Bitget publishes a Proof of Reserves (PoR) roughly once a month, using a Merkle tree so each user can check that their balance was counted. On 24 September 2026 Bitget reported unauthorized transfers from some of its hot wallets, and the first question most users asked was whether reserves are still sufficient. This guide uses the official data behind Bitget's PoR page to lay out the latest total reserve ratio and the BTC, ETH, USDT and USDC ratios, the trend over the last six months, how the Merkle tree works and how to verify it yourself. It then follows Bitget's own announcements for the incident timeline, the withdrawal restoration schedule and the Protection Fund. All figures were checked on 2026-09-28. The incident is still being handled, so Bitget's official announcements are the source of truth for the latest status.
Key takeaways
- The latest PoR snapshot is 2026-09-16 00:00 (UTC+8): total reserve ratio 135%; BTC 133%, ETH 160%, USDT 100%, USDC 140%. This snapshot is from before the 24 September incident, and as of the check date Bitget had not published a post-incident round.
- Merkle tree, self-published: neither the official PoR page nor the GitHub documentation lists a third-party auditor's report. Users can verify their own inclusion with Bitget's open-source tool.
- Hot wallet incident: Bitget's first estimate on 24 September was about $351.6 million, revised on 25 September to about $387.5 million. Bitget says cold wallets were not affected, user balances are unaffected and the loss is covered by the Protection Fund; under the schedule Bitget has announced, withdrawals are set to resume in phases by coin from 28 September.
- Protection Fund: the official page shows 5,500 BTC; the 24 September notice put its value at over $464 million at that time.
- Users in Taiwan: Bitget is not on the FSC's VASP AML registration list. A PoR is a transparency measure the exchange publishes itself; it is not regulatory supervision.
A PoR shows that at the moment of the snapshot the exchange held at least as much as its users' balances. It does not reflect events that happen after the snapshot.
Latest proof of reserves: the 2026-09-16 snapshot
The table below comes from the official public data used by the Bitget Proof of Reserves page (audit ID Au2026091600), checked on 2026-09-28. Reserve ratio = the amount of a coin Bitget holds on-chain ÷ users' balances in that coin on the platform.
| Coin | User balances | Platform reserves | Reserve ratio |
|---|---|---|---|
| BTC | about 27,657 BTC | about 36,779 BTC | 133% |
| ETH | about 121,427 ETH | about 193,902 ETH | 160% |
| USDT | about 1.195 billion | about 1.199 billion | 100% |
| USDC | about 102 million | about 142 million | 140% |
| Total (four main coins, USD) | about $4.496 billion | about $6.072 billion | 135% |
Three things to note:
- USDT sits right at 100%: reserves exceed user USDT by about 0.3%, which the page shows as 100%. A 100% ratio means fully backed; anything above that is extra held by the exchange.
- BTC reserves span several chains: in the same round most BTC sits on the Bitcoin mainnet (about 35,498 BTC), with smaller amounts on BNB Smart Chain, the Lightning Network and others.
- This round's breakdown lists 19 coins: besides the four above it includes LINK, LTC, DOGE, XRP, SOL, ADA, SUI, BNB and more, each at 100% or higher. The previous round (2026-08-20) listed only BTC, ETH, USDT and USDC.
Total reserve ratio over the last six months
The same official data source keeps the latest 12 rounds. The last six (times in UTC+8):
| Snapshot | Total ratio | Platform reserves (USD) | User balances (USD) |
|---|---|---|---|
| 2026-09-16 00:00 | 135% | about 6.072 billion | about 4.496 billion |
| 2026-08-20 22:00 | 122% | about 4.591 billion | about 3.767 billion |
| 2026-07-20 17:00 | 122% | about 4.556 billion | about 3.721 billion |
| 2026-06-15 16:00 | 123% | about 4.925 billion | about 4.003 billion |
| 2026-05-20 08:00 | 127% | about 5.567 billion | about 4.385 billion |
| 2026-04-17 10:00 | 130% | about 5.441 billion | about 4.193 billion |
Rounds come roughly monthly at varying times. According to the official data, the total ratio in every round is based on the same four coins (BTC, USDT, ETH and USDC); the September round additionally lists single-coin ratios for 15 more coins. Totals move with prices and user holdings, so comparing a single coin across rounds (BTC 133% vs 134%, for example) is more meaningful.
How Bitget's PoR works: a self-published Merkle tree
The official page describes three steps:
- Verify address ownership: open-source tools are used to verify the wallet addresses holding reserves and confirm Bitget owns them.
- Snapshot user balances: each user's total assets across all wallets at the snapshot time.
