What happened
Bitget confirmed on Wednesday that attackers drained roughly $388 million from exchange-controlled wallets, according to CoinTelegraph's reporting on Q3 industry security data. The exploit is the largest single incident of the quarter and the largest centralized-exchange breach since the FTX collapse in late 2022. Bitget has not published a full post-mortem at the time of writing. The exchange said customer deposits remain backed and that affected funds will be covered by its insurance reserves, though it has not disclosed the current size of that fund or the attack vector.
The $388 million figure lands inside a Q3 total of $1.26 billion in crypto security losses, spread across 247 distinct incidents. September alone contributed roughly $769 million of that - more than 60% of the full quarter. That makes it the worst security month of 2026 by a wide margin.
Why it matters
The Bitget incident flips the narrative that CEX risk had been engineered out of the market. For most of 2025 and the first half of 2026, DeFi protocols were the dominant target: cross-chain bridges, lending markets, oracle manipulation. Q3 moves the center of gravity back to centralized venues. One exchange breach now accounts for roughly 30% of the quarter's total industry losses.
That has two consequences. First, it reopens the proof-of-reserves conversation that cooled off after Binance and OKX standardized Merkle-tree attestations in 2024. Readers should expect new regulator scrutiny on exchange-held customer funds, particularly from the EU under MiCA's custody provisions. Second, it tightens the market's attention on insurance funds. Bitget historically disclosed a protection pool north of $600 million, but on-chain analysts have not independently verified the current balance since mid-2025.
