Bitget, one of the largest crypto exchanges, has experienced a $351.6 million hot wallet drain following a security breach. Arkham Intelligence initially flagged the incident, identifying massive withdrawals of AVAX, BNB, ETH, and stablecoins that were subsequently swapped to ETH.
According to Bitget CEO Gracy Chen, the attacker compromised a critical back-end system in the wallet infrastructure without accessing private keys. The attacker spoofed transaction history and triggered withdrawal authorization through this compromise.
Cold wallet funds remain unaffected by the exploit. Bitget has temporarily suspended withdrawals while conducting a security review, though depositing and trading continue normally. User balances on the exchange remain secure.
The exchange has flagged the receiving address and is collaborating with law enforcement and on-chain security firms to recover the stolen funds. Bitget expects to publish a full incident report within 24 hours detailing how the breach occurred and remediation measures.
Chen has guaranteed that Bitget will cover the full fund loss through its User Protection Fund, which currently holds over $464 million. The exchange has also implemented additional measures to prevent further theft.
The Bitget exploit ranks as the largest crypto hack of 2026 by funds lost. The Liquid Network exploit ($320 million) and KeloDAO hack ($292 million) follow closely behind.
Cybersecurity experts at Certik note a structural shift in attack patterns this year. Rather than exploiting smart contract bugs, attackers increasingly target infrastructure compromise, hot wallet theft, and private key compromise to drain large amounts of funds at once.


