Skip to main content

Wallets and self-custody

Bitget Raises Hack Loss Estimate to $387.5 Million: What Custodial Risk Actually Means

Bitget revised its hack loss estimate to $387.5 million and paused withdrawals. Here is how exchange custody works and why it matters.

8 min read27 September 2026CryptoBipto editorial

Bitget Raises Hack Loss Estimate to $387.5 Million: What Custodial Risk Actually Means

A number moved, and it moved in the wrong direction. Bitget, a centralized cryptocurrency exchange, revised its estimate of losses from a recent security breach upward to $387.5 million. Alongside that revision, the exchange outlined a plan to restart withdrawals, which are currently unavailable to users. The timeline and the full details of how the attack happened are still developing.

That upward revision is the part worth sitting with. An initial loss figure after a breach is a first guess made under pressure. It gets refined as forensic work continues, as stolen funds are traced across chains, and as the exchange reconciles what it thought it held against what it can actually account for. Sometimes the number goes down. Here it went up.

You can read the running coverage of the incident on our news page for this story, and the original reporting at NewsBTC.

The rest of this piece is not really about Bitget. Exchange incidents recur, and the specific names change. What does not change is the underlying mechanic: what it means when someone else holds your crypto, why a withdrawal can be switched off, and what "we will make users whole" is and is not.

The word that explains everything: custody

Custody means control of the private keys.

A private key is a long secret number. Whoever knows it can move the coins associated with it. There is no manager to appeal to, no password reset, no identity check. The key is the ownership. Everything else in crypto is a wrapper around that fact.

When you hold crypto in a self-custody wallet, you hold the key, usually in the form of a recovery phrase of twelve or twenty-four words. You sign your own transactions. Nobody can freeze you, and nobody can help you if you lose the phrase.

When you hold crypto on a centralized exchange, the exchange holds the keys. Your balance on the screen is a database entry — a record of what the exchange owes you. That record is a claim, not a coin. The actual coins sit in wallets the exchange controls, usually pooled with everyone else's in what is called an omnibus wallet: one large pot, with an internal ledger tracking who is owed what.

This is not a scandal. It is how exchanges work, and it is what makes them fast. Moving value between two users inside an omnibus system is a database update, not a blockchain transaction. No fee, no confirmation wait. The convenience is real.

The trade-off is also real. When the pot is the target, your claim is exposed to what happens to the pot.

Hot wallets, cold wallets, and where the breach usually lands

Exchanges split their holdings roughly into two categories.

  • A hot wallet is connected to the internet. It funds withdrawals automatically, in seconds, all day. Keys must be reachable by live software, which means they exist in an environment that is online and therefore attackable.
  • A cold wallet is kept offline. Keys live on hardware that never touches the internet, often behind multi-person approval. Moving funds out is slow and deliberate by design.

Most exchanges keep a small share of assets hot and the large majority cold. The hot wallet is the operational float. So when you read about a nine-figure exchange loss, the interesting question is which layer broke.

Historically, large exchange losses have tended to involve one of a few patterns: compromise of the signing process for large transfers, compromise of internal staff credentials or devices, a flaw in the software that authorizes withdrawals, or an attacker gaining enough access to make a fraudulent transfer look legitimate to the systems that approve it. In the Bitget case, the research available does not yet establish which of these applies. The exchange has not published a verified technical post-mortem, and independent auditors have not yet weighed in. Anyone telling you confidently how it happened right now is guessing.

If you want a structured tour of how funds get taken across the wider industry — from contract-level exploits to approval drainers to key compromise — our lesson on DeFi scams, rug pulls, drainers and major hacks walks through the attack families and how each one is detected after the fact.

Why withdrawals get switched off

A withdrawal pause is the single most alarming thing an exchange can do, and it is also a standard step after a breach. Both things are true.

From the exchange's side, pausing serves several functions at once. It stops the attacker from using normal withdrawal rails to launder stolen funds out through user accounts. It freezes the ledger so forensic accountants can reconcile the books against on-chain reality without the target moving. And it prevents a disorderly run, where everyone withdraws at once and the last people in the queue find the float empty.

From the user's side, it means a balance on a screen that cannot be turned into anything. That is the moment where the abstract phrase "counterparty risk" becomes concrete.