- Build the Merkle tree: each user's ID and balance are hashed, then paired upward until a single root hash (the Merkle root) remains.
According to Bitget's official GitHub documentation, each leaf is the SHA-256 hash of the encrypted UID, a per-user nonce and the coin balances, truncated to 16 characters; each parent hashes its two children together with their summed balances. Changing any user's balance changes the root, so if the root you compute matches the published one, your balance is in that tree.
Note that as of 2026-09-28, neither the PoR page nor the GitHub documentation lists a report from an accounting firm or third-party auditor. It is a self-published PoR that users can verify. That does not mean the numbers are wrong; it just means the liabilities side (user balances) is compiled by the exchange itself.
How to verify it yourself: two ways
Option 1: "My proof of assets" on the official page
The PoR page has a "My proof of assets" entry; after logging in you can view your own proof for a snapshot, and the page lets you switch between rounds to see each root hash and reserve ratio. It is the simplest route, but the result is still displayed by the exchange.
Option 2: verify offline with the open-source tool
- Download the official verifier for your system (Linux amd64/arm64, macOS or Windows).
- Unzip it to a folder such as
~/Downloads/proof-of-reserves-*. - Download your Merkle path file
merkel_tree_bg.jsonfor that round and replace the file of the same name in the folder. - Run
start.sh(on Windows, clickstart.bat). - "Consistent with the Merkle tree root hash. The verification succeeds" means you passed; "Inconsistent" means it failed.
If you code, you can skip the executable and write your own check from the published hashing rules, computing from your leaf up to the root.
Verification only tells you that your balance is in this round's tree. Whether the reserves really sit on-chain has to be checked against the published reserve figures, which an ordinary user cannot fully do with this tool alone.
The 24 September 2026 hot wallet incident: official timeline
This section only summarizes Bitget's own announcements and leaves out anything Bitget has not confirmed. The incident is ongoing, so check Bitget's official announcements for the latest status.
| Announcement | Key points |
|---|---|
| 24 Sep security notice | Unauthorized transfers from some hot wallets detected at 18:31 UTC; first estimate about $351.6 million; cold wallets unaffected; withdrawals paused, deposits and trading running |
| 25 Sep incident update | About $387.5 million confirmed moved to attacker-controlled addresses; vulnerability identified and fixed; Mandiant and SlowMist assisting; recovery bounty launched |
| 26 Sep phased withdrawals | Schedule for resuming withdrawals by coin; user balances unaffected; the Protection Fund covers the financial impact of this platform-wide incident |
What Bitget has said
- Scope: Bitget runs a three-tier wallet architecture and says only part of the hot and warm wallet layers was affected; cold wallets are secure. Affected assets span Ethereum and several EVM networks, the XRP Ledger, Zcash and TRON, including XRP, ETH, USDT, ZEC, USDC, USDT0, XAUt, BNB, AVAX and TRX.
- Why the figure went up: the 25 September update says the revision adds affected assets on Zcash and TRON that were missing from the first estimate; it does not reflect new unauthorized transfers, and the incident is contained.
- User balances: the 24 and 26 September notices both state that account balances are accurate and unaffected, and that the loss falls under the Protection Fund as a platform-wide incident.
- Recovery bounty: 5% of successfully frozen funds to whoever directly caused the freeze, and 5% of successfully recovered funds to whoever directly caused the recovery. Actions under court orders or law-enforcement requests are excluded, and Bitget decides eligibility and amounts.
Planned withdrawal restoration schedule (26 Sep notice, UTC)
| Time (UTC) | Coin | Networks |
|---|---|---|
| 28 Sep 08:00 | BTC | Bitcoin |
| 29 Sep 08:00 | ETH | Ethereum, BSC, Arbitrum, Base, Optimism |
| 30 Sep 08:00 | USDT | Ethereum, BSC, Solana, Tron |
| 2 Oct 08:00 | Other tokens, fiat, P2P | — |
In Taiwan time (UTC+8) that is 16:00 on each date. Bitget says users do not need to do anything beforehand and that availability will show directly on the platform; it also announced a live AMA with CEO Gracy Chen at 07:30 UTC on 28 September. As of the check date (2026-09-28), Bitget's announcement list had no incident update newer than 26 September.
This schedule is the plan Bitget published on 26 September and may change; check the official announcements and the coin status in the app before withdrawing.
How the incident relates to the PoR
As of 2026-09-28, Bitget's latest PoR is the 2026-09-16 snapshot (before the incident), and no newer round has been published. So:
- The 135% in the 16 September round describes the pre-incident position and cannot be read as the post-incident position.
- Subtracting the loss from the reserves to estimate a current ratio is not recommended: the coins involved, flows after the snapshot, and whether and how the Protection Fund is used have not yet been published as a PoR.
