Source cutoff: September 25, 2026, at 10:15 a.m. Taipei time (UTC+8). This article examines the September 24 incident and the discussion around it on X. It is not a live withdrawal-status page.

A hardware wallet, illustrative Bitcoin coin and key beside an exchange screen
Conceptual illustration of asset custody, not a depiction of this incident or the platform’s interface.

What has Bitget confirmed?

Bitget’s security notice dates the detection of abnormal transfers to September 24 at 18:31 UTC, or September 25 at 02:31 in Taipei. The roughly $351.6 million figure is the exchange’s preliminary estimate of affected funds, not an amount recovered or paid out.

Bitget says the incident affected parts of its hot- and warm-wallet layers, while cold wallets remained secure and deposits and trading continued. These are the exchange’s statements: we have not tested its services or independently audited its assets. The notice makes the resumption of withdrawals conditional on completing a security review, with no firm reopening time.

Source: Bitget: Security notice on the September 24 hot-wallet incident

What are the commentators on X focusing on?

The following views are paraphrased from posts read on September 25. At that time, their X profiles showed approximately 105,000 followers for DCF GOD, 166,000 for The DeFi Investor and 21,000 for 0xLoki. We included 0xLoki because his Chinese-language observations about on-chain activity directly addressed this incident. Follower counts describe an account’s reach; they do not establish that its conclusions are correct.

DCF GOD (@dcfgod) initially questioned the way funds were being swapped. He observed a new address exchanging about 19.67 million USDT0 for 7,111 ETH on Arbitrum and argued that the hurried trades, at a premium, looked unlike an ordinary purchase. His initial post framed this as a question. He later updated his estimate in the same discussion to about $183 million. That was an early on-chain observation, not a substitute for the exchange’s subsequent total.

0xLoki (@0xLoki_Zeng) focused on the window for intervention. He said the attacker was converting BSC assets into BNB, suggested that a cross-chain transfer might follow, and tagged relevant platforms and network participants to urge an attempt to intercept the funds. This was a proposed response. We have no evidence that his suggestion resulted in an interception or recovery.

The DeFi Investor (@TheDeFinvestor) focused on the stablecoin issuer’s response, criticizing Circle for not freezing the relevant USDC. His post quoted an observation by Tay (@tayvano_), so the two do not constitute independent investigations. We have not obtained Circle’s response or records of its actions. We therefore cannot establish when it learned of the addresses or whether timely intervention was possible, and do not treat the commentator’s criticism of its motives as fact.

These perspectives address the detection of unusual transactions, intervention while funds are moving, and the role a stablecoin issuer might play. They help explain the questions the community is asking. The cause of the attack, the amount recovered and withdrawal arrangements still require formal disclosure.

Source: DCF GOD: Original unusual-swap post and subsequent discussion0xLoki: BNB conversion and proposed cross-chain interventionThe DeFi Investor: Criticism of Circle’s responseDCF GOD’s X profile0xLoki’s X profileThe DeFi Investor’s X profile

What do the Protection Fund figures establish?

Comparing the two figures in the exchange’s notice, the estimated $351.6 million loss is about 75.8% of a $464 million baseline. That supports a limited conclusion: using the stated nominal valuations, the fund is larger than the preliminary loss estimate.

The fund’s composition also matters. Its dedicated page lists 5,500 BTC and says its valuation uses the price at 00:00 UTC each day. The dollar value moves with Bitcoin’s price, and claims are subject to investigation results. This is the exchange’s protection arrangement, not bank deposit insurance.

What do the Protection Fund figures establish?
ComparisonAmount or ratioWhat it means
Exchange’s preliminary estimate of affected fundsAbout $351.6 millionMay change after investigation
Fund valuation stated in the noticeMore than $464 millionThe exchange’s figure at the time of the notice
Loss / $464 million baselineAbout 75.8%351.6 ÷ 464; not a payout percentage
Baseline less the preliminary loss$112.4 million464 − 351.6; not the fund’s actual remaining balance

Source: Bitget: Security notice on the September 24 hot-wallet incidentBitget: Protection Fund

Why does a larger fund not mean withdrawals can reopen immediately?

