Security

Bitget's $351M Hack: The Balance That Wasn't There

Bitget lost $351.6M in a hot-wallet hack, no private keys touched. What a non-custodial, coinbase-paid payout looks like instead.

Diagram of a spoofed approval routing Bitget hot-wallet funds out across seven chains, labeled $351.6M affected on Sept 24, 2026

At 18:31 UTC on September 24, 2026, Bitget's security systems flagged transfers that should not have existed. Wallets holding customer funds were emptying in pieces across Ethereum, the XRP Ledger, BNB Chain, Avalanche, Arbitrum, Optimism and Base. No customer had asked for a withdrawal. No attacker had stolen a private key. Bitget's own systems approved each transfer as if Bitget itself had asked for it.

By the time the team stopped the outflow, roughly $351.6 million was gone. The Bitget $351 million hack is the largest reported theft from a crypto exchange in 2026, according to CoinDesk's reporting on the breach. It hit an exchange that follows the industry's standard playbook: cold storage for most customer assets, a nine-figure protection fund, and a same-day public disclosure.

What Bitget Says Happened To Its $351 Million

CEO Gracy Chen has been specific about the mechanics. The attackers compromised a backend system inside Bitget's wallet infrastructure, used it to spoof transaction data, and triggered the exchange's own authorization and signing process to move funds out. Chen wrote that a private key compromise "has been ruled out." Bitget keeps its cold wallets off that backend, and the attackers never reached them. They reached the hot and warm wallets, the ones a live exchange keeps online so withdrawals and trades clear in seconds.

Chen also said IP behavior and on-chain analysis look "highly consistent" with known North Korean hacking groups, and that the exact intrusion method is still under investigation, with a full technical report to follow. Deposits and trading stayed open. Withdrawals stopped pending a security review. Bitget says its User Protection Fund, which holds more than $464 million, covers the full loss, so customer balances stay whole on paper whatever investigators claw back.

The on-chain trail shows how fast a spoofed approval moves once it lands. Arkham Intelligence traced about $228 million leaving Bitget in 18 minutes, between 18:58 and 19:16 UTC, and found the attackers swapping stablecoins for ether within ten minutes of the first transfers. The single largest piece was roughly $153 million in XRP. That protection fund holds 5,500 BTC, so a full $351.6 million loss would consume about 76% of it, as CryptoSlate calculated, and the exact share will move with the bitcoin price and with whatever gets frozen or recovered.

The Bitget Hack Made September 2026 the Costliest Month

Bitget did not suffer alone this week. A few hours earlier on the same Thursday, the crypto casino Duelbits took its site offline after attackers drained about $7 million from its hot wallets, in what investigators suspect was a stolen private key. Earlier in the month, attackers took roughly $320 million from Blockstream's Liquid Network. With Bitget added, CryptoSlate puts September's reported losses above $684 million, ahead of April's $646.9 million, which makes it the costliest month for crypto theft in 2026 so far.

Neither Bitget nor Duelbits runs a mining pool. Both held other people's money in wallets those people did not control. Keep that detail in mind, because the rest of this post turns on it.

The Difference Between A Balance And A Payment

Every account of the Bitget breach starts from the same place. A system decided, on the customer's behalf, where money should go, and an attacker inside that system tricked it into deciding wrong. You cannot blame that on one company's engineering. It comes with holding a balance for someone else at all. A balance is a promise, backed by whatever controls, protection funds and incident response a company can build around it. An attacker who reaches the right backend can bend that promise without touching anyone's key.

A block reward found through solo mining does not have to work that way. As NexusPool's technology page explains, the coinbase transaction, the first payment in every new block, pays the finder's own address directly. The block pays your address. We hold no balance for you, and the pool fee is 0%. Nobody inside NexusPool or outside it can spoof, redirect or freeze a pool-held balance between a found block and your wallet, because that balance never exists.

That is also why NexusPool built Payout Preflight. You enter an address and see the exact coinbase transaction that would pay it on the current block, built by the same code that builds a real one, before anyone finds a block. You check the destination while nothing is at stake, instead of after a headline forces the question.

What the Bitget Hack Does Not Prove About Solo Mining

None of this makes solo mining a safer place to park savings than a well-run exchange. A coinbase paid straight to your address still depends on you: lose that address's private key and the reward is gone. Your chance of finding a block depends on your hashrate divided by network difficulty. It is identical at every pool, NexusPool included, and nothing in this post changes it. This is not an investment pitch. NexusPool's core software is not open source today, so the technology page describes what the system does rather than a public codebase you can audit line by line. The full terms sit on NexusPool's terms page, not in a blog post. The claim here is narrower and structural: a payment that never passes through a company-held balance has one fewer place to fail than a payment that does.

On the night of September 24, Bitget's engineers stopped the transfers and the numbers on their dashboard stopped moving. The question behind the breach stayed open: whose system decides where the money goes, and can someone fake that decision from the inside? For a coinbase transaction that pays a miner's own address, NexusPool puts no such system in the middle to fool.

Trust nothing. Verify who controls the payment before you need to.