Bitget Hack of $351 Million: What to Check at Your Crypto Exchange Now
Bitget reports unauthorised outflows of around $351.6 million and has suspended withdrawals. For existing customers in Europe, that closes the one route MiCA had left them.

Table of Contents
Table of Contents
On the evening of Thursday, September 24, 2026, the crypto exchange Bitget said it detected unauthorised outflows from part of its wallets at 18:31 UTC and suspended withdrawals in response. The figure the company itself gives is around $351.6 million. For a European investor, the most important detail is not the size of the loss but the withdrawal freeze: anyone still holding a residual balance at Bitget cannot reach it right now.
That hits a group already working against the clock. Since July 1, 2026, providers without MiCA authorisation have been barred from taking on new business in the European Economic Area. Bitget has exited the EEA market in stages and told existing customers to withdraw their balances. That single remaining route is now temporarily closed.
What happened at Bitget: hot wallets, warm wallets and $351.6 million
A hot wallet is an exchange wallet whose private key stays permanently connected to the internet. It has to be, because withdrawals are meant to settle in seconds. A cold wallet keeps the key offline instead, usually on separated hardware; it is slow, but out of reach for an attacker working over the network. Between the two sits the warm wallet, an intermediate tier with limited but real network access.
Bitget describes its custody setup as a three-tier architecture built from exactly those layers. According to chief executive Gracy Chen, quoted by CoinDesk, only part of the hot and warm wallet tier is affected and the cold wallets are intact. The amounts on-chain observers could see diverged at first: blockchain analysts reported movements of roughly $178 million to $183 million in the opening hours, while the company puts the figure at $351.6 million. A spread like that is normal in the first hours after an incident, because outside observers only see the transactions they have already been able to attribute.
The outflows were spread across fifteen transfers and seven assets on several networks, according to an analysis by CryptoSlate. The largest single block, 44.4 percent, was Ethereum; BNB, AVAX and the stablecoin USDT were among the others affected. Notably, the funds were then consolidated into a single address.
The exchange treats deposits and withdrawals differently: deposits and trading continue to run, the company says, and only withdrawals are paused for the duration of the security review. Bitget announced hourly updates and a full report on the root cause within 24 hours. Neither had appeared by the time this article went to press.
Why the withdrawal freeze hits existing European customers hardest
To a European investor the case may look remote at first, because Bitget is no longer permitted to write new business here. That is precisely what makes the situation more awkward rather than less. When a provider withdraws from the EEA in an orderly fashion, existing customers are usually left with exactly one action: withdraw. If that route is blocked for an indefinite period, the people affected lose the only option regulation had left them.
A second deadline runs alongside, unrelated to the incident. On September 18 Bitget announced it would delist the trading pairs COTI/USDT, SAGA/USDT and RVN/USDT on September 24 at 10:00 UTC. For those three assets, withdrawals run until December 24, 2026, 10:00 UTC, according to the announcement. Anyone still holding positions there has a date in the calendar and a blocked withdrawal route at the same time. That combination is why waiting does not resolve itself here.
In practice: check today whether you are affected at all. Log in, note the balance with the date and time, take a screenshot and file a withdrawal request as soon as the function reopens. A documented balance is the basis for any later claim and for your tax return. Do not respond to emails or direct messages offering help with the withdrawal in this situation: a withdrawal freeze is exactly the moment when fraudsters approach customer lists with supposed recovery services.

MiCA and the ESMA register: which exchange is allowed to serve you
The European regulation on markets in crypto-assets, MiCA for short, has since 2025 required every provider offering crypto-asset services in the EEA to hold an authorisation as a CASP (crypto-asset service provider). Authorised providers appear in a public register kept by the European securities regulator ESMA. The transitional rules for legacy providers expired on July 1, 2026.