A security incident creates two tasks: replacing lost assets and restoring a trustworthy process for sending funds out. Even if sufficient assets are available to absorb the entire loss, reopening transfers before the compromised part of the system is isolated could expose funds to the same risk. This is an explanation of the mechanism, not a finding about this attack’s technical path.

Assets held in BTC also fluctuate in value. Turning an accounting valuation into funds available for payment depends on actual control, any restrictions, the currencies needed and the ability to mobilize the assets in time. The table is a static comparison; it does not establish that those conditions have been met. We have not obtained evidence of an actual fund disbursement for this incident.

The most useful next development would therefore be a specific reopening plan: which assets and networks will be available, whether withdrawal limits apply, how queued requests will be handled, and what asset disclosures follow the response. Repeating a fund’s total value does not tell account holders when they can move their assets out.

Source: Bitget: Security notice on the September 24 hot-wallet incidentBitget: Protection Fund

Why are both roughly $180 million and $351.6 million being reported?

Wu Blockchain’s timeline summarized early on-chain observations in which tallies for publicly labeled addresses ranged from about $178 million to $190 million. The exchange later announced approximately $351.6 million. The observations may cover different times and addresses. They should not be added together, and the gap alone does not establish an additional theft. We have not recalculated the transactions individually.

The same report notes that a wallet labeled “cold” by an explorer or analyst may not correspond to the exchange’s internal cold-, warm- or hot-wallet categories. Assessing whether cold storage was affected requires evidence about addresses, transactions and wallet architecture. A label alone cannot resolve the difference between external labels and the exchange’s account.

Source: Wu Blockchain: Bitget Hacked Suddenly — Timeline Recap

What can account holders check?

Keep records of account balances, pending withdrawals and transaction IDs. Read notices through the app you already use or an official address you enter yourself. The notice reviewed for this article still described withdrawals as paused; consult subsequent official updates for actual arrangements.

Do not follow requests to transfer funds first, disclose a seed phrase or connect to an unfamiliar website to “unlock withdrawals” or “claim compensation.” The notice cited here did not require those steps, and there is no need to use a stranger to handle the resumption of withdrawals.

This article does not speculate about the attacker’s identity or present unverified technical attribution as a conclusion. The documents to watch are the formal incident report, the affected scope and the remediation measures. The exchange promised a full report within 24 hours; that promise does not establish that the report has been published.

Source: Bitget: Security notice on the September 24 hot-wallet incident

References

Sources consulted: · Editorial policy

Bitget: Security notice on the September 24 hot-wallet incident

The exchange’s own notice supports its reported timing, preliminary estimate and service arrangements. It is not an independent asset or security audit.

Bitget: Protection Fund

The fund page supplies the BTC holding, valuation time and claim conditions. Its live dollar field did not render correctly and was not used.

Wu Blockchain: Bitget Hacked Suddenly — Timeline Recap

A secondary timeline dated September 24, 2026, used to explain differences between early on-chain observations and the exchange’s figures. Address labels are not treated as proof of wallet architecture.

DCF GOD: Original unusual-swap post and subsequent discussion

The full original post and the author’s updates in the discussion were read. X displayed September 25. The figures and suspicious behavior described were the author’s observations at the time.

0xLoki: BNB conversion and proposed cross-chain intervention

The September 25 post was read. A cross-chain transfer was a possibility raised by the author, and interception was a proposal, not a confirmed result.

The DeFi Investor: Criticism of Circle’s response

The September 25 post was read and quotes Tay. It is commentary; this article has not verified the allegations about Circle’s actions or motives.

DCF GOD’s X profile

The profile showed approximately 105,000 followers on September 25. The count can change.

0xLoki’s X profile

The profile showed approximately 21,000 followers on September 25 and included a signup link to another exchange. The commentary is not treated as an independent audit free of commercial interests.

The DeFi Investor’s X profile

The profile showed approximately 166,000 followers on September 25. “Crypto Analyst” is the account’s own description.