Crypto Exchange Protection Funds Recalculated: What Really Covers Your Balance After the Bitget Hack
The $351.6 million attack on Bitget would eat up three quarters of the exchange's in-house protection fund. We retrieved the protection promises of several exchanges ourselves and measured them against deposit insurance and MiCA liability.

Table of Contents
Table of Contents
When a crypto exchange loses money, no government steps in. What protects your balance there is first a voluntary promise by the exchange, and second a liability rule from the European crypto regulation. The exchange can change the first one tomorrow; the second applies only if the exchange is authorised. The attack on Bitget during the night leading into September 25, 2026 is putting both on display.
So rather than rewrite what is being reported about the incident, we retrieved the protection promises ourselves and ran the numbers. This analysis was compiled by cryptoticker.io on September 25, 2026. The finding in one sentence: the largest in-house protection fund in the industry covers the damage from this single incident only 1.32 times over, and it is held in exactly the currency that falls along with the market in a crisis.
The Bitget hack of September 24, 2026: $351.6 million and suspended withdrawals
The exchange Bitget has confirmed that around $351.6 million flowed out of its hot and warm wallets on September 24, 2026. The company gives 18:31 UTC as the time of detection. According to chief executive Gracy Chen, no private keys were compromised; the attackers are said to have taken over a wallet backend, faked transaction data and thereby triggered the internal approval process. Withdrawals have been suspended since then, and the company describes its cold holdings as untouched. Chen has publicly voiced the suspicion that North Korean attackers were behind it, pointing to IP traces.
A hot wallet is a wallet whose keys sit on a system connected to the internet, so that withdrawals can run automatically. A warm wallet sits in between: it is not permanently online, but it is faster to reach than cold storage. Exchanges keep only a fraction of customer holdings there. That fraction is precisely what was hit here.
For you as a customer, the interesting question is not how the attack worked technically. It is this: who replaces the money when an exchange loses it, and what is that claim based on?
What a crypto exchange protection fund is, and what it is not in legal terms
A protection fund, often called an insurance fund or a safety fund, is a stock of coins that an exchange sets aside to compensate customers in a platform-wide loss event. It is a self-imposed commitment, not a statutory protection scheme. Nobody audits it, nobody prescribes its size, and no authority pays out when it is empty.
This is where retail investors regularly mix something up. Anyone coming from a current account knows deposit insurance up to 100,000 euros and mentally transfers it to the exchange account. That transfer does not hold, for a reason written into the statute and set out further below.
How robust such a fund is comes down to three figures: its size measured against a realistic loss event, the currency it is held in, and the conditions under which it pays out. The first two can be calculated. The third sits in the exchange's fine print.
Our analysis: 5,500 bitcoin in the protection fund, valued at the September 25 price
We retrieved Bitget's fund page on September 25, 2026 at around 12:55 UTC (HTTP 200). The public fund page puts the holding at 5,500 BTC and carries that figure in the page title as well. The value shown next to it read "The fund is currently valued at $0" at the time of our retrieval, plainly a display error on the page, since the holding itself is quantified in the same line. For valuation, the page refers to the opening price at 2:00 (UTC+2) of the respective day.
Because the page does not output the dollar value, we derived it ourselves. The bitcoin price stood at $84,462 when we pulled market data at 12:50 UTC.
- Fund value today: 5,500 BTC times $84,462 comes to roughly $464.5 million. That matches the $464 million the chief executive has cited publicly and confirms the composition.
- Share taken by this one loss: $351.6 million out of $464.5 million is 75.7 percent of the fund.
- What would be left on paper: around $112.9 million, or about 1,337 BTC.
- Coverage ratio: 1.32 times the loss. A second incident of this magnitude would no longer be covered.
These figures are not a forecast and say nothing about the solvency of the company, which by its own account is bearing the loss in full and describes customer balances as correct. They describe only how much buffer the publicly stated protection promise has left after this single event.

The design flaw: a bitcoin protection fund shrinks when it is needed
The second finding of our calculation weighs heavier than the first. The fund is held in bitcoin, so its protective value swings with the price. At the time of our retrieval, bitcoin was trading 33.0 percent below its record high of $126,080 set on October 6, 2025.
The same holding of 5,500 BTC would have been worth around $693.4 million at that record. Today it is $464.5 million. The protective effect has shrunk by roughly $228.9 million without a single coin leaving the fund.
This is systematic and affects every exchange that holds its insurance fund in cryptocurrencies. Loss events cluster in turbulent market phases, and turbulent market phases are exactly when such a fund is worth least. Our calculation also shows where the limit sits: below a bitcoin price of around $63,900, 5,500 BTC would no longer have covered the September 24 loss. That price level has already been within reach this year.
