Bitget’s $352 Million Hack Sharpens Dubai’s Crypto-Security Test

Bitget’s $351.6 million theft and withdrawal suspension show why wallet security, verified reserves and regulatory status matter to Dubai’s crypto market.

Sep 28, 2026 - 03:02
0
Bitget’s $352 Million Hack Sharpens Dubai’s Crypto-Security Test
Bitget’s $352 million crypto theft raises exchange-security questions for Dubai’s digital-asset market.

The theft and temporary suspension of withdrawals show why exchange solvency, wallet controls and regulatory status matter as Dubai builds a globally significant digital-asset market.

Cryptocurrency exchange Bitget suspended customer withdrawals after approximately $351.6 million in digital assets was stolen from several wallets, renewing questions about how regulators and investors should assess the security of centralised trading platforms.

Bitget detected unauthorised transfers on September 24, according to chief executive Gracy Chen. The Seychelles-based company subsequently stopped withdrawals while investigating the incident.

Chen said the exchange would absorb the loss and that customer balances were protected. “Withdrawals remain temporarily suspended as a security precaution, not because of any shortfall in funds,” she told Reuters.

Those assurances remain company claims until independently verified. Bitget has not publicly disclosed a complete forensic report identifying the attack method, affected assets, wallet architecture or responsible party. It has also not published audited evidence demonstrating how the loss will be covered.

The incident has direct relevance for Dubai even though Bitget does not appear in the Virtual Assets Regulatory Authority’s public register of licensed providers reviewed for this article.

Bitget has actively sought a greater regional presence, while Dubai increasingly competes to become a centre for exchanges, custodians and institutional digital-asset services. The latest theft demonstrates why attracting platforms must be accompanied by rigorous scrutiny of their reserves, cybersecurity and ability to continue serving customers during a crisis.

A large balance sheet does not prevent operational failure

Bitget says it serves more than 120 million users, placing it among the world’s largest crypto platforms by claimed customer base.

Scale can provide financial resources for reimbursing users, but it does not remove technological or governance risk.

Centralised exchanges typically control wallets holding assets belonging to many customers. Some funds remain in online “hot wallets” so the platform can process deposits and withdrawals quickly. Their internet connectivity makes them more operationally convenient—and more exposed to attack—than offline storage.

The unanswered question is how the attacker obtained sufficient authority to transfer approximately $352 million.

Possible explanations in exchange breaches can include compromised private keys, manipulated transaction-approval systems, malicious insiders, social engineering or weaknesses in software supplied by an external vendor. No conclusion about the Bitget incident should be drawn until forensic evidence is released.

The distinction matters for regulators. Replacing a compromised key is different from repairing a governance system in which one employee, device or supplier can authorise transfers without effective independent checks.

A credible post-incident report should explain how the attack occurred, why preventive controls failed and whether the same weakness affected additional wallets.

Withdrawal suspensions transfer risk to customers

Temporarily halting withdrawals can prevent an attacker from extracting further assets and give investigators time to isolate affected systems.

It also illustrates a fundamental difference between holding assets directly and leaving them with an exchange.

Customers whose withdrawals are suspended cannot move their tokens, meet obligations elsewhere or sell through another platform. Even if account balances remain visible, users depend on the exchange restoring access.

This counterparty risk is often obscured during normal trading. It becomes obvious only when a platform encounters a cyberattack, liquidity shortage or legal restriction.

Bitget’s statement that it will cover the loss is therefore important, but solvency and liquidity are separate questions. An exchange might possess assets exceeding its liabilities while still lacking immediate access to sufficient liquid reserves to meet withdrawals.

Public wallet data can verify some on-chain holdings but rarely provides a complete financial picture. It may not reveal conventional-currency liabilities, loans, pledged assets, legal claims or obligations spread across corporate affiliates.

Proof-of-reserves exercises are useful only when matched against independently verified liabilities and supported by controls showing that reported assets are owned by the relevant customer-facing entity.

Dubai’s framework addresses custody—but implementation is decisive

VARA requires licensed virtual-asset service providers to comply with activity-specific and cross-sector rules covering custody, technology, risk management and client assets.

Custodians must maintain control of assets placed with them and follow safeguarding requirements. The framework also restricts the reuse of custody assets and requires client-property protections.

Technology rules impose governance and resilience obligations, while VARA’s public register allows users to check which entities are licensed and which activities they may perform.

These protections are material. A company may be authorised for brokerage without holding a custody licence, for example, or may use another regulated institution to safeguard assets. Customers should consequently check the precise permissions rather than relying on a Dubai office, innovation programme or general claim of regional presence.

Licensing cannot guarantee that a provider will never be hacked. Its purpose is to reduce the probability and impact of failure by requiring controls, capital, reporting and accountable local management.

The Bitget case suggests several questions regulators should ask of every exchange handling customer assets:

  • How much value can be moved from a hot wallet before additional approval is required?
  • Are transaction-signing devices and personnel separated across locations?
  • Can unusual withdrawals be stopped automatically?
  • How frequently are wallet controls tested independently?
  • Is insurance available, and what exclusions apply?
  • Can the company finance customer withdrawals while absorbing a major loss?

Answers should be supported by evidence rather than marketing descriptions such as “institutional-grade security”.

Exchange hacks remain highly concentrated

Bitget’s loss follows a series of large attacks against crypto infrastructure.

TRM Labs estimated that $2.87 billion was stolen across nearly 150 crypto hacks in 2025. The $1.46 billion Bybit breach accounted for approximately half that total, demonstrating how a single compromised platform can dominate annual losses.

Its research found a record number of incidents during the first half of 2026, even though the total amount stolen remained below $1 billion during that period. The figures indicate that falling aggregate losses do not necessarily mean attacks are becoming less frequent.

Centralised organisations have become attractive targets because successful access to a small number of transaction-signing systems can unlock enormous value.

Blockchain transparency helps investigators trace funds after they move. It does not automatically recover them. Attackers can divide assets among thousands of addresses, exchange them across blockchains or route them through services designed to conceal ownership.

Fast coordination between exchanges, stablecoin issuers, blockchain-analytics companies and law-enforcement agencies is therefore essential. A delay of several hours can materially reduce the amount that can be frozen.

Dubai must compete on trust, not licence numbers

Dubai’s digital-asset strategy depends partly on attracting international exchanges and trading firms. A broad licensed ecosystem can create skilled employment, investment and deeper links between conventional finance and tokenised markets.

Rapid expansion also increases supervisory demands.

Every additional platform introduces new technology, corporate structures and international dependencies. A provider may serve Dubai customers through one entity, hold their assets through another and operate its wallet infrastructure from a third country.

Responsibility can become unclear when a breach occurs. Customers need to know which legal entity owes them assets, which regulator oversees it and where they can seek redress.

The most effective response is not to claim that licensed exchanges are invulnerable. It is to demonstrate that they maintain stronger controls, provide clearer disclosures and restore customer access more reliably when systems fail.

Bitget says its own resources will protect users from the latest loss. The decisive evidence will be whether withdrawals resume without customer shortfalls and whether the exchange publishes a sufficiently detailed investigation.

For Dubai, the incident reinforces a simple principle: the credibility of a crypto centre is established not when markets are rising, but when a platform loses hundreds of millions of dollars and customers discover exactly what their protections are.

sources

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Abdul Ahad

Finance news and analysis writer with two years of experience covering markets, AI, cryptocurrency, fintech, blockchain, investment trends, and digital economy developments for global readers.

Comments (0)

User