet layers were touched. She added that cold wallets remain fully secure. So the damage, while large, stayed inside the exchange’s online custody tiers.
The drained assets spanned several chains. They included ETH, XRP, USDT, USDC, AVAX, BNB, and USDT0. The flows crossed Ethereum, the XRP Ledger, Avalanche, BNB Chain, and Arbitrum.
Bitget also said the loss falls within its User Protection Fund, which it claims holds more than $464 million. In other words, the roughly $351.6 million hole sits at about 76% of that declared fund. Still, withdrawals were paused while deposits and trading stayed open.
About twelve minutes after Chen’s notice, an account called @BitgetWalletApp posted an emergency message. It told users to temporarily revoke approvals for its contracts and ended with a “Learn more” link.
That account is not the official Bitget Wallet handle. The real one is @BitgetWallet, which carries roughly 2.88 million followers. The impersonator had about 6,000 followers, yet its post still reached around 202,000 views.
The scammer copied the wallet’s Instagram handle, its emoji, and its “100M users” bio. As a result, the post looked convincing. Some aggregators even repeated the revoke line as if it were official guidance.
Then the real account stepped in. At 02:06 UTC on 25 September, Bitget Wallet posted a blunt correction: “BITGET WALLET IS NOT AFFECTED.” It also urged users to watch for phishing and impersonation.
On-chain watchers spotted the outflows before any official word. Blockchain security firm PeckShield first flagged a potential hot-wallet hack above $178 million.
Analytics platform Bubblemaps then tracked about $180 million flowing across multiple chains to a single address. Etherscan tagged that wallet as “Bitget Exploiter 1.” The consolidation address sits at 0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee.
Early on-chain estimates ranged from roughly $145 million to $192 million, well below the official figure. The gap narrowed once Lookonchain published a fuller token breakdown that added about 102.93 million XRP, worth around $157 million.
According to Lookonchain, the attacker then swapped most of the EVM loot into roughly 67,982 ETH. That flow pushed value into ETH, but it was not an attack on any Ethereum protocol.
Bitget’s September 24–25 incident began with on-chain outflows before official alerts, followed by a fake wallet account impersonating Bitget.
A 0.84 ETH probe transfer moves from a Bitget-labeled wallet to the later identified exploiter address.
Large amounts of USDT, USDC, XAUT, ETH and XRP move from Bitget-labeled wallets.
Arkham, PeckShield and Bubblemaps publicly flag the suspected compromise and track rising losses.
Gracy Chen confirms the incident, says cold wallets are safe and withdrawals are paused.
An impersonator posts a “revoke approvals” message. It is not an official Bitget Wallet statement.
Chen says spoofed transaction data entered Bitget’s signing path and that private keys were not compromised.
The official Bitget Wallet account warns users about impersonation and says Bitget Wallet was not affected.
Bitget’s full incident report and withdrawal reopening remain pending.
Chen offered a working explanation in a follow-up post at 00:43 UTC on 25 September. She said attackers compromised a critical backend system inside the wallet infrastructure.
From there, she said, they spoofed transaction data and triggered Bitget’s own authorization process to move funds out. In short, the story points to privileged internal-system abuse rather than a leaked private key.
Chen also said private-key compromise has been ruled out, and that no further unauthorized transfers are possible. The exact intrusion path, however, is still under investigation.
An approval is a permission slip. When you use a decentralized exchange or bridge, you sign a transaction. That signature lets a contract pull a set amount of your tokens.
Revoking that permission helps if a specific contract you already approved was compromised. Yet it does nothing when an exchange hot wallet is emptied from the inside, which is what Bitget describes here.
For that reason, a mass “revoke our contracts” blast from an unknown account is a classic drainer tactic. Clicking a panic link can prompt you to sign a fresh malicious approval instead. Bitget Wallet says users should only follow updates from its official channels. This article is not financial advice.
Several questions are still open. Bitget has not detailed exactly how the backend was breached, whether through malware, a vendor, or leaked admin credentials.
There is also no official count of drained customer accounts. So far there is no confirmed timeline for reopening withdrawals either. Claims of state-linked hacking groups remain speculation that Bitget has not confirmed.
Meanwhile, the market reacted fast. Bitget’s BGB token slid roughly 6% as the reports spread, trading near $1.96. That drop shows how quickly confidence can wobble even when spot books stay open.
Bloomberg, The Block, and CoinDesk have all confirmed the $351.6 million figure and the withdrawal halt. Bitget has promised a full incident report. The clearest test now is whether its protection fund actually covers users.
Our Crypto Talk is committed to unbiased, transparent, and true reporting to the best of our knowledge. This news article aims to provide accurate information in a timely manner. However, we advise the readers to verify facts independently and consult a professional before making any decisions based on the content since our sources could be wrong too. Check our Terms and conditions for more info.
Bitget Hack Drains $351.6M, Fake Account Targets Users
DCENT Wallet Users Urged to Move Funds After Alert
rsETH Exploit Drains $7.73M From Ethereum Safe Wallet
Huma Warns of Phishing Scam Using Fake Claim Portal
Bitget Hack Drains $351.6M, Fake Account Targets Users
DCENT Wallet Users Urged to Move Funds After Alert
rsETH Exploit Drains $7.73M From Ethereum Safe Wallet
Huma Warns of Phishing Scam Using Fake Claim Portal