Bitget's security systems flagged unauthorized transfers out of the exchange's hot and warm wallets at 18:31 UTC on September 24, 2026. By the time the company had a handle on the scope, an estimated $351.6 million in assets had moved out, a figure industry reporting has already described as one of the largest crypto exchange hacks of the year. Some outlets have put the number closer to $350 million or $352 million depending on rounding and timing, but Bitget's own figure, and the one used throughout this article, is $351.6 million.
If you hold crypto on Bitget, the practical questions are straightforward: is your balance actually affected, do you owe anything to the IRS because of this, and what should you be saving right now in case the situation doesn't resolve the way Bitget says it will. This case looks different from a typical exchange hack, because Bitget's CEO has publicly guaranteed full reimbursement through the company's own protection fund rather than leaving affected users to absorb a loss. That changes the tax analysis considerably from cases where stolen funds never come back.
Key Takeaways
- Bitget lost an estimated $351.6 million from hot and warm wallets: the September 24, 2026 breach did not touch cold storage, where the company says the bulk of its reserves sit.
- The attacker didn't steal private keys: Bitget's CEO says a compromised backend system was used to spoof transfer data and trigger the exchange's own withdrawal-authorization process instead.
- Bitget has publicly guaranteed full reimbursement: the loss is covered by the company's User Protection Fund, which it says holds more than $464 million, more than the amount affected.
- Withdrawals are paused with no confirmed restart date: deposits and trading have continued throughout, and Bitget says it won't commit to a timeline it can't guarantee.
- A North Korea link is suspected, not confirmed: Bitget cites preliminary IP-address evidence tied to VPN services previously associated with a North Korean hacking group, but has stopped short of calling that established.
What Happened: The Bitget Hack, Step by Step
Bitget detected the breach on the afternoon of September 24, 2026, when its security systems flagged unauthorized transfers moving out of parts of its hot and warm wallet infrastructure. The company suspended withdrawals within hours as a precaution while it assessed the damage, and it has kept deposits and trading running throughout the investigation.
| Time (UTC) | Event |
|---|---|
| September 24, 18:31 | Bitget detects unauthorized transfers from parts of its hot and warm wallet infrastructure. |
| September 24, later | Bitget suspends withdrawals as a precaution. Deposits and trading continue. The company confirms cold wallets are unaffected and estimates roughly $351.6 million moved out. |
| September 24-25 | CEO Gracy Chen states the loss is fully covered by the User Protection Fund and that user funds are safe. |
| September 25 | Chen says the attack used spoofed backend transfer data rather than a stolen private key, and says Bitget suspects North Korea-linked actors based on preliminary IP evidence. |
Bitget's own security notice lays out the same sequence and adds that an emergency response team was activated within minutes, with the affected transfer addresses flagged and reported. The notice also states that relevant authorities and on-chain security firms have been formally notified, though it doesn't name which ones.
Keep your own record of what you held
If you had funds on Bitget when the breach happened, CoinTracking shows you exactly what was in your account beforehand, timestamped and ready if you ever need to back it up.
Not a Private-Key Theft: How the Attack Actually Worked
Most headline crypto hacks trace back to a stolen private key or a phished seed phrase somewhere in the chain. Bitget says this one didn't work that way. In a statement, CEO Gracy Chen said the attacker "compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out." Chen has been explicit that a private key compromise has been ruled out.
That distinction matters for how you think about the incident. Bitget describes its wallet setup as a three-tier architecture, and the company's official notice says the breach reached only a portion of the hot and warm wallet layers, not the cold wallets where it says the bulk of its reserves sit. Cold wallets stay offline and disconnected from the systems an attacker would need to forge a transfer through, which is why Bitget frames them as unaffected regardless of what happened in the hot and warm layers.
Chen has also said investigators found preliminary evidence pointing toward state-linked actors: IP addresses tied to VPN services previously associated with a North Korean hacking group. She has stopped short of calling that confirmed, describing it as a lead the investigation is still working through rather than an established fact. Nothing about that attribution is settled as of this article's publication, and it's worth treating it that way until Bitget says otherwise.
Are Your Funds Safe? The User Protection Fund and the Reimbursement Promise
Bitget's central claim is that no user ends up out of pocket. Chen says the company's User Protection Fund holds more than $464 million, comfortably above the $351.6 million affected, and that this fund covers the loss in full. She has stated plainly that user funds are safe. Account balances, she says, continue to reflect actual holdings accurately, meaning nobody's recorded balance was altered by the breach itself.
Being made whole and being able to withdraw right now are two different things, though. Withdrawals remain suspended while Bitget completes its security review, and as of September 25 there's no confirmed restart date. Chen has said the goal is a full restart as soon as possible, adding that "we will not commit to a timeline we cannot deliver." Deposits and trading have kept operating the entire time, so the disruption so far is about withdrawal access, not about your balance disappearing.
Bitget also committed to publishing a full incident report, including a root-cause analysis, within 24 hours of its first notice, putting the deadline at roughly 21:30 UTC on September 25. As of this article's publication, that report had not yet gone live. If it publishes with different details than what's described here, treat the official report as the more current source.
Do You Owe Tax on Crypto Held on Bitget During the Breach?
If your crypto sat on Bitget when this happened, you don't owe tax because of the breach itself. The IRS's digital asset guidance centers on selling, exchanging, or otherwise disposing of a digital asset, not on an exchange having a security incident while you hold funds there. A hack you didn't choose and didn't cause isn't a disposal, so it creates no gain or loss to report on its own.
Two things stay true no matter how this resolves. Any gains you already recognized before September 24, from an earlier trade or from staking or other rewards, were taxable when you received them and remain taxable regardless of what happened to Bitget's wallets afterward. And because Bitget says your recorded balance wasn't changed by the breach, there's currently nothing for most users to report differently than they would have anyway.
