Bitget hack drives September crypto losses to $684 million high

Bitget's $351.6M breach on September 24 pushed monthly crypto losses past $684M, making it 2026's costliest month and reversing August's trend.

Jan Whitfield News

The Bitget hack on September 24 drained $351.6 million from hot and warm wallets at 18:31 UTC, prompting immediate withdrawal suspensions. The exchange attributed the breach to wallet compromise but declined to specify the attack vector while investigations continue. CEO Gracy Chen confirmed Bitget's $464 million User Protection Fund would cover the loss, leaving approximately $112 million in reserve capacity.

The Bitget incident pushed September's cumulative crypto losses past $684 million across multiple breaches, surpassing April's $646.9 million to become the costliest month of 2026. This reverses the trend established in August, when the industry recorded 50 hacks but only $136.3 million in aggregate losses.

August pattern breaks as severity returns

August 2026 saw a record number of attacks targeting smaller protocols and individual wallets. The average loss per hack fell to $2.7 million, down from roughly $9 million in July, according to PeckShield data. Only one incident exceeded $74 million, and validators froze the affected network before funds moved off-chain.

September moved in the opposite direction. The Bitget breach represents the third-largest single incident of 2026. A Fetch.ai bridge exploit on September 20 drained $1.55 million after a signing key compromise, and at least 17 smaller incidents added to the month's total. Fifteen transfers across seven assets left Bitget's wallets, with Ethereum accounting for roughly 44 percent of identified losses.

Attackers refocused efforts on centralized infrastructure rather than protocol-level code vulnerabilities that dominated August. The shift mirrors patterns from early 2026, before infrastructure hardening temporarily diverted attention toward less-defended targets.

Protection fund narrows after payout

Bitget maintained normal deposit and trading operations throughout the hack. The exchange's User Protection Fund, established to cover exactly this scenario, held $464 million before the breach. With $351.6 million allocated to cover losses from the Bitget hack, the remaining $112 million would cover a mid-sized exploit but leaves limited buffer for a repeat incident on similar scale.

Most major platforms maintain reserve ratios above 2x their largest historical loss, following concentrated attack campaigns earlier this year. Bitget identified and flagged wallet addresses connected to the transfers, notified law enforcement, and engaged on-chain security firms to trace fund movements.

Exchange targeting resurfaces

The timing of the Bitget hack coincides with renewed volatility in traditional markets, though no direct connection between macro conditions and exploit activity has been established. Centralized exchanges process higher transaction volumes than individual DeFi protocols, creating larger targets for sophisticated attackers.

Bitget committed to hourly updates and promised a full incident report within 24 hours. The exchange has not disclosed whether the $351.6 million represents the final tally or an initial assessment subject to revision as forensic analysis continues.

Disclaimer The information provided on Coinliva is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency investments are highly volatile and involve risk. While we strive to provide accurate and up-to-date information, some details may change over time. Always conduct your own research before making any financial decisions.