VERSE PRESS

Crypto News, Global First.

Suspected Hack Drains Up to $183M From Bitget Wallets in Two-Hour Window

Bitget has not confirmed the incident. On-chain data shows funds moved through multiple chains and were swapped at a premium, consistent with prior exchange breaches.

|

More than $170 million in crypto assets was transferred out of wallets linked to centralized exchange Bitget on Thursday afternoon, according to on-chain data and reporting from multiple outlets. The transfers occurred between approximately 2:31 p.m. and 4:55 p.m. ET on September 24, 2026, flowing from at least three hot wallets and one cold wallet into a single freshly created address. As of 5:00 p.m. ET, Bitget had issued no public statement and did not respond to requests for comment.


What the On-Chain Data Shows

Blockchain analytics firms Bubblemaps and Arkham Intelligence were among the first to flag the suspicious outflows publicly. The funds moved across four networks: Ethereum, Arbitrum, BNB Chain, and the XRP Ledger. Assets drained include ETH, USDT, USDC, AVAX, BNB, and XAUT, a token backed by physical gold.

Unchained Crypto, which tracked individual wallet movements, put the total closer to $183.8 million. The breakdown includes roughly 24,373 ETH (valued near $65 million), about $34.75 million in USDT, $12.85 million in USDC, 3,000 XAUT tokens (worth approximately $12.8 million), and 821,012 AVAX (near $8.5 million). Analysts treat these figures as preliminary estimates pending official confirmation from Bitget.

The primary receiving address, tagged "Bitget Exploiter 1" on the blockchain explorer Etherscan, carries the identifier 0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee. A secondary dispersal address, identified on-chain as 0x469Ac1406dE92f82C0563477240a3627057425DC, also received a portion of the funds.


Speed, Premium, and Urgency

The behavioral profile of the transfers closely matches prior exchange breaches. One newly created wallet spent $19.67 million in USDT0, a bridged stablecoin variant, to buy 7,111 ETH on Arbitrum within six minutes. The trades were executed through UniswapX and 1inch Fusion, two decentralized exchange aggregators, at prices up to 5 percent above market rate. Paying a premium to move that volume that fast is, analysts say, a classic indicator of urgency over cost efficiency.

"Fresh wallet 0xe410...d946 just bought 7,111 ETH on Arbitrum in 6 min with 19.67M USDT0," wrote pseudonymous on-chain researcher DCF GOD, who flagged the activity in real time.

The funds were then bridged across chains using Stargate and Celer's cBridge, protocols that allow assets to move between blockchains. Cross-chain bridging of this kind makes it significantly harder for stablecoin issuers like Tether and Circle to freeze assets before they are converted or dispersed further.

Users began reporting blocked withdrawals on social media roughly in parallel with the outflows. Crypto commentator Crypto Rover posted on X: "BREAKING: Bitget reportedly hacked for over $170 million. Large amounts of $ETH, $AVAX, $BNB and stablecoins are being transferred out, while users report withdrawal issues. Bitget has not yet confirmed a hack."


What Bitget's Protection Fund Covers

Bitget launched a $200 million user protection fund in August 2022. The fund grew to more than $300 million through 2023, peaking at $368 million in July 2023, and was valued at approximately $617 million as of December 2024, according to the exchange's own reporting. That December 2024 figure is the last publicly available valuation; the fund's current value has not been confirmed.

The fund was designed to cover losses from hacks, extreme market events, or force majeure situations. Whether it will be activated in response to this incident, and whether its current value is sufficient to cover losses at this scale, remains an open question as of publication.


Regional Exposure: Africa, South Asia, and Beyond

For users outside the United States and Europe, the stakes are concrete. Bitget operates in South Africa through a licensed local entity, Parsa Financial Services (Pty) Ltd, registered under the country's Financial Advisory and Intermediary Services Act. The exchange reports more than 40,000 South African users and approximately $70 million in average monthly trading volume on the platform. South Africa is Africa's largest crypto market by on-chain volume, estimated at $35 billion annually, and the country's broader crypto sector has been valued at more than $11 billion.

Local FAIS registration does not automatically guarantee deposit protection in the event of an exchange-level hack, meaning the status of the protection fund is directly relevant to South African retail users.

Nigeria, another active and unrestricted Bitget market, has heightened sensitivity around exchange security following the CBEX scam earlier in 2026, which is estimated to have cost victims more than $250 million.

In India, Bitget suspended new user onboarding in February 2026 but existing users retained full access, leaving a potentially large cohort of retail traders exposed to any withdrawal freeze. A second major incident affecting a platform with significant South Asian presence is likely to accelerate calls for mandatory exchange insurance or proof-of-reserves regulation across the region.

In Pakistan, where currency depreciation and capital controls have led many users to rely on crypto as a primary mechanism for accessing dollar-denominated assets, Bitget also operates. Withdrawal disruptions carry outsized impact in such markets, and the Pakistani user base remains directly exposed to any access freeze stemming from this incident.


Context: A Familiar Pattern

This incident arrives 19 months after the Bybit breach of February 2025, in which the Lazarus Group, a North Korean state-linked hacking collective, stole $1.4 billion in ETH, still the largest single crypto theft on record.

The WazirX hack of July 2024, also attributed to Lazarus, drained $234.9 million and affected an estimated 4.4 million users primarily in South Asia.

The pattern seen here, including rapid stablecoin-to-ETH conversion, cross-chain bridging, and initial silence from the exchange, is consistent with those prior incidents. No threat actor has been identified in connection with the Bitget transfers.

Whether this proves to be a hack, an internal reorganization, or another event entirely will depend on what Bitget discloses. Readers following this story should watch for three developments in particular: whether Bitget activates its protection fund, when withdrawals are restored for affected users, and what the exchange's first official statement says about the scope of the incident. Verse Press will update this story as the exchange responds.