What happens to your funds when a crypto exchange is hacked
What follows an exchange breach: withdrawal freeze, the protection-fund question, phased reopening, the incident report, and what to do in the first 24 hours, with Bitget, Bybit and FTX as cases.
Key facts
- In a hot-wallet hack your account balance is usually untouched; what you lose first is access, because every serious exchange freezes withdrawals within minutes of detection.
- Whether you are made whole depends on reserves the exchange held before the hack, not on anything it does afterward: Bitget (2026), Bybit (2025), KuCoin (2020) and Binance (2019) paid users in full; WazirX (2024) socialised a 45 percent loss; FTX (2022) and Mt. Gox (2014) users waited years.
- Withdrawals typically reopen in phases by asset and network; Bitget took four days to reopen BTC and eight days to reopen everything.
- A credible exchange publishes a root-cause report naming the compromised component; Bybit did within days, Bitget promised one within a week.
- In the first 24 hours: do not sell into the panic, change your password if the exchange says credentials were exposed, ignore every 'recovery' message, and check the exchange's official notice page rather than social media.
Exchange hacks follow a pattern. Knowing it in advance is the difference between a calm week and a panicked one, because most of what happens is not up to you. This guide walks through the sequence using the cases we have documented, above all the Bitget breach of September 2026, which we traced in a five-part series.
Hour zero: the exchange finds out
Exchanges learn of a hack in one of two ways: their own reconciliation flags balances that do not match, or an on-chain analyst posts about unusual outflows. Bitget’s risk system flagged the discrepancy 34 minutes after the first fraudulent transfer; Arkham and Bubblemaps posted about it two hours later. Either way, the first public sign is usually a tweet from the CEO, followed within an hour by a support-centre notice.
What you will see: withdrawals stop working, often with a generic “maintenance” message, before any announcement. Deposits and trading usually continue.
The first day: freeze and reassurance
Within hours the exchange will say some version of “user funds are safe.” That sentence means two different things and it is worth separating them.
Your balance is safe is almost always true after a hot-wallet hack. The attacker drained the exchange’s wallets, not your account ledger. Bitget stated that “account balances are accurate” on the first night and it was true; nothing in any user account changed.
Your money is safe depends on one number: whether the exchange held reserves larger than the loss before the hack happened. This is not something it can fix afterward.
| Exchange | Year | Loss | Outcome for users |
|---|---|---|---|
| Bitget | 2026 | $387M | Covered by a $465M protection fund; withdrawals reopened in phases from day 4 |
| Bybit | 2025 | $1.5B | Covered by treasury and loans; withdrawals never stopped |
| WazirX | 2024 | $235M | 45% of user balances written down; partial repayment over a year |
| DMM Bitcoin | 2024 | $305M | Users compensated, but the exchange was wound down and accounts transferred |
| KuCoin | 2020 | $280M | Fully covered; most funds recovered with token issuers’ help |
| Binance | 2019 | $40M | Covered by SAFU fund within days |
| FTX | 2022 | $8B shortfall | Bankruptcy; repayments began in 2025 |
The pattern is simple. Exchanges with a published protection fund or audited reserves larger than any plausible hot-wallet loss pay in full. Exchanges without them socialise the loss or fail. This is why the exchange ranking lists fund size and proof of reserves, and why our safety guide tells you to check them before depositing rather than after.
Days one to three: the investigation
Expect a preliminary explanation within a day and a promise of a full report. Bitget said “backend system compromised, private keys not leaked” on the first night, “third-party security product zero-day” on day four, and promised the Mandiant and SlowMist report for the following week. Bybit named the compromised Safe{Wallet} front-end within 48 hours.
Two things happen in this window that matter to you:
- Credential rotation. If the attacker had internal access, the exchange revokes and reissues internal credentials. It may also force users to re-authenticate or reset passwords. Do it when asked; do not do it from a link in an email.
- The freeze race. The exchange contacts stablecoin issuers, other exchanges and blockchain foundations to freeze what it can. Stablecoins can be frozen by their issuers, native assets such as ETH, XRP and BTC cannot. In Bitget’s case the attacker converted all stablecoins to ETH within 23 minutes, and most of the stolen XRP was inside Binance deposit accounts within four days. Freezes recover a few percent at best; do not count on them.
Days three to ten: phased reopening
Withdrawals come back asset by asset, usually starting with the exchange’s largest and simplest network. Bitget’s schedule: BTC on day 4, ETH on day 5, USDT on day 6, everything else on day 8. Bybit, unusually, never paused. WazirX kept withdrawals closed for months.
During this phase the exchange will typically say the loss is covered and the fund will be replenished. Bitget committed to topping its protection fund back up to $300 million within a week from corporate reserves. That commitment, and whether it is kept, tells you more about the exchange’s finances than any marketing.
What to do in the first 24 hours
- Read the exchange’s own notice page, not screenshots on social media. Every major exchange posts to a support-centre URL; bookmark it now.
- Do not panic-sell. Trading usually stays open, and the token of a hacked exchange (BGB fell about 3 percent) tends to recover if the loss is covered. Selling into the first hour locks in the panic price.
- Ignore every message about recovery. Nobody from the exchange will DM you. “Recovery services” that appear after a hack are the second wave of the scam, as our scams guide explains.
- Check your account for unfamiliar API keys, devices or withdrawal addresses, in case the breach extended to user data. Rotate your password if the exchange tells you credentials were exposed.
- Decide your withdrawal plan calmly. When withdrawals reopen, move whatever you do not actively trade to a hardware wallet. Use a whitelisted address you have tested, not one typed in a hurry.
What the report should tell you
A post-incident report worth the name answers four questions: which component was compromised and how; why the signing pipeline accepted the fraudulent instructions; why detection did not stop the outflow sooner; and what changed. Bitget’s own timeline shows three hours and thirteen minutes between detection and signing shutdown, during which the attacker kept withdrawing. If a report does not address that kind of gap, the exchange has not learned the lesson, and you should size your balance accordingly.
The habit that makes all of this manageable
Keep on any exchange only what you would be comfortable not touching for two weeks. Every other precaution in this guide is about managing a bad week; that one prevents it from being a bad year.
Questions
Can I lose my balance in an exchange hack?
In a hot-wallet hack, no: the attacker takes coins from the exchange's wallets, not from your account record, and your balance stays as it was. You lose money only if the exchange cannot cover the shortfall and becomes insolvent, or if it decides to socialise the loss across users as WazirX did in 2024.
Why do exchanges freeze withdrawals after a hack?
Because the pipeline that signs withdrawals is the thing that was compromised. Until the exchange knows how the attacker inserted transfers, reopening withdrawals could let them do it again. Bitget kept withdrawals closed for four days while it rotated credentials and rebuilt the signing flow.
Should I withdraw everything as soon as withdrawals reopen?
Withdraw what you do not need for active trading, calmly. If the exchange has covered the loss from its own fund and published a credible report, the risk of a second loss is lower than the risk of rushing funds to an unfamiliar address under stress.