What is Bitget?
Where does an exchange actually keep your crypto?
What really happened?
How much was stolen?
What happens to the money now?
Who is responsible?
Is it safe to keep cryptocurrency on Bitget?
What this means for Indian crypto users
FAQs

On the night of September 24, a brand-new wallet spent 19.67 million USDT to buy 7,111 ETH on Arbitrum in just six minutes.
The buyer paid a premium of up to 5% over the market price. Nobody overpays like that with their own money. That trade was the first public sign that Bitget was being hacked.
Bitget is a crypto exchange where users buy and sell crypto. It was founded in 2018, is incorporated in the Seychelles, and says it has more than 120 million registered users in over 150 countries.
It exploded in growth after the fall of FTX and quickly became one of the biggest crypto derivatives exchanges. A derivative is a contract that lets traders bet on price moves without holding the coin itself. Bitget provides a feature known as copy trading, where users are able to copy the trades made by expert traders. Additionally, the exchange has its own utility token, BGB, which gives users discounts on trading fees.
Bitget suspended registration of new users from India from February 6, 2026, while it worked on complying with the requirements of FIU-IND. Users can still use the services provided by the exchange if they registered before February 6, 2026.
Your crypto is always stored on the blockchain. A blockchain is a digitally distributed ledger and a record of cryptocurrency transactions. Exchanges store users' crypto in their exchange wallets. Wallets contain private keys, which provide proof of ownership of the crypto. Exchanges use different types of wallets: hot, warm, and cold wallets. Hot wallets are online and connected to the internet, warm wallets are semi-connected, and cold wallets are fully offline. The main vault of a bank is a good example of a cold storage wallet.
During the recent hacking incident, Bitget said the attackers only accessed some of the hot and warm wallets,s and the cold storage was not affected.
Most exchange hacks involve the theft of private keys. The hack of Bitget is believed to involve a different method. Gracy Chen, the CEO of Bitget, stated that the hacker accessed a backend system, used it to fake transaction data, and then tricked the exchange into processing the transactions.
This is what is believed to have occurred based on information disclosed by Bitget.
1. The hacker accessed Bitget's system through a vendor. Gracy Chen, in a live session, stated that initial investigations showed that the hack involved breaking into a vendor system that is integrated with one of Bitget's backend systems.
2. The hacker generated false transaction messages. The hacked vendor system created fake transaction messages and instructed Bitget's signing machines to process the transactions.
3. The system processed the transactions. As the messages were generated through an internal and authorised process, they were automatically approved. Chen said the hacker did not forge customer withdrawal requests and never got the private keys for any hot, warm or cold wallet.
4. The hacker drained the funds in minutes. CNBC reported 19 transfers out of parts of the hot and warm wallets. Bitget's systems detected the unauthorised transfers at 18:31 UTC on September 24, which was 12:01 am IST on September 25.
5. The hack was stopped. Chen later stated that the losses were contained and no further unauthorised transactions could take place.

