Back to the desk

News briefing

Bitget loses $387.5 million in 2026's biggest crypto theft so far: what Indian users should know

Severity: HighPublished GlobalIncident2026-0930-BG03 min readBy Vivek Kumar
Conceptual illustration: a server vault with a red warning sign, coins streaming out of its open door along a red path to another machine. Text: BITGET HACK 2026, CRYPTO THEFT.

AI-generated editorial illustration by CyberShitty. Not a photograph or a document from the organisations named.

Attackers drained Bitget's hot wallets on 24 September. Bitget first put the loss at $351.6 million, then raised it to $387.5 million, and says its protection fund covers users. Bitget was on India's March 2026 list of exchanges ordered blocked.

01 / What happened

Bitget said its systems detected unauthorised transfers from some of its hot wallets at 18:31 UTC on 24 September 2026. Its first notice put the loss at approximately US$351.6 million. The next day it raised the figure to about US$387.5 million, announced by chief executive Gracy Chen, after counting Zcash and TRON transfers left out of the first count; it described this as a fuller accounting, not further theft. Its support notice still shows the first estimate.

Bitget says its cold wallets were not affected, withdrawals were paused, and the loss falls within its User Protection Fund, which it said held over US$464 million. According to Bitget, as reported by The Hacker News, the attacker compromised a critical backend system in its wallet infrastructure and used it to spoof transaction data and trigger its authorisation process. By 28 September, FXStreet reported, Bitget had begun restoring withdrawals.

02 / Who is behind it

Bitget's chief executive has called North Korean involvement 'very likely'. Blockchain analysts TRM Labs say they have not definitively attributed the attack, but found on-chain links to earlier thefts attributed to North Korea, including the US$1.5 billion Bybit theft that the FBI attributed to North Korea in February 2025. No government has attributed the Bitget theft so far.

03 / The other big thefts of 2026

  • Liquid Network, 6 September: about US$319 million in bitcoin taken through a software bug; about 85% was later returned. (TRM)
  • KelpDAO, April: about US$292 million released from a cross-chain bridge. (CoinDesk)
  • Drift Protocol, 1 April: about US$285 million drained using compromised admin keys; Drift says it traced the attack to a North Korean group that spent six months posing as a trading firm. (The Hacker News)

TRM says thefts it attributes to North Korea came to about US$690 million in 2026 up to 16 September, before Bitget.

04 / Why it matters in India

Bitget was among 53 offshore platforms whose apps and websites FIU-India had directed to be taken down, according to a Lok Sabha answer of 30 March 2026, and it was not among the 54 platforms registered with FIU as of 9 March 2026. Indians who used it anyway have no Indian regulator or registered-entity route if something goes wrong; they depend on Bitget's own compensation.

Indian exchanges have been hit too. WazirX lost about US$230 million in July 2024, and its restructuring, approved by a Singapore court in October 2025, repaid users mostly in crypto, with the rest issued as recovery tokens. CoinDCX lost about US$44 million from an internal account in July 2025 and said customers were not affected. Bengaluru police arrested an employee who, CoinDesk reported, had been doing freelance work for unknown overseas clients; police were investigating whether malware or credential misuse during that side work enabled the theft.

Hacks of the exchange are one risk. Most losses for ordinary users come from scams, copied addresses and fake apps.

05 / What to do if you hold crypto

  • Keep only what you are actively trading on any exchange. Know whether your exchange is one of those registered with FIU-India, and understand that registration is not protection. How to check.
  • Check the whole wallet address before every transfer, not just the first and last few characters. One user lost about US$50 million in December 2025 after copying a lookalike address planted in their history. (CoinDesk)
  • Install wallet apps and browser extensions only from the developer's official site or store listing, and never type your seed phrase into a website, app or chat.
  • If a job offer or a 'client' asks you to run code or install an app, especially on a work laptop, stop. Drift says its attackers spent months posing as a trading firm before getting in.
  • If you lose money to a scam, call 1930 and file at cybercrime.gov.in. How to report.

06 / Confirmed vs. claimed

Confirmed by Bitget: the time of detection, the first US$351.6 million estimate, cold wallets unaffected, the paused withdrawals and the protection fund (its notice), and the revised US$387.5 million (announced by its CEO, reported by Fortune, the Financial Times and others). Reported: the description of the method and the restart of withdrawals. Claimed, not confirmed: North Korean responsibility, which Bitget calls very likely and no government has confirmed. Confirmed from Parliament: Bitget's place on the takedown list and its absence from the March 2026 registration list.

Source log / 2026-0930-BG

More from the archive