Bitget Says It Will Cover Its $352M Hack in Full — Here's How to Tell If That Promise Is Credible
Bitget lost $351.6 million to hackers on September 24, 2026, and says its Protection Fund will make every user whole. Here's the actual checklist for judging whether an exchange's 'your funds are safe' promise after a hack is real — with a side-by-side comparison against Bybit's $1.5B hack and a case where similar promises failed.
On September 24, 2026, at 18:31 UTC, Bitget’s security systems flagged unauthorized transfers draining several of its hot wallets. Within roughly 20 minutes, attackers had moved out $351.6 million in crypto — according to CoinDesk’s reporting, by spoofing the internal transfer-authorization system rather than stealing a private key. CEO Gracy Chen said the attackers compromised the backend that approves withdrawals, not the wallets’ cryptographic keys themselves — a meaningfully different failure mode than a stolen seed phrase. CNBC reported that Bitget suspects North Korea-linked actors, consistent with the group blamed for most large exchange hacks in recent years. Cold wallets were untouched; the breach was confined to hot and warm wallet layers.
Bitget’s response was immediate and specific: it says its Protection Fund — 5,500 BTC, roughly $464 million, held in publicly verifiable on-chain wallets — will cover every user’s loss on a 1:1 basis, on top of over $1 billion in additional company assets. Multiple outlets tracking the fund’s on-chain addresses note the payout would consume roughly 84% of that fund’s total value once the loss is fully assessed.
If you don’t hold anything on Bitget, this is still worth ten minutes of your attention. “We’ll cover it, your funds are safe” is now the standard first response to any exchange hack — Bybit said essentially the same thing during its record $1.5 billion hack in February 2025, and so did several exchanges that later failed to make good on it. The claim itself tells you almost nothing. What tells you something is whether you can check it.
Three different failure modes, and why they don’t call for the same reaction
It’s worth being precise about what actually happened here, because the instinct after any exchange headline is to lump it in with every other exchange horror story. They’re not the same:
Insolvency or fraud (a collapse). The exchange doesn’t have what it owes customers — money was misappropriated, lent out, or never there in the first place. Orionx is a recent example: a shortfall that had been building for years, surfaced by an audit, with no fast path to full recovery. Withdrawals stop and stay stopped.
A peg or bridge break. A wrapped or bridged token stops being reliably redeemable for the asset it claims to represent, as covered in the Liquid Network hack — a backing failure in the token itself, not necessarily in any single company.
An external hack of a solvent exchange. Someone drains funds from outside — a hot wallet exploit, a compromised backend, a smart contract bug — but the exchange has enough capital elsewhere (a dedicated fund, corporate reserves, emergency financing) to make customers whole without touching a cent of what it owed them in the first place. This is what happened to Bitget, and it’s what happened to Bybit in 2025.
The third case is the one people most often misjudge, in both directions — treating it as a full-blown collapse and panicking, or taking “your funds are safe” at face value and not checking anything. It deserves its own checklist.
The credibility checklist for a “we’ll cover it” promise
Run through these before deciding how worried to be, whether or not you personally use the exchange in question.
1. Is the fund actually on-chain and publicly verifiable, or is it a number in a press release? Bitget’s Protection Fund addresses are public, meaning anyone can check the BTC balance directly rather than trusting a claimed figure. A fund you can verify independently is a fundamentally different kind of promise than “we have reserves” with no addresses attached. If an exchange makes this claim without pointing you to something checkable, that absence is itself informative.
2. What percentage of the fund does this specific loss consume? This is the number most coverage undersells. A fund covering a loss that’s 5% of its size is a very different credibility situation than one covering a loss that’s 84% of its size, even if both result in “fully covered” today. The Bitget fund is expected to absorb the large majority of its value in this one incident — it can make users whole this time, but it now has far less capacity to absorb a second incident before being replenished.
3. Does the exchange have capital beyond the dedicated fund? Bitget has pointed to more than $1 billion in additional company assets beyond the Protection Fund itself. A fund plus a genuinely solvent parent company is stronger than a fund alone; a fund that’s effectively the entirety of the company’s liquid capital is a thinner promise wearing the same words.
