Bitget $352 million hack

XRP logo, representing the largest asset reported stolen in the Bitget hack
Benwhale1 / Wikimedia Commons.

Bitget $352 million hack is the central phrase for this report because it captures the specific development readers need to evaluate. Nineteen suspicious transfers drained several blockchains; the exchange says users will be covered, while its North Korea attribution remains preliminary.

What Bitget confirmed

Bitget said roughly $351.6 million was removed through 19 unauthorized transfers spanning several blockchains. Hot and warm wallet infrastructure was affected; the company said cold wallets and private keys remained secure. Withdrawals were paused while deposits and trading continued. XRP was the largest reported asset category, at roughly $120 million.

The protection-fund test

Chief executive Gracy Chen said Bitget’s user protection fund exceeded $464 million and that customers would be covered. That pledge is central because a reserve advertised for crises becomes meaningful only when claims are paid promptly, transparently and without forcing users to absorb hidden conversion losses. A rush to withdraw after service resumes could test liquidity as much as the theft tests solvency.

North Korea is an allegation, not a conclusion

Chen said on-chain patterns suggested North Korean state-linked actors. That attribution is preliminary and disputed. Blockchain traces can show movement, clustering and laundering behavior, but assigning a state sponsor usually also requires infrastructure evidence, operational overlap and intelligence unavailable to the public. This report does not treat the attribution as established fact.

Who gains and who loses

Cold-storage and self-custody advocates gain another example of the risks concentrated in exchange-controlled wallets. Chain-analysis and incident-response firms gain demand. Bitget faces reputational damage even if every user is reimbursed, while XRP sentiment may feel a short-term effect because it was the largest drained asset. Rival exchanges gain only if they can demonstrate stronger controls rather than exploit fear.

What happens next

The key evidence will be a wallet-by-wallet accounting, restoration of withdrawals, verified reimbursements and any recovery or freezing of stolen assets. Investigators also need to explain how 19 transfers crossed controls and whether one credential, one service or several systems failed. If the total holds, the theft will rank among 2026’s largest; the lasting verdict will depend on disclosure quality and customer outcomes, not the anniversary-week headline.

Related Signal Post News coverage

an earlier cross-chain key failure the regulatory debate around crypto market structure

Sources and reporting basis

Reporting note: This is a fixed September 25, 2026 snapshot. Attributed claims remain attributed; forecasts, polls, vendor results and early cyber findings can change as new evidence appears.

Crypto / Security · Published September 25, 2026Back to latest reports