Binance Joins Bitget Recovery Effort After $351.6 Million Wallet Breach
Cryptocurrency trading is speculative and your capital is at risk when you trade. We may earn affiliate commissions from some of the products on this page - at no extra cost to you.

Highlights:
- Binance is helping Bitget trace stolen funds after a $351.6 million hot wallet security incident.
- Bitget says private keys and cold wallets stayed secure, while withdrawals remain temporarily paused for checks.
- The exchange says its $464 million protection fund covers losses as Mandiant and SlowMist investigate.
Binance is working with Bitget after a major security incident affected part of the crypto exchange’s hot and warm wallet infrastructure. Bitget estimates that about $351.6 million in funds were affected, while its cold wallets remained secure.
Binance CEO Richard Teng said on September 25 that the company’s security team has been working closely with Bitget since the incident was detected. Binance is sharing intelligence, tracing funds and supporting recovery efforts. Teng said the wider crypto industry is working together against the attackers.
We stand with @bitget and its users after the recent incident.
Our security team has been working closely with their side since it was detected, sharing intelligence, tracing funds, and supporting recovery.
In moments like this, the industry unites against the attackers. The… https://t.co/0nToi36DSt
— Richard Teng (@_RichardTeng) September 25, 2026
Bitget detected unauthorized transfers at 18:31 UTC on September 24. The exchange activated its emergency response procedures soon after discovering the activity. It later identified and flagged suspicious addresses and contacted law enforcement and blockchain security firms.
Here is what we can confirm at this stage:
On the attack:
Our security team has made initial progress in tracing the source. The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization… https://t.co/5nINjwbXpC— Gracy Chen @Bitget (@GracyBitget) September 25, 2026
Bitget Says Wallet Breach Did Not Compromise Private Keys
Bitget CEO Gracy Chen said the company’s initial investigation found that the attacker compromised a critical backend system connected to its wallet infrastructure. According to Chen, the attacker used the compromised system to spoof transaction data and trigger Bitget’s authorization process, allowing funds to leave the affected wallets. However, Bitget has ruled out a private key compromise.
Chen also said the loss has been contained and no further unauthorized transfers can take place. The exact method used to enter the system remains under investigation, and Bitget plans to publish a full technical report once its findings are confirmed. Bitget said affected assets include ETH, XRP, BNB, AVAX, USDT, USDC and several other cryptocurrencies. The incident involved multiple networks, including Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Smart Chain and Base.
The exchange said XRP represented the largest single-chain loss. It has contacted organizations connected to the affected networks, and some hacker addresses have already been frozen.
Bitget Protection Fund Covers the Loss
Bitget said customer balances remain intact and the full estimated loss is covered by its User Protection Fund, which holds more than $464 million. Chen also said the company has more than $1 billion in its own assets and maintains 1:1 coverage for customer funds.
The company said its cold wallets were not affected. Bitget Wallet, its separate self-custodial wallet service, was also unaffected because it operates on independent infrastructure. Deposits and trading remain available on Bitget Exchange. However, withdrawals are temporarily paused while the company completes further security checks. Bitget has not provided a confirmed time for withdrawals to resume.
Bitget is now working with independent cybersecurity firms Mandiant and SlowMist on the investigation. Chen also said the attack showed similarities to techniques associated with North Korea-linked hacker groups based on IP behavior and on-chain patterns. The company has reported those findings to relevant authorities, but the investigation remains ongoing.
[UPDATES] We are currently working with independent third-party experts Mandiant and SlowMist for a full investigation.
Our first priority is our users. User balances remain intact, and Bitget's User Protection Fund covers the impact on this platform-wide incident.
Bitget…
— Bitget (@bitget) September 25, 2026
Best Crypto Exchange
- Over 90 top cryptos to trade
- Regulated by top-tier entities
- User-friendly trading app
- 30+ million users
eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong.