Bitget holds no such authorisation and does not appear in that register. The company has applied for a licence in Austria and is building a European entity in Vienna; until a licence is granted, it offers no services in the EEA. What looks like a formality in hindsight is the real difference for you: with an authorised provider you would have a European supervisor to address, reporting duties and documented custody requirements. Without authorisation that whole apparatus is missing, and you depend on the company's assurances.
From that follows the first check, and it reaches beyond this one case. Find out under which company and in which country your provider is actually authorised, and compare that against the ESMA register. If you want a starting point, our overview of regulated crypto exchanges for European investors lists the providers that have cleared this hurdle. The obligations those companies face under the MiCA licensing regime are a separate subject we have set out elsewhere.
One misunderstanding comes up often: a MiCA authorisation is no shield against hacks. It obliges the provider to meet organisational requirements and to segregate client assets, and it gives you a regulated counterparty if something goes wrong. It does not prevent the technical break-in.
Hold your balance yourself: the devices comparedThree wallet tiers at an exchange: what actually protects your balance
When you hold coins in an exchange account, you do not own coins on the blockchain. You own a claim against the company. The exchange runs an internal ledger of your balance and keeps all customer holdings pooled in its own wallets. That distinction matters the moment the exchange's holdings fall below the sum of the claims against it.
Splitting funds into hot, warm and cold is the standard answer to that risk. The large majority of customer holdings is meant to sit offline, while only a working float is kept online, large enough for day-to-day withdrawals. If the split works as intended, a break-in at the hot wallet reaches only that working float. In this case, though, the sum the company names runs into the hundreds of millions, which shows how large that float gets at a major exchange.
From that you can derive a question to put to any provider: does it publish proof of reserves, and can that proof be verified independently? A meaningful attestation names addresses, a cut-off date and a method by which customers can confirm their own balance was included. A press release with a total and no verifiable addresses does not meet that bar.
The protection fund is not deposit insurance: what $464 million in cover means
Bitget points to its own protection fund, which the company says holds more than $464 million and will cover the loss in full. That is a solid commitment only within the frame in which it is meant, and that frame differs fundamentally from what you know from your bank account.
Statutory deposit insurance in the European Union protects bank balances up to 100,000 euros per customer and institution. It rests on a directive, is supervised by the state, and applies whether or not the bank wants to pay. A crypto exchange's protection fund, by contrast, is a voluntary reserve held by the company. The company itself decides on payout, priority and amount. No statutory deposit insurance exists for crypto-assets in the EU, and MiCA does not create one.
This says nothing about Bitget's willingness to pay; it describes the nature of the instrument. A protection fund can absorb a loss in full, and funds in this industry have done so before. What you cannot do is rely on it the way you rely on a bank guarantee.

Self-custody and hardware wallets: when moving off an exchange account pays
Self-custody means you hold the private key to your coins yourself and nobody else can dispose of them. A hardware wallet is a small device that generates that key and keeps it permanently separated from your computer; transfers are confirmed on the device and the key never leaves it. The seed phrase is the sequence of words from which the key can be restored, and therefore the actual access to your assets.
The advantage is obvious: a break-in at an exchange does not reach holdings that sit on your own device. The downside is often underestimated. Self-custody comes with no recovery hotline. A lost or photographed seed means permanent loss, and in August 2026 a flaw in the key generation of certain offline devices showed that this route carries risks of its own.
A workable rule of thumb separates funds by purpose. Amounts you actively trade may sit at a regulated exchange, because you need to be able to act quickly there. Anything you intend to hold for months, and whose loss would hurt, belongs on your own hardware. If you are moving funds for the first time, read up in our hardware wallet comparison first and send a small test amount before you move the rest.
One element of diligence costs nothing and is regularly forgotten: write the seed phrase down by hand, keep it separate from the device, and never store it as a photo, a text file or in cloud storage. Total losses in self-custody rarely trace back to an attack on the device. Usually a copy of the seed existed somewhere that somebody else could reach.
