SimpleSwap Blog

Bitget Hack: $351.6M Hot-Wallet Breach Puts Custody Back in Focus Use

hack

Bitget detected unauthorized transfers from some of its hot wallets at 18:31 UTC on September 24, 2026, and estimates the affected assets at about $351.6 million. That is roughly double the $170 million to $183 million that on-chain analysts counted in the first hours. Withdrawals are paused. Deposits and trading continue, according to Bitget, which says its User Protection Fund, valued by the exchange at more than $464 million and holding 5,500 BTC, will cover the loss. The part worth a longer look is structural: where the single point of failure sits for anyone who keeps a balance on a platform. All figures are as of September 25, 2026.

What happened at Bitget

Bitget CEO Gracy Chen posted the first security notice on X at about 21:30 UTC on September 24. On-chain records reviewed by Forbes place the first outflow, a small test send from a wallet labeled "Bitget 6", at 18:31:11 UTC, with a final transfer at 21:23:11 UTC. Before Bitget spoke, on-chain data cited by The Block and an Arkham Intelligence analyst showed more than $170 million leaving Bitget-labeled wallets, and Decrypt later reported about $183 million. Most early dashboards missed the XRP Ledger. Lookonchain's asset breakdown lists 102.93 million XRP, worth about $157.5 million, as the largest single component and puts the total near $356.9 million at its own prices.

According to Chen, the attacker compromised a backend system inside Bitget's wallet infrastructure and used it to spoof transfer data, which pushed 19 transfers through the exchange's own authorization process. She said private key compromise has been ruled out and cold wallets were not affected. In her description, the breach touched only part of the hot and warm wallet layers. Seven networks were named, including the XRP Ledger and Ethereum. In a livestream, Chen said some IP addresses matched VPN services previously used by a North Korean group, and stressed that this attribution is not confirmed.

Bitget has said the loss will be covered from the fund and that the fund will then be replenished. At the time of writing on September 25, withdrawals had not reopened. Bitget said it would restore them once the affected systems had been checked and gave no date. The full incident report had not been published.

What a hot-wallet compromise means for a platform balance

A balance on an exchange is a row in the exchange's database. The coins behind that row sit in wallets the exchange controls, some of them online so withdrawals can clear quickly. When those online wallets are drained, the row usually stays correct, and Bitget says its users' balances are accurate. What changes is access. The platform decides when withdrawals reopen, and until it does, a correct balance cannot be moved.

The User Protection Fund is Bitget's answer to that gap, and the exchange has committed it to this loss. It is still a promise made after the event by the company that held the assets. Its dollar value also moves with bitcoin: Bitget's own August 2026 report shows the fund ranging from $345.3 million to $441.5 million within that month. None of this changes the custody structure. A user's claim remains a claim on a company.

A pattern that repeats across cycles

Mt. Gox halted bitcoin withdrawals on February 7, 2014, and filed for bankruptcy protection at the Tokyo District Court on February 28, disclosing that about 850,000 BTC were missing. Bitfinex lost about 120,000 BTC on August 2, 2016, and spread the loss across all customer accounts with a 36% reduction. FTX filed for bankruptcy on November 11, 2022, and within 24 hours Elliptic tracked more than $663 million leaving its wallets, about $477 million of it in what Elliptic treats as suspected theft. On February 21, 2025, Bybit lost about $1.5 billion in ether, a theft the FBI attributed to North Korean activity it calls "TraderTraitor" in a public service announcement on February 26, 2025.

Bitget's case differs from these in scale and in response, and the exchange reports a fund larger than the loss. The user-side mechanics are the same in every case: while a platform holds the coins, a decision by that platform determines when customers can move them, and on what terms. The pace has not slowed. In a December 18, 2025 report, Chainalysis counted more than $3.4 billion stolen across the industry from January to early December 2025, with $2.02 billion of it attributed to North Korean hackers. In a July 1, 2026 report, TRM Labs recorded $972 million across 207 hacks in the first half of 2026, a record number of incidents for a six-month period in its data, even as dollar losses fell.