Counterparty risk is the risk that the other party to an arrangement cannot deliver what they owe you. It is not exotic. It is the same category of risk you take on with any institution that holds something on your behalf. In crypto, it is more visible because there is no deposit insurance in the background and because the assets can move irreversibly in a single transaction.

It is worth separating this from a different kind of withdrawal delay you will encounter in crypto, because the words look identical. On some blockchain scaling systems, withdrawals are delayed by protocol design rather than by a company's decision. Optimistic rollups, for instance, impose a challenge period — typically around seven days — during which anyone can submit a fraud proof to dispute a bad exit. Our lesson on optimistic rollups, fraud proofs and withdrawal windows covers how that works. That kind of delay is a rule written in code and known in advance. A post-breach exchange pause is a discretionary decision made by a company in an emergency. Same word, completely different mechanism.

What "we will cover user losses" actually is

Reporting indicates Bitget has committed to covering user losses. The details of any reimbursement process have not been independently verified.

This is a category of promise worth understanding on its own terms, because it comes up after almost every major exchange incident.

A commitment to cover losses is a corporate promise backed by corporate resources. Whether it can be honoured depends on things outsiders usually cannot see: how large the company's own reserves are relative to the loss, whether there is insurance and what it actually covers, whether the shortfall is concentrated in one asset, and whether the business generates enough revenue to absorb the gap over time.

Some exchanges have absorbed large losses fully and continued operating for years afterwards. Others have made the same promise and failed to deliver. The promise itself does not tell you which case you are in. What tells you more, over time, are verifiable things: a published technical post-mortem, third-party audit confirmation, on-chain evidence of reserves being topped up, and whether withdrawals actually resume at full capacity rather than in a throttled trickle.

A related tool you will see referenced is proof of reserves — a cryptographic attestation that an exchange holds assets matching user balances. It is genuinely useful, but it has a known limitation: it shows assets at a moment in time and generally does not show liabilities the exchange owes elsewhere. An exchange can pass a proof-of-reserves check and still be in trouble if it has borrowed heavily against those assets.

The part that happens in your head

There is a reason breaking news about a frozen exchange feels physically uncomfortable, and it is not irrationality. Human decision-making weights losses more heavily than equivalent gains — a well-documented asymmetry usually called loss aversion. Combine that with an unresolved situation, a countdown you do not control, and a feed full of speculation, and you get a state that is poorly suited to careful reading.

The predictable consequence is that this environment attracts secondary scams. After every large incident, fake "recovery" services, fake support accounts, and fake compensation-claim forms appear within hours. They ask for a recovery phrase or for a wallet connection that grants spending approval. They are targeting the exact emotional state the news creates. No legitimate exchange recovery process requires your seed phrase.

Our lesson on the neuroscience of FOMO and loss aversion goes into why the brain responds this way to unrealised losses, including during periods when nothing can be done until an external process completes. Understanding the mechanism does not remove the feeling. It does make it easier to notice that you are inside it.

The concepts to take away

Six months from now, the Bitget figure will be a footnote and some other headline will be live. These parts will still hold:

ConceptWhat it means
CustodyWhoever controls the private key controls the coins
Omnibus walletPooled exchange funds; your balance is a claim on the pool
Hot vs coldOnline float versus offline reserve; the hot layer is the exposed one
Counterparty riskThe risk that the party holding your assets cannot deliver them
Proof of reservesEvidence of assets at a point in time; usually silent on liabilities
Loss aversionLosses register more strongly than gains, which shapes behaviour under stress

Self-custody removes counterparty risk and replaces it with operational risk — lost phrases, damaged devices, signing a malicious transaction, inheritance problems. Neither arrangement is risk-free; they are different risks with different failure modes. Trade-off analysis of this kind is a recurring skill in crypto, and it shows up in unrelated corners too: our lesson on impermanent loss and LP risk modeling applies the same habit of naming the exact mechanism before estimating exposure.

What we know here is narrow: the estimate was revised to $387.5 million, withdrawals are paused, a restart plan exists without a confirmed timeline, and a reimbursement commitment has been reported but not independently verified. Everything beyond that is still being investigated.

CryptoBipto is an education platform. Nothing here is financial advice, and nothing here is a recommendation about any exchange, asset, or course of action. We explain mechanisms so you can evaluate situations yourself.

CryptoBipto — editorial standards

Start at the level that suits you and learn at your own pace.