Reimbursement might not always mean simply restoring frozen access. If Bitget instead pays someone through a token swap or another substitute, that structure could carry its own tax treatment. Nothing like that has been described so far. Bitget's stated plan is straightforward fund-backed coverage of the shortfall, not a swap or replacement program.
Document your holdings properly
CoinTracking imports your transaction history from over 400 exchanges, wallets, and blockchains, so your cost basis and timestamps are already on record if you ever need them.
Can You Deduct Anything If the Reimbursement Falls Through?
This question only becomes relevant if Bitget's reimbursement promise doesn't hold up for you specifically, and right now nothing published suggests that's happening. Still, it's worth understanding the law in case your situation ends up different from the general case.
A theft-loss deduction, whether for crypto or anything else, generally requires a genuine, unrecovered loss with no reasonable prospect of getting the money back. The IRS's own guidance on casualty and theft losses confirms that personal-use property losses are deductible only when tied to a federally or state-declared disaster. A wallet breach doesn't clear that bar. Crypto held for investment sits in a different category. IRS legal guidance on scam and hack victims confirms a theft-loss deduction can still apply there, disaster or not. It requires a genuine profit motive and no reasonable prospect of recovery.
That last part is exactly what a public, funded reimbursement guarantee undercuts. A company stating it holds more than $464 million and intends to cover a $351.6 million shortfall in full is a real prospect of recovery. That is the opposite of what a theft-loss deduction requires. Form 4684 splits personal-use property (Section A, gated by the disaster requirement) from investment property (Section B, no disaster requirement). For most people affected by this specific breach, neither section has anything to attach to yet, because Bitget hasn't described anyone as permanently out funds.
That could change if reimbursement is denied, materially delayed beyond what Bitget has promised, or doesn't fully cover a specific account. If that happens to you, talk to a tax professional before claiming anything, since the facts of your case, not a general rule for this incident, will determine what's deductible.
Outside the US, the rules differ by jurisdiction, and a public reimbursement guarantee like Bitget's may be weighed differently depending on where you file. Australia's Tax Office, for instance, publishes its own guidance for loss or theft of crypto assets, worth checking if you file outside the US.
What to Document While the Investigation Is Still Open
Whether or not a deduction ever becomes relevant, good records protect you either way. If reimbursement is delayed, partial, or disputed for any reason, you'll want proof of exactly what you held and when, rather than a memory of what your account looked like before September 24.
- Balance before September 24: a timestamped screenshot or export showing exactly what you held on Bitget immediately before the breach.
- Transaction history and cost basis: acquisition dates and cost basis for anything you held on the exchange, calculated the same way as any other taxable event.
- Official statements: save your own copy of Bitget's security notice and any follow-up updates, since official pages get edited as an investigation continues.
- Correspondence about withdrawals or reimbursement: keep every message and date if Bitget contacts you directly about your account.
- A clear timeline: when you acquired the crypto in question, when the breach happened, and when you learned about it.
A CoinTracking import handles most of this automatically for anything already connected to your account. Every trade, deposit, and transfer carries its own timestamp and cost basis, so the record already exists if you ever need it, rather than something you have to reconstruct from memory months later.
What This Means for You: Three Scenarios
Exchange hacks generally fall into one of two categories: a hot wallet gets drained through a stolen key, or, as Bitget describes here, an attacker forges legitimate-looking authorization data without ever touching a key at all. Either way, the underlying question for anyone holding funds on a centralized exchange is the same: how much of your holdings sit in systems connected to the internet, and what happens if that layer gets compromised.
Scenario A: You Hold Funds on Bitget
Save everything listed above now, while Bitget's notices and your own records are still easy to find. Check Bitget's official channels for withdrawal updates rather than third-party rumors, and don't assume a specific tax treatment before speaking with a professional. Documentation protects you whether the situation resolves exactly as promised or not.
Scenario B: You Don't Use Bitget
Your holdings were never exposed to this specific breach, but the underlying lesson still applies to any exchange you do use. Centralized platforms keep some portion of assets in hot or warm wallets to process withdrawals and trades quickly, and that connected layer is inherently a different risk category than offline cold storage, regardless of which exchange operates it.
Scenario C: You're Deciding Where to Hold Crypto Going Forward
A centralized exchange and self-custody carry different kinds of risk, and this incident is a useful data point for weighing them rather than a verdict on either approach. An exchange concentrates operational risk in its own hot-wallet infrastructure and how it authorizes withdrawals. Self-custody removes that layer but puts the entire burden of key management on you. Neither model is risk-free, and understanding which kind of risk you're accepting is the point, not assuming one option is automatically safer.
Conclusion
Bitget's own numbers make this look recoverable rather than catastrophic for individual users. The company reports a $351.6 million shortfall against a protection fund it says holds more than $464 million, cold wallets that stayed untouched, and a public commitment to make affected balances whole. Until the investigation closes and withdrawals actually resume, your best move is proof: what you held before September 24, your cost basis, and copies of every official update. That way, whichever direction this ends up going, you're not the one left reconstructing the story from memory.
Keep your records ready for whatever comes next
CoinTracking has tracked crypto portfolios and calculated taxes for over 2.2 million users since 2012, across more than 400 exchanges, wallets, and blockchains. Import your history once, and you're ready the next time an exchange has a bad week.
Disclaimer
This article is for general informational purposes only and does not constitute financial, tax, or legal advice. The facts of this incident were current as of the article's publish date and may change as Bitget's investigation continues. Tax treatment of exchange breaches and any related reimbursement depends on your individual circumstances and on current law, which can change. Readers should consult a qualified tax professional before making decisions based on the information presented here. The author and publisher are not responsible for any losses or damages incurred as a result of using the information in this article.