- The more reliable approach is to wait for the next round and check whether the single-coin ratios for affected assets such as XRP, ETH, USDT and USDC are still at or above 100%.
Protection Fund: 5,500 BTC
The Bitget Protection Fund page shows 5,500 BTC, valued daily at the 00:00 UTC price, so its dollar value moves with BTC; the 24 September notice put it at over $464 million.
- When it applies: the page says users whose accounts are compromised or whose assets are stolen or lost because of platform-wide events not attributable to their own actions or trading behavior may make a claim.
- Case by case: Bitget reserves the right to assess each claim, and payouts depend on the investigation.
- What it does not cover: leaking your own password, falling for phishing or trading losses are not platform-wide events.
As of the check date Bitget had not announced whether the fund will be topped up or resized after the incident; the page still shows 5,500 BTC. Check that page for the latest figure.
What Bitget's PoR covers and what it does not
These are general limits of Merkle-tree PoR at any exchange, not a comment on Bitget specifically.
What it can show
- How much the exchange held in its on-chain addresses at the snapshot.
- That your balance was included in the user liabilities (via your Merkle path).
- Whether reserves in each coin cover users' balances in that coin.
What it cannot show
- Anything after the snapshot: a PoR is a photo of one moment; changes between rounds are not captured.
- All liabilities: the Merkle tree covers user balances; other liabilities such as loans are outside its scope.
- Whether assets are pledged or lent: holdings are visible on-chain, other commitments are not.
- Operational and security risk: a PoR cannot prevent events like a hot wallet breach.
A PoR is one tool for checking an exchange; read it together with the protection fund, wallet architecture and how transparently the exchange communicates, rather than relying on one ratio.
What you can do on your own account
- Trust only official channels: Bitget's footer links to "Verify official channels" and an "Anti-scam hub". If you receive messages or links claiming to help "unfreeze" funds or "claim compensation", check them there first.
- Turn on security settings: check in your account security settings whether two-factor authentication, an anti-phishing code and a withdrawal whitelist are enabled.
- Never share API keys or verification codes, including with anyone claiming to be a rebate platform or support agent.
For users in Taiwan
Bitget is not on Taiwan's FSC list of virtual asset service providers that have completed AML registration (list version 2026-09-03). A PoR is a transparency measure the exchange publishes itself; it is separate from whether an exchange is supervised in Taiwan. See offshore exchanges and Taiwan's VASP register.
How this relates to fee rebates
Binding a rebate only needs your UID; the rebate platform never touches your account or assets, so reserve and security risk is the same with or without a rebate. See is a crypto fee rebate safe. On Bitget, binding code NOVA888 through Quant Nova gives new users a 40% rebate at Lv.1, 45% at SVIP and up to 50% (Supernova, invite-only). Rates and worked examples are in the Bitget fee rebate guide, and you can bind on the Quant Nova rebate platform.
FAQ
What is Bitget's latest reserve ratio?
As of 2026-09-28 the latest round is the 2026-09-16 00:00 (UTC+8) snapshot: total 135%, BTC 133%, ETH 160%, USDT 100%, USDC 140%. It predates the 24 September incident.
Has Bitget published a new PoR since the hot wallet incident?
Not as of the check date. The latest round is still the 16 September snapshot; when the next one appears, look at the single-coin ratios for the affected assets.
Were my funds affected by the incident?
Bitget's 24 and 26 September notices say account balances are unaffected and the loss is covered by the Protection Fund, and the announced schedule resumes withdrawals in phases by coin. For your own account, rely on what the app shows and official support.
When do Bitget withdrawals resume?
Under the schedule in the 26 September notice: BTC on 28 Sep, ETH on 29 Sep, USDT on 30 Sep, other tokens and fiat on 2 Oct, each at 08:00 UTC (16:00 Taiwan time). Actual timing follows Bitget's announcements and the platform.
Is Bitget's PoR audited by a third party?
As of 2026-09-28 neither the PoR page nor the GitHub documentation lists a third-party auditor. Bitget publishes the Merkle tree and reserve figures monthly and users verify with open-source tools.
How big is the Protection Fund and who can claim?
The page shows 5,500 BTC, with a dollar value that moves with BTC (over $464 million per the 24 September notice). It applies to platform-wide events not attributable to the user, assessed case by case.
Reserve figures are from the official public data behind Bitget's Proof of Reserves page, and incident details are from Bitget's official announcements, checked on 2026-09-28. The incident is ongoing and reserve figures update each round; the official pages and announcements always take precedence. This article is information only, not an assessment of any exchange's safety or investment advice.