Tax and the holding period: what a frozen balance means for your return
A withdrawal freeze is, for tax purposes, a non-event to begin with. As long as your coins sit in the account and merely cannot be moved, you have neither sold nor swapped, and no disposal has taken place. In Germany the one-year holding period under section 23 of the Income Tax Act keeps running during this time, because it attaches to acquisition and disposal, not to availability.
It looks different once a blocked balance turns into an actual loss. Whether and how a loss from stolen or no longer withdrawable crypto-assets can be claimed for tax has not been settled in Germany and depends on the individual case. The federal finance ministry did not take a clear position on theft losses in its guidance on crypto-assets. What follows for you is above all a duty to document on your own account: secure account statements, transaction lists and the provider's notices with dates while you still have access to your account.
If you already run a portfolio tool, record the event there as a separate item rather than keeping it in your head. Our overview of crypto tax software and portfolio trackers shows which programmes produce records in a form a tax office accepts. For larger amounts a tax adviser is the cheaper option, because a wrongly stated loss position triggers questions later.
September 2026 in the hack ledger: Liquid Network, Bitget and the year's total
The incident does not stand alone. On figures CryptoSlate compiles from DeFiLlama, losses from attacks in September 2026 already stood at roughly $342 million before the Bitget incident. With the loss now reported, the month adds up to more than $684 million, surpassing the previous high for the year set in April at $646.9 million.
The largest single item before that came in early September from the Liquid Network at around $320 million, where the attackers stated they had acted as white hats. Smaller incidents followed, among them an attack on a hot wallet belonging to the provider Duelbits worth about $7 million. For context, a monthly tally depends heavily on a few large individual cases, and no trend for the coming quarter can be read from it.
For judging your own risk, another observation is more useful anyway. The large losses of this year arose overwhelmingly where assets sat pooled with a single custodian. That holds for the orderly cases too: both the shutdown of BitMEX on September 23 and the announced closure of CoinEx at the end of the year put customers in the same position, having to pull balances under time pressure off a platform they could no longer choose. Bitcoin itself barely reacted to the news that evening; the market now treats a break-in at a single exchange as an event belonging to that exchange.
Checking the Bitget hack: what to take away
- Establish today whether you are affected, and document the position. Log in, note balances with date and time, save the transaction list and the provider's notices, and file the withdrawal request as soon as the function reopens. For the three trading pairs delisted on September 24, the withdrawal window closes on December 24, 2026. Keep the records in the form a tax office will later want to see — the tools for that are in our comparison of crypto tax software.
- Check the authorisation of every exchange you use. Find out which company in which country is liable for your account, and match it against the ESMA register. A provider without CASP authorisation may not serve you in the EEA, and in a dispute you have no European supervisor to turn to. The houses that have cleared this hurdle are in our overview of regulated crypto exchanges.
- Separate trading holdings from long-term holdings. What you move around may sit at the exchange; what you hold for months belongs on your own hardware, with the seed phrase written by hand and kept apart from the device, and a small test amount sent before the first large transfer. The devices and how they differ are in our hardware wallet comparison.
A final note that applies at the time of writing: Bitget reported the incident itself, quantified the loss and promised cover from its own protection fund. Whether withdrawals reopen quickly, and whether the promised root-cause report answers the open questions, could not be foreseen as this article went to press. Until then the sober rule this evening has confirmed again applies to you: a balance at an exchange is a claim against a company, and its worth depends on that company being able and permitted to pay.
(As of September 24, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- Crypto Exchange Shutting Down: What to Do Before the Deadline Passes
- Crypto Withdrawal to Your Own Wallet: Ten Providers Checked, Three Will Not Let Your Coins Out
- Bitget Review 2026: Is Bitget a Good Crypto Exchange? What You Need to Know
- Binance Is Out of the EU: How to Move to a MiCA-Regulated Exchange
- Your Crypto Exchange Is Telling You to Withdraw: How to Spot Phishing After the MiCA Deadline






























