Blockchain AcademicsBlockchain Academics
$170-183 Million Drained From Bitget Wallets in Under an Hour

$170-183 Million Drained From Bitget Wallets in Under an Hour

Between $170 million and $183 million in cryptocurrency moved out of Bitget exchange wallets to a newly created address across multiple blockchains in less than an hour. Both hot and cold storage reserves appear affected. Bitget has not issued an official statement.

Alejandro Silva RamírezEdited by Wael RajabSeptember 24, 20264 min read
Share

$170-183 Million Drained From Bitget Wallets in Under an Hour

Between $170 million and $183 million in cryptocurrency moved out of wallets labeled as belonging to Bitget exchange on Thursday, transferred to a newly created, unidentified address across multiple blockchains in less than sixty minutes. The exchange has not issued any official statement confirming or denying a breach.

The scale and speed of the transfers are what make this incident alarming. Hot and cold storage reserves alike appear to have been affected, which is unusual even in confirmed exchange hacks. Most attacks target hot wallets specifically because cold storage, by design, requires additional authentication steps and is typically kept offline. Reaching both simultaneously within a single hour points either to a highly coordinated external attack exploiting multiple vulnerabilities at once, or to an insider with privileged access to several wallet key sets.

The receiving address was freshly created, a classic indicator of a wallet generated specifically to receive stolen funds. On-chain observers noted that the address has already executed several token swaps since receiving the transfers. Swapping assets quickly after a large inflow is a common technique used to complicate tracing, as it breaks the direct on-chain link between the original assets and the current holdings.

That said, the activity is not conclusive proof of theft. Bitget itself could theoretically be moving and rebalancing assets internally, using a new address as part of a security response to a detected threat rather than as a victim of one. Without a statement from Bitget, the difference between a catastrophic hack and an authorized internal transfer is not yet established. Wallet labeling on blockchain explorers is based on heuristics and community tagging, not official confirmation from exchanges. Misattributed labels have caused false alarms before.

Still, the combination of factors here creates a pattern that security researchers associate with unauthorized access rather than routine treasury management: the volume, the speed, the multi-chain scope, the freshly created receiving address, and the subsequent swaps.

The broader historical record provides grim context for what a confirmed breach of this size would mean. The 2016 Bitfinex hack drained approximately $72 million at the time, triggering a prolonged crisis of confidence and a years-long legal and financial recovery process. The 2018 Coincheck hack in Japan reached $530 million. Each of these events accelerated regulatory scrutiny of exchange security practices and, in several cases, resulted in the exchange halting withdrawals entirely while it assessed the damage. If Bitget confirms a breach approaching $183 million, it would rank among the largest exchange hacks in the industry's history by dollar value at time of incident.

Bitget is a Seychelles-registered exchange that has grown significantly over the past three years, particularly in derivatives trading volume. It has marketed itself as holding substantial proof-of-reserves, and any confirmed loss at this scale would immediately raise questions about whether user funds are covered and whether withdrawals remain operational. Those questions will intensify with every hour that passes without an official response.

The absence of a statement is itself informative. Exchanges that detect unauthorized transfers and move quickly to contain them typically communicate fast, both to reassure users and to coordinate with blockchain analytics firms and other exchanges to flag the receiving address for freezing. Silence at this stage is either a sign that the internal investigation is still ongoing, or that the situation is worse than initial on-chain data suggests.

On-chain monitoring will be the primary source of real-time information until Bitget speaks. If the receiving address continues to swap assets and begins bridging them across chains or routing them through mixers, that behavior would strongly suggest an attempt to launder the funds rather than a legitimate internal operation. Conversely, if the address goes quiet and funds return to known Bitget addresses, the incident may resolve as a precautionary internal move that was misread by outside observers.

For users with funds on Bitget, the practical calculus right now is straightforward: watch for any announcement about withdrawal restrictions and monitor the exchange's official channels closely. The next few hours will determine whether this becomes one of the defining security incidents of 2026 or a false alarm that briefly rattled the market.

Discussion

Loading comments...