Figure 1. How the Bitget hack worked. Source: Bitget, CNBC, TechFlow. Data as of 25 September 2026.
The vault remained locked, ed and the vault key remained in its place. Someone accessed the office that creates payment vouchers, printed payment vouchers that looked real, and presented them to the approval desk of the bank. The approval desk endorses payment vouchers to be released to the beneficiaries.
Chen compared the method to the Bybit hack of February 2025. The Bybit hack included a signing fraud and a supply chain attack on the Safe multi-sig interface. The security team is still working to confirm the attack vector.
The amount kept increasing. On-chain trackers first estimated the loss at 174 million dollars, then revised it to 183 million dollars. Later, Bitget reported and confirmed the loss at 351.6 million dollars (approximately ₹3,360 crore).
What was the missing link? The XRP Ledger. Dashboards and trackers that only monitor the activity of EVM chains missed the XRPL transfers at first.
According to Chen, the affected assets were ETH, XRP, BNB, AVAX, USDT and USDC, across Ethereum, XRPL, Arbitrum, Avalanche, Optimism, BNB Smart Chain and Base. The table below brings together the figures reported so far.
| Item | Amount | Approx. in ₹ |
|---|---|---|
| Total loss (Bitget estimate) | $351.6 million | ₹3,360 crore |
| XRP stolen (largest asset) | 102.93 million XRP, $157.5 million | ₹1,505 crore |
| First stablecoin swap on Arbitrum | 19.67 million USDT0 → 7,111 ETH | ₹188 crore |
| ETH held by hacker addresses | about 68,000 ETH | not stated |
| Assets left in hit wallets after first wave | about $530 million | ₹5,064 crore |
| Bitget User Protection Fund | over $464 million (5,500 BTC) | ₹4,434 crore |
Source: Bitget CEO Gracy Chen on X, Lookonchain, SlowMist, Ember via TechFlow. Data as of 25 September 2026. Rupee figures at ₹95.55 per dollar, the 27 August 2026 close reported by PTI. For informational purposes only.
Bitget is yet to publish an official statement concerning the individual losses. The XRP figure comes from Lookonchain, not from the exchange.
The money goes into ETH. Tether can freeze USDT, and Circle can freeze USDC. None of that is the case for ETH. So, the attacker was willing to pay a 5% premium on UniswapX and 1inch Fusion.
Usual price concerns are thrown out the window. In this case, speed of execution was the most important factor.
According to SlowMist, addresses linked to the attacker still hold about 68,000 ETH and about 103,000,000 XRP. The infographic below breaks down the losses and shows where the funds were moved to.

Figure 2. Asset breakdown and money trail. Source: Lookonchain, SlowMist, Specter. Data as of 25 September 2026.
North Korea is the main suspect. Chen said Bitget found IP addresses matching the VPN choices of a specific DPRK group and believes an attack by North Korea is very likely. She did not disclose the name of the group.
Specter, another on-chain sleuth, linked the stolen XRP to funds from the July AFX hack. That hack, valued at around $24,000,000, was attributed to a group called TraderTraitor, which is associated with the Lazarus Group.
The shared money trail is strong evidence, but it does not prove the same group carried out the Bitget attack. Formal attribution could take weeks, just as it did for the FBI in the Bybit case.
According to Bitget, user balances are accurate, and deposits and trading are functioning normally. Withdrawals remain suspended until the security review is complete. Bitget has not announced when withdrawals will be resumed. Bitget's Onchain Trading service was also briefly unavailable on September 25, 2026.
The protection fund is fully backed by bitcoin, and its rupee value changes with the price of bitcoin. Bitget committed to keeping the protection fund above $300 million.
Bitget Wallet, the self-custody wallet of Bitget, was not affected.
Bitget is the largest cryptocurrency hack of 2026 so far. 2025's hack on Bybit is more than 4 times the value of Bitget's hack and remains the largest hack in cryptocurrency history.

Figure 3. Bitget versus selected crypto hacks, US$ million. Data as of 25 September 2026.
It is important to understand that hacks and security breaches of centralised exchanges can happen even when the keys are perfectly secure. Leaving your cryptocurrency on an exchange makes you completely dependent on that exchange. You do not own the private keys.
Users from India can check the FIU-IND registration list first. As of July 2026, 54 VDA (Virtual Digital Assets) providers were registered with FIU-IND. Unregistered providers may face blocking and/or fine orders under PMLA (Prevention of Money Laundering Act), 2002. Registration does not provide immunity. Service provider registration enables the agency to exercise oversight over the VDA provider.
Next, users should monitor the platform for the resumption of withdrawals. Additionally, users should monitor for Bitget's investigation report. If the report supports the supply chain theory, users should expect the platform to tighten vendor access to its wallet systems.
Holding Virtual Digital Assets (VDAs) is risky. VDAs are cryptographic assets and are not covered by any investor protection scheme. Further, VDAs are not deposits and are not protected by any deposit protection scheme. This publication and the information provided herein do not constitute an offer, invitation, or solicitation of any offer to buy or sell any VDAs, securities, or other financial instruments.
India Crypto Research operates independently. The information presented herein is intended solely for educational and informational purposes and should not be construed as financial advice. Before making any financial decisions, it's essential to undertake your own thorough research and analysis. If you're uncertain about any financial matters, we strongly recommend seeking guidance from an impartial financial advisor.