On September 24, 2026, Bitget lost $351.6M from its hot and warm wallets. The exchange says the loss is fully covered by its User Protection Fund, but withdrawals were paused with no date for reopening. Below is what is known so far, and the question every trader with funds on a centralized exchange should ask this week: where does the risk to your money actually sit?
What happened at Bitget
At 18:31 UTC on September 24, Bitget's security systems detected unauthorized transfers from part of its hot wallets. On-chain analysts, including Bubblemaps and Arkham, flagged the outflows publicly within minutes. The first estimates were around $176–183M moved in roughly an hour; Bitget later confirmed the total at $351.6M.
According to CEO Gracy Chen, the attacker compromised a critical backend system inside the wallet infrastructure, used it to spoof transaction data, and triggered Bitget's own authorization process to move funds out. Private key compromise has been ruled out. In other words, nobody stole the keys — the exchange's own system signed the withdrawals because it was fed false data.
| Fact | Detail |
|---|---|
| Detected | September 24, 2026, 18:31 UTC |
| Total affected | $351.6M |
| Wallets hit | Hot and warm wallets; cold wallets reported safe |
| Assets moved | ETH, USDT, USDC, AVAX, BNB, XAUT |
| Attack vector | Compromised wallet backend, spoofed transactions, exchange's own approval flow |
| Private keys | Not compromised, per Bitget |
| Coverage | User Protection Fund, over $464M |
| Withdrawals | Paused pending security review, no timeline |
| Deposits and trading | Open |
One on-chain detail shows how fast this moved: the first suspicious trade on Arbitrum swapped $19.67M of USDT0 into 7,111 ETH in about six minutes, paying roughly 5% over market. When an attacker overpays that much, speed matters more than price — the goal is to convert and move before anything gets frozen.
Your balance is safe. Your access is not
Bitget says user balances are accurate and the loss is covered. Taking that at face value, nobody should lose money on paper. But the practical outcome for every user is the same as in any exchange incident: you cannot withdraw until the exchange decides you can.
For a trader, that is not a formality. If you run a delta-neutral position with one leg on Bitget, you cannot move margin to the other leg. If the other side gets liquidated, the hedge breaks and you are left with open directional exposure on a venue you cannot withdraw from. The size of the protection fund does not help with that.
This is not a one-off
Large centralized exchanges have been hacked or frozen regularly. Bybit lost about $1.5B in February 2025, the largest crypto theft on record. FTX halted withdrawals in November 2022 and never reopened them in the normal way. Bitget is one of the largest derivatives venues in the world, with a nine-figure protection fund — and it still happened.
The common thread is structural. On a CEX, your deposit sits in wallets the exchange controls, and every withdrawal passes through systems you cannot see or audit. You are trusting the exchange's key management, its internal software, its staff, and its decision to let you withdraw at all.
Where custody risk sits: CEX vs perp DEX
| Centralized exchange | Perp DEX | |
|---|---|---|
| Who holds the funds | The exchange, in its own wallets | A smart contract or protocol vault; you sign from your own wallet |
| Withdrawals | Approved by the exchange; can be paused at any time | Signed by you; depends on the protocol and its bridge |
| Account freeze | Possible for compliance, security or any internal reason | No account to freeze in the usual sense |
| Main technical risk | Hot wallet and backend compromise, insider risk | Smart contract bugs, bridge risk, oracle or market manipulation |
| Transparency | Proof-of-reserves snapshots at best | Positions, open interest and vault balances visible on-chain |
| Extra upside | Fee discounts, VIP tiers | Points programs and airdrops on top of trading |
Perp DEXs are not risk-free, and anyone who says so is selling something. Contracts can have bugs, bridges have been drained, and thin markets can be manipulated. What changes is the shape of the risk: nobody can decide to stop your withdrawal for their own reasons, and most of what matters — open interest, vault balances, positions — is visible on-chain instead of behind a statement.
How to choose a safer perp DEX
If this incident is a reason to move part of your trading on-chain, the venue choice matters more than the decision to switch. A small DEX with a thin book can be riskier than a large CEX. Practical filters:
- Size first. Prefer venues with deep open interest and daily volume. Liquidity is also a proxy for how much scrutiny the contracts have had. Compare venues in the perp DEX ranking.
- Check the real cost of trading. Zero-fee marketing means little if the book is thin. Execution Cost shows what a $10k–$1M order actually costs on each venue, including slippage.
- Understand the bridge. Many perp DEXs run on their own chain or rollup, and deposits pass through a bridge. That bridge is part of your risk, so read how it works before depositing size.
- Split capital. No single venue — centralized or not — should hold everything. Spreading across two or three large venues limits the damage from any one incident.
- Watch funding before you move. Funding on DEXs can differ sharply from CEXs; the funding screener shows where you would pay and where you would collect.
Points: the upside CEXs do not offer
There is one more difference that has nothing to do with security. Many perp DEXs run points programs: you trade, you accumulate points, and the points convert into tokens at launch. On a CEX the same volume earns you a fee discount at best.
Points are not guaranteed money — allocations, dilution and token prices vary widely, and some programs pay far less than they look. But if you already trade the volume, earning points on it is a free option. The points calculator estimates what a point may be worth on each venue, and the airdrop calendar tracks which programs are live.
The bottom line
Bitget's users will most likely be made whole. That is the good outcome, and it is still a reminder of how custody works on a centralized exchange: your money is safe until the moment access to it depends on someone else's system. If you trade on CEXs, check your balances, follow only official announcements, and ask whether all of your capital needs to sit there. If you move to perp DEXs, pick large venues, understand their risks, and collect points on the way.