What self-custody changes

In self-custody, the keys sit in a hardware or software wallet you control. An exchange's hot wallet or balance sheet has no bearing on coins that were never deposited there. That is the structural point: if you keep no long-term balance on a platform, that platform's wallet security drops out of your risk. When you need to swap, your exposure to the service narrows to a single transaction, from the moment you send funds until the output lands in your wallet.

What self-custody does not remove?

Self-custody hands the remaining risks to the user. Blockchain transactions are irreversible, so pasting an address with a single wrong character or depositing on the wrong network can send funds to a destination from which they cannot be recovered. The seed phrase is the wallet: whoever holds it controls the funds, and losing it without a backup ends access. Phishing is the other constant. Within hours of the Bitget breach, Forbes reported that fake tokens and lookalike addresses were used to imitate the attacker's transfers, a technique called address poisoning. Clone sites that copy swap services work the same way. This is shared responsibility. Good tools reduce mistakes, and the final check before sending is the sender's responsibility. The SimpleSwap Safety Academy covers these checks in more detail.

Where a self-custodial swap aggregator fits

SimpleSwap is a self-custodial swap aggregator that has operated since 2018. Funds move from a wallet you own to a wallet you own, and SimpleSwap does not hold long-term user balances. It aggregates liquidity from 20+ CEX and DEX providers across 2,800+ assets. No account is needed for most crypto-to-crypto swaps, though KYC may be required for transaction security and compliance, and the service applies risk-based checks and transaction screening. A fixed rate locks the price for 20 minutes, while a floating rate settles at execution. Each swap gets an order ID with real-time tracking, and support is available 24/7 with an average response time of 4 minutes. The fee starts from 0.2% and is bundled into the quoted rate, with network fees going to the blockchain. The service is subject to jurisdictional restrictions set out in its Terms, and decisions and transaction risks sit with the user.

"An exchange hot wallet exists so withdrawals clear quickly, which means some signing path has to stay online and reachable. That path is what attackers go after. We built SimpleSwap's routing so that each order is matched against CEX and DEX liquidity and settled directly to the user-specified address. With no standing user balance on our side, the engineering effort goes into routing accuracy and settlement."

Stefan Lauer, Head of Infrastructure, SimpleSwap

FAQ

Is SimpleSwap safe from exchange hacks like Bitget's?

SimpleSwap does not keep long-term user balances, so there is no stored balance of yours on the service for an exchange-style breach to reach. Funds pass through one order at a time. The risks that remain in any swap (a wrong address, a wrong network, a leaked seed phrase, a clone site) sit with the user.

Is SimpleSwap legit?

SimpleSwap has operated at simpleswap.io since 2018 and has processed 20M+ swaps. Its swap engine is integrated into 6,000+ partner products, including Exodus and Tangem, and it held a 4.1 TrustScore on Trustpilot across 2,500+ reviews in mid-2026. For a SimpleSwap review, recent user feedback is a reasonable place to start. Searches for "Simple Swap" can surface lookalike sites; the only official domain is simpleswap.io.

What can go wrong in a self-custodial swap?

Most problems stem from four sources: an incorrect recipient address, the wrong network, an exposed seed phrase, and clone sites. Transactions are irreversible, so check the details before sending; then use the order ID to track the swap and contact support if it stalls.

This article is for educational purposes only and is not financial or investment advice. Crypto involves risk, including the possible loss of funds. SimpleSwap's only official domain is simpleswap.io.

 

How do you rate this article?

5


SimpleSwap
SimpleSwap Verified Member

SimpleSwap is a self-custodial multi-source swap aggregator that helps users exchange crypto wallet-to-wallet with more privacy and control. It supports swaps across 20+ liquidity providers and 2,800+ assets, combining CEX and DEX liquidity under the hood


SimpleSwap Blog
SimpleSwap Blog

SimpleSwap is a self-custodial multi-source swap aggregator that helps users exchange crypto with more privacy and control, without comparing providers and routes themselves. It supports direct wallet-to-wallet swaps across 20+ liquidity providers and 2,800+ swappable assets, combining liquidity from well-known CEX and DEX sources under the hood.

Publish0x

Send a $0.01 microtip in crypto to the author, and earn yourself as you read!

20% to author / 80% to me.
We pay the tips from our rewards pool.

Page not displaying correctly?