Open app

NexFlow › Is Bitget safe

Is Bitget safe? The second-tier custodian with the biggest stated backstop

Bitget is the largest custodian most non-traders have never heard of — 100M+ claimed users, the copy-trading pioneer, monthly Merkle PoR at 191%, and a protection fund that averaged $561M in April 2025. Its exchange has never suffered a documented user-fund breach since 2018. What its record does contain is more interesting than a hack: a trade rollback that put the CEO's own earlier criticism on trial, and an $8M wallet-arm incident Bitget chose to cover — the rare case of a venue paying for a loss it didn't cause.

Updated September 28, 2026 · By the NexFlow editorial desk · Sources linked throughout; vendor claims labeled.

What Bitget is

Bitget, founded 2018 in Seychelles, is a top-tier global derivatives-and-spot custodian that grew on copy trading — the feature letting retail mirror professional traders — and now claims 100M+ users across 150+ markets. Custody shape is standard CEX: balances are claims, assets sit in platform-controlled cold/hot/multisig wallets, and the safety question splