Crypto

Bitget Says $388 Million USD Was Taken. Disclosed Freezes Add Up to 0.2%

·
Bitget Says $388 Million USD Was Taken. Disclosed Freezes Add Up to 0.2%

Bitget reopens Ethereum withdrawals today, five days after an attack on its wallet systems that the exchange now estimates affected approximately $388 million USD. The freezes disclosed so far across the chains that money moved through come to $823,000 USD, about 0.2% of Bitget’s own estimate of the loss, roughly one fifth of one percent.

That ledger is partial by its own terms. Two freezes have been disclosed publicly, and one of the four flows below was attempted rather than executed. What the week does settle is this: the protections written into Canada’s rulebook are built for one failure, the platform going under. Bitget did not go under. Coins were taken from a platform that stayed solvent and says it covered its users in full, which is a different accident with a much thinner set of answers behind it.

What Bitget says happened

Bitget’s incident timeline puts the unauthorized transfers late on September 24, 2026, flagged by its reconciliation system about half an hour later, contained roughly two hours after they began, and traced to a root cause the next morning. The company describes the amount affected as “currently estimated at approximately $388 million”, across “12 wallet addresses associated with hot or warm wallets.”

On method, Bitget says the attacker exploited a vulnerability in a third-party security product “to potentially obtain high-level internal credentials”, then used them to send “fraudulent withdrawal commands” the wallet system executed. Private-key compromise is ruled out and cold wallets were not affected. There is a 5% bounty on any amount frozen or recovered. Bitcoin withdrawals resumed on September 28, Ethereum today, and the rest by October 2.

The freezes disclosed so far

Set beside the flows that were not blocked, the disclosed freezes describe the machinery.

What moved Amount Outcome
NEAR Intents, attacker swap attempts more than $50,000,000 USD attempted $503,000 USD frozen mid-trade; $166,000 USD passed through
Circle and Tether, stablecoins not disclosed about $320,000 USD frozen by the issuers
THORChain, ETH to BTC swaps about $6,300,000 USD routed through on September 28 nothing blocked; request refused
XRP, roughly 103 million coins about $160,000,000 USD (at $1.54 USD per coin, CoinDesk, September 26) about $83,000,000 USD moved out of the holding wallets; cannot be frozen

NEAR Intents froze $503,000 USD mid-trade and let $166,000 USD through, out of more than $50 million USD the attacker attempted to swap. A swap attempted and never executed is not the same as one that got through, and these figures do not separate them, so what screening itself stopped is not established here. The rows are pieces of the total rather than the whole of it, and most of what Bitget says was taken has not been publicly traced.

The other disclosed freeze was stablecoins, because Circle and Tether are the issuers of those tokens and built blacklist controls into them, which they used, and native chain assets have no equivalent switch. Per CoinDesk on September 26, the XRP Ledger “lets companies freeze tokens they issue on it, but that power does not extend to XRP itself.” The same is true of Bitcoin and of Ethereum, so recourse after a theft is possible on issued tokens and absent on the coins most people hold.

Two protocols answered the same request differently

Bitget chief executive Gracy Chen publicly asked THORChain to refuse service to the attacker’s addresses. THORChain declined on September 28, saying it does not censor by design and that the network-wide halt it can trigger is not a tool for targeting one wallet: “A halt is not a selective freeze of specific funds or an individual swap.” It has been consistent about it: when THORChain was itself exploited for $10.7 million USD in May, the attacker’s addresses were never blacklisted either. Security researchers push back that its validator-controlled vaults give it more room to intervene than it admits.

NEAR Intents took the other side, screening swaps through a system it calls SHIELD, where in general manager Alex Shevchenko’s words “the protocol can decide how to handle a transaction.” It also said it would waive its share of Bitget’s bounty so the exchange could recover more. The cost is the mirror image of the benefit, because a protocol that decides how to handle a transaction sits between a holder and their own funds, which is the machinery THORChain refuses to build.

Bitget’s users were made whole, by a fund Bitget assesses itself

Chen said the Protection Fund holds more than $464 million USD and that over $1 billion USD in company assets back user balances 1:1. Bitget says no customer was left out of pocket. Against the revised $388 million USD estimate, the fund leaves roughly $76 million USD of cushion, a third less than it left against Bitget’s earlier and lower estimate.

The fund is also a claims process rather than an entitlement: Bitget’s terms say it “reserves the right to assess each claim in relation to platform-wide incidents.” It worked because a private company chose to honour it and had the balance sheet to, which is a good outcome and not the same thing as an obligation.

Bitget is not registered with the Saskatchewan regulator

The Financial and Consumer Affairs Authority of Saskatchewan said in an investor alert on Bitget and CapTex on July 10, 2025 that neither is “registered with the FCAA to trade or sell securities or derivatives in Saskatchewan.” The alert points investors to the Canadian Securities Administrators’ National Registration Search at aretheyregistered.ca. For a Canadian holding coins there, neither route into Canadian protection is open: the exchange is not registered with that regulator, and CIPF coverage runs through firms that are CIRO members.

Where Canadian coverage stops, in CIPF’s own words

Registration decides which rulebook a platform trades under. Coverage is a separate question that does not follow from it, because CIPF pays out on the insolvency of a CIRO member firm, and even then it stops short of the coin. Per CIPF’s own coverage rules, the fund covers “missing property”, meaning property a member firm held for you and does not return after its insolvency. Limits run to $1 million CAD for all general accounts combined, the bucket that holds TFSAs and FHSAs, $1 million CAD for all registered retirement accounts combined, and $1 million CAD for all RESPs combined.

Crypto is excluded by name. Coverage does not extend to “crypto assets held by a member firm on your behalf that are missing at the time of the member firm’s insolvency.” CIPF is a custody backstop rather than a loss backstop, and the event it answers is insolvency rather than theft. Deposit insurance does not reach the coin either. CDIC insures eligible deposits up to $100,000 CAD per category and names cryptocurrencies, including stablecoins, among the products it does not cover.

What a registered Canadian platform puts in writing

Wealthsimple, which calls itself “the first regulated crypto trading platform in Canada”, sets out its arrangements in its help centre directly. It holds client crypto in trust, “which means in the unlikely event something happens to us, your crypto is protected. This is because property held in trust is protected from claims by creditors.” The majority of client crypto sits with regulated third-party custodians it says carry appropriate insurance and capital, and it says client crypto is protected against crimes like hacks or theft through insurance held by it and its custodial partners. Cash in a crypto account is CIPF-covered because Wealthsimple Investments Inc. is a CIRO member, and the same pages add: “Crypto assets aren’t covered by CIPF.” Our Wealthsimple review covers the account types and fees.

That is the mismatch in miniature. The trust structure answers a platform collapsing, and the CIPF cash coverage answers a member firm failing with your money inside it. Neither answers an attacker with working credentials at a platform still open for business, and against that the answer on offer is private insurance, with the word “majority” doing real work above, because some client crypto sits elsewhere.

Holding your own keys moves the risk rather than removing it

There is one more place a coin can sit: a wallet whose keys you hold. What Bitget describes did not begin with stolen private keys. It began with credentials inside a platform sending withdrawal commands the wallet system obeyed, and that failure needs a platform in the middle to happen at all.

Take the platform out and the rest goes too. There is no member firm, so no CIPF claim to make and no insolvency for CIPF to answer. There is no corporate protection fund and no custodian’s insurance, because there is no company and no custodian. What replaces all of it is you, and a lost key or a bad signature has no claims process behind it. Self-custody answers theft from a platform, and answers nothing else.

The one route that sits inside the coverage

A security held in a brokerage account is eligible CIPF property. A coin a platform holds for you is not. The difference is not diligence, it is what you own. A crypto-linked equity is a security, and so is a TSX-listed fund holding coins for its unitholders. The Canadian crypto stocks on the TSX are the equity end of that. Either way the coverage runs through the firm you open the account with, not the ticker you buy, which is where CIRO membership matters and why our guide to opening a brokerage account in Canada is worth reading first.

It answers the dealer-insolvency question and nothing else. It does not protect the price, and it does not mean nobody can be hacked, because a fund still holds coins with a custodian somewhere.

Where Bitcoin and Ethereum are trading

Our intraday snapshot at 07:05 ET on September 29, 2026 had Bitcoin at $83,906.67 USD, up 0.48%, and Ethereum at $2,714.28 USD, up 0.95%. In Canadian dollars, $119,188.36 CAD and $3,853.37 CAD. Both are higher on the day.

The uncomfortable part is that the offshore holders came out fine. Bitget says it covered them in full, out of a fund it assesses itself, which is a better result than CIPF would have produced for a coin. A discretionary payout that lands is still not an entitlement, though, and the next one is decided by whoever is holding the money at the time. What a Canadian can point to instead was built for a firm failing rather than a thief getting in, and CIPF, the fund a Canadian would turn to, does not cover the coin itself. Neither route protects the coin. They differ in who decides, which is worth knowing before something goes wrong rather than after.


Disclaimer: The content on bestcanadianstocks.ca is for informational and entertainment purposes only and does not constitute financial advice. Past performance is not indicative of future results. Always consult a qualified financial advisor before making investment decisions.