4. Is there a track record, from this exchange or a comparable one, of actually following through? This is where the Bybit comparison is useful, not as a guarantee Bitget will behave the same way, but as a reference point for what “it worked” actually looked like the last time an exchange this size made the same promise.
| Bitget (Sept 2026) | Bybit (Feb 2025) | |
|---|---|---|
| Amount stolen | $351.6M | ~$1.5B (largest crypto hack on record) |
| Attack method | Spoofed transfer authorization (backend), not private keys | Intercepted a routine cold-to-warm wallet transfer |
| Suspected actor | North Korea–linked (per Bitget, unconfirmed) | Lazarus Group, per Elliptic and a U.S. IC3 advisory |
| Cold wallets affected | No | Effectively yes — the transfer being moved was itself cold-to-warm |
| Reimbursement mechanism | Dedicated Protection Fund (5,500 BTC) + corporate assets | Emergency bridge loans and “whale” deposits to replenish reserves within 72 hours |
| Independent verification | On-chain fund addresses, publicly checkable | Hacken proof-of-reserves audit confirmed over 100% collateralization post-replenishment |
| Outcome (as reported) | In progress; withdrawals paused pending review | Bybit says users bore no financial loss; stolen ETH itself remains largely unrecovered |
The pattern in Bybit’s case is worth noting: the exchange didn’t recover the stolen funds — it replaced them, fast, with outside capital, then proved it had done so with an independent audit rather than just asserting it. That combination — speed plus independent verification, not just a promise — is what separates a credible “you’re covered” from a hopeful one. Bitget is following a similar playbook; whether it completes the same way is something to watch over the coming weeks, not assume from day one.
5. What does the exchange do differently after the review — not just during the crisis? A hack that gets a fast, transparent, fully-verified reimbursement and is followed by a real security overhaul is a different exchange going forward than one that pays out once and changes nothing. This is the slowest-moving part of the checklist, but it’s the one that tells you whether to trust the platform with size again, not just whether this one incident gets made whole.
What to actually do if you hold funds on an exchange that’s just been hacked
Don’t panic-withdraw the moment trading resumes, but don’t ignore it either. Withdrawals are frequently paused during the security review itself, so there’s often nothing to do in the first hours regardless of how you feel about it. Once withdrawals do reopen, test one — an actual withdrawal, not just a balance check in the app — before assuming everything is back to normal.
Watch for the on-chain verification, not just the press statement. If an exchange claims a fund is fully solvent, and the fund’s addresses are public, check the addresses yourself or via a tool that tracks them. This takes a few minutes and turns a trust question into a verification question.
Expect recovery scams to show up immediately. Every major exchange hack is followed within days by “recovery agents” in comment sections and DMs offering to retrieve funds for an upfront fee. This is exactly the pattern described in the aftermath section of how to tell if a crypto exchange is about to collapse, and it applies here just as much as it does to an outright collapse.
Keep your own records regardless of what the exchange promises. Screenshot balances, save transaction history, and keep any official communications — not because you’re assuming the reimbursement will fail, but because if it doesn’t fully materialize the way promised, documentation is the difference between a straightforward claim and a fight later.
The takeaway that outlasts this specific hack
“Your funds are safe” is now the reflexive first sentence of every exchange hack disclosure, regardless of whether it turns out to be true. The words themselves carry no information — Orionx’s customers likely heard some version of reassurance too, before a shortfall that had existed for years finally surfaced. What actually separates a credible promise from a hopeful one is checkable: a fund you can verify on-chain, a sense of how much of that fund this specific loss consumes, capital beyond the fund itself, and a track record — this exchange’s or a comparable one’s — of following through with independent proof rather than just a statement. Apply that checklist the next time a “your funds are safe” headline shows up, because there will be a next time.
FAQ
If an exchange says a protection fund will cover 100% of a hack, does that mean I’ll get my money back? Often yes, but not automatically — it depends on whether the fund is verifiably solvent, how much of it the payout consumes, and whether the exchange follows through over the following weeks rather than just the first 24 hours of a press statement. Treat “covered 1:1” as a claim to verify, using the checklist above, not as a guarantee to relax about.
Is a hack of a still-operating exchange the same risk as an exchange collapsing? No, and the distinction matters for what you should actually do. A collapse — insolvency, fraud, an exchange that simply doesn’t have what it owes customers — usually means withdrawals stop and recovery runs through a liquidation process that can take years and return a fraction of what’s owed. A hack of a solvent exchange with real reserves is a liquidity event, not an insolvency event: the exchange has the money elsewhere to cover the gap, and the question is whether it actually will, quickly and verifiably.
Should I withdraw everything from an exchange the moment it discloses a hack? There’s rarely a clean answer, since withdrawals are often paused during the security review anyway. Once withdrawals reopen, testing a real withdrawal — not just checking your balance in the app — is the single most useful thing you can do.
If a protection fund ends up not covering my full loss, is that treated as a tax-deductible loss? Possibly, but the mechanics are unusual — you may need to treat it as a partial capital loss and a partial reimbursement, or wait until the exchange’s process formally concludes before any shortfall is treated as final. This is not tax advice, and it’s a case where professional guidance matters more than usual.