On-chain researchers flagged a suspected security breach affecting Bitget Wallet users on September 24, 2026, with more than $170 million in assets moved out and swapped into ETH. The alert came from blockchain analyst account WuBlockchain, which described the incident as a suspected breach rather than a confirmed exploit. Bitget had not published a public cause or a final loss figure at the time of writing.
The pattern the trackers described, mixed tokens draining from multiple wallets and consolidating into a single asset, is a common signature after a mass compromise. Attackers frequently convert stolen holdings into ETH because it is liquid, easy to move across bridges and mixers, and hard to freeze once it leaves a centralized chokepoint. That consolidation step is often the first visible sign of an incident, before any team confirms the root cause.
The custody line that gets blurred
Bitget runs both a centralized exchange and a separate self-custody product, Bitget Wallet. The two are not the same thing, and the distinction matters for anyone trying to gauge their exposure. Exchange balances sit with Bitget. Wallet balances sit with the user, secured by a private key or seed phrase that the user controls.
That design is the whole point of a self-custody wallet: no company can move your funds, and no company failure can freeze them. The trade-off is that the security burden shifts to the user and to the wallet software itself. A compromised signing library, a malicious token approval, a poisoned dApp connection, or a front-end hijack can drain a non-custodial wallet without the provider ever touching the keys. Until Bitget states a cause, it is not possible to say which layer failed here, or whether the losses trace to the wallet software, individual user approvals, or something else.
A rough month for wallet security
This incident lands in a stretch of similar events. Earlier in September, on-chain sleuths tracked nearly $20 million in XRP drained from thousands of wallets in a multi-wave attack, and researchers warned that an iPhone Safari zero-day could expose seed phrases directly from the device. Gate separately flagged FomoPeek iOS malware built to steal wallet logins. The through-line is that the attack surface has moved off the exchange and onto the endpoint: the phone, the browser, the approval a user signs without reading.
The wider market barely registered the news. ETH traded at $2,686, up 0.5% on the day, while BTC held near $84,233, essentially flat, as of September 24, 2026. A $170 million wallet drain is severe for the affected users but small against Ethereum's roughly $328 billion market cap, so the swap into ETH did not move the price.
Steps that reduce your exposure now
The practical response does not depend on Bitget's post-mortem. If you hold assets in any browser or mobile hot wallet, review your active token approvals and revoke anything you no longer use, since open approvals are a frequent drain vector. Move balances you are not actively spending to a hardware wallet or another cold-storage setup. Treat any unexpected transaction prompt or "verification" request tied to this event as a phishing attempt, because attackers routinely follow a public incident with a wave of fake recovery pages.
The same logic applies to spending products layered on top of wallets. Crypto cards that draw from a connected self-custody balance inherit that wallet's security posture. Convenience at the point of sale does not remove the key-management responsibility that sits underneath it.
Overview
More than $170 million in assets was flagged draining from Bitget Wallet users on September 24, 2026, and swapped into ETH, in what on-chain trackers called a suspected breach. Bitget had not confirmed a cause or a final figure at the time of writing, so the failed layer, wallet software, user approvals, or something else, remains unclear. The event fits a September pattern of endpoint-level wallet attacks, and the immediate user response is to revoke stale approvals, move idle funds to cold storage, and ignore any recovery prompts that follow.