Anyone picking an exchange by its protection fund should therefore never read the holding in dollars, but in coins, and hold it against a realistic loss event. Which providers disclose their safeguards, and how they are supervised, can be checked before opening an account.
Regulated crypto exchanges comparedDeposit insurance up to 100,000 euros: why the German deposit guarantee act does not cover crypto assets
Statutory deposit insurance is the benchmark almost everyone carries in their head. In Germany it sits in the Einlagensicherungsgesetz, EinSiG for short. Under section 2(3) EinSiG, deposits are "credit balances, including fixed-term and savings deposits" that arise from amounts held in an account and "are repayable by the CRR credit institution under the applicable statutory and contractual terms". The coverage limit under section 8(1) EinSiG is 100,000 euros per depositor.
Two features of that definition rule out your exchange account. First, a CRR credit institution has to stand behind it, meaning a bank with the corresponding licence. A crypto exchange is generally not one. Second, the subject is money balances repayable at face value. Bitcoin, ether and solana are not money balances and have no face value.
In practice that means: if you hold euros in a settlement account run by a licensed partner bank, deposit insurance can apply to that euro amount. It does not apply to the coins sitting beside it, not even pro rata. This is not a gap somebody forgot to close, it is how the statute is built.
MiCA Article 75: the liability an authorised crypto exchange cannot contract away
Since the European regulation on markets in crypto-assets came into force, something else has taken the place of deposit insurance, and it is often overlooked in practice: a direct liability on the part of the custodian.
Article 75(7) MiCA requires crypto-asset service providers to segregate client holdings from their own and to keep them legally separate from their own assets. Paragraph 8 goes further: the provider is liable to its clients for the loss of crypto-assets or of the means of access to them where the incident is attributable to the provider. That liability is capped at the market value of the lost crypto-asset at the time of the loss. Excluded are events where the provider demonstrates that they occurred independently of its service, such as disruptions of the underlying blockchain itself.
The decisive difference from a protection fund: this liability is not a goodwill gesture. An authorised custodian cannot limit it towards clients through its terms and conditions where the loss goes back to operational incidents, malfunctions or attacks connected to its service. An attack that runs through the provider's own wallet backend, as in the Bitget case, falls squarely within the provider's sphere of responsibility on this reading.
What counts as custody was described by BaFin in its guidance note on crypto-asset services under MiCAR of January 3, 2025: the safekeeping or control of crypto-assets, or of the means of access to them, on behalf of clients, Article 3(1)(17) MiCAR. Which obligations this brings for providers is something we have broken down in our overview of the MiCA licensing duties.

Bitget and MiCA authorisation: what the pending application means for customers in Germany
That liability hangs on a single word: authorised. It applies to providers that hold an authorisation as a crypto-asset service provider in the EU and therefore fall under the supervision of a European authority.
According to its own announcement of July 2, 2026, Bitget has filed an application for authorisation under MiCAR with the Austrian financial market authority through its Bitget EU entity. The company itself writes there that it intends to offer crypto-asset services in the EU "once the required authorisation has been granted and all applicable regulatory steps have been completed", and points out that the timing, scope and outcome of the procedure are subject to assessment by the authority. For existing customers of the global offering, that announcement states, the previous contractual and legal arrangements continue to apply.
What follows for you is a sober reading, and one that implies no accusation against the company: as long as an authorisation is pending, your claim in a loss event rests on a contract with an entity outside the European supervisory framework and on the voluntary fund promise. The non-waivable liability under Article 75 MiCA and access to a European supervisory authority only come with the authorisation. That is the practical difference between an authorised and a non-authorised trading venue, and it only shows once something has gone wrong.
Proof of reserves and 1:1 backing: what other exchanges' attestations show and what they do not
For context, we retrieved the security disclosures of two further providers available to German investors on the same reference date. Both take a different approach to the loss-fund model.
Kraken publishes proof of reserves using the Merkle tree method, reviewed by an independent third party. The coverage ratios shown on the page stood, as of the June 30, 2026 reference date, at 102.9 percent for bitcoin, 100.5 percent for ether, 100.6 percent for solana, 102.3 percent for XRP and 100.3 percent for cardano; for the stablecoins named there, above 105 percent. No loss fund or insurance for customer holdings is mentioned on that page.
Bitpanda cites on its security page a legally binding separation between its own assets and those of its customers, physical 1:1 backing of all user holdings, cold storage and a commitment not to speculate with customer funds. Here too there is no protection fund and no reference to deposit insurance for crypto assets.
What proof of reserves delivers is narrowly bounded, and that belongs in the picture. It shows that the holdings existed on a given date. It says nothing about whether they are encumbered by liabilities, and it replaces no compensation if they are stolen later. The gap is worth noting: the most recent attestation shown on the page was 87 days old on the day of our survey.
Hardware wallets comparedProtection fund or self-custody: the buying route under MiCA and the holding period
No blanket recommendation to pull coins off the exchange follows from these findings. What follows is a split by purpose.
Amounts you actively trade belong on a trading venue, and there the supervisory question is the more important one: does the provider hold a MiCA authorisation, and which authority supervises it? Holdings you intend to keep for longer are exposed to no exchange risk at all on your own hardware wallet. There, however, nobody is liable for you any more either: a lost recovery phrase is lost for good, and Article 75 MiCA does not help, because no custodian is involved.
What the move triggers for tax, and what it does not
One important point, because it is often misunderstood: merely moving your own coins from an exchange to your own wallet is not a taxable event. You are not disposing of anything, you are only changing where it is kept, and the one-year holding period under section 23 of the German income tax act keeps running unchanged. Tax becomes relevant on a sale and on a swap into another cryptocurrency.
In practice that means you have to carry your acquisition data with you. Anyone spreading holdings across several platforms easily loses track of the acquisition date and acquisition cost per lot, and those are exactly what the tax office will want later. Clean documentation is easiest with a tax and portfolio tool that consolidates deposits and withdrawals across platforms. For larger holdings and for borderline questions, that is no substitute for tax advice.
Markers and thresholds: how to measure whether a protection promise holds
So that you do not have to think this through afresh with every provider, here are the checkpoints that came out of our survey.
- Authorisation before fund. Check first whether the provider holds a MiCA authorisation and which authority supervises it. Only then does the non-waivable liability under Article 75 apply. A fund without authorisation is a promise, not a claim.
- Read the fund size in coins, not in dollars. The dollar figure on a provider page is a snapshot of the price. The holding in BTC or ETH is the figure that can be compared.
- Calculate against a realistic loss. Set the fund size against an incident of the magnitude this industry has actually seen. A coverage ratio near 1 is not a buffer.
- Read the payout conditions. Bitget's fund page, for instance, explicitly names platform-wide events as a precondition and reserves the right to review each individual claim. An individual account loss is evidently not covered.
- Check the age of the proof of reserves. A reference date months in the past says little about the situation today.
- Treat euro balances separately. Deposit insurance only comes into consideration for money amounts held at a licensed partner bank.
Method of our survey: six objects, one reference date, three open points
The survey date is September 25, 2026, and all retrievals took place between 12:50 and 13:05 UTC. Six objects were checked, each returning HTTP 200: Bitget's public fund page, the same provider's MiCAR announcement, Kraken's proof-of-reserves page, Bitpanda's security page, sections 2 and 8 of the German deposit guarantee act, and BaFin's guidance note on crypto-asset services under MiCAR. The market data comes from a separate retrieval at 12:50 UTC. Method: retrieval of the disclosures in the original, followed by our own conversion of the coin holding into dollars at the spot price and a cross-calculation against the reported loss amount.
Three things we could not verify, and they belong on the record. First, the fund's coin holding could not be counted independently on the blockchain; the fund page does link a wallet, but counting the address ourselves was not possible within this survey. The 5,500 BTC are therefore a figure stated by the provider, which we report, not a quantity we counted. Second, the loss amount of $351.6 million is a company statement that had not been conclusively confirmed externally at the time of our retrieval. Third, the full text of the MiCA regulation was not retrievable from our environment; the account of Article 75 rests on a generally available version of the regulatory text and on the BaFin guidance note for the definition of the custody service.
Checking a protection fund: what to take away
- Check today which supervisor your trading venue sits under. Look on your provider's site for the authorisation, the supervisory authority and the registered seat of the entity you have the contract with. If you find a pending procedure rather than a granted licence, you know that liability under Article 75 does not apply yet. A sorted starting point is the overview of regulated crypto exchanges.
- Run the numbers on your provider's protection fund once yourself. Take the stated coin holding, multiply it by today's price and hold the result against a loss in the order of $350 million. If the coverage ratio is near 1, the fund is a signal and not a safety net. How the major trading venues compare on fees, supervision and custody is shown in our comparison of the best crypto exchanges.
- Separate your trading balance from your long-term balance. What you are not moving in the next few weeks does not belong on an exchange account. Moving it to your own hardware wallet triggers no tax and does not interrupt the holding period; store the recovery phrase separately from the device and note the acquisition date and acquisition cost for each lot.
(As of September 25, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- Bitget Hack of $351 Million: What to Check at Your Crypto Exchange Now
- Bitget Review 2026: Is Bitget a Good Crypto Exchange? What You Need to Know
- Compensation After an Exchange Hack: What Twelve Crypto Providers Really Promise German Customers
- Source of Funds at a Crypto Exchange: Why a Deposit Can Freeze Your Account for 15 Days
- Proof of Reserves Explained: How to Check an Exchange Attestation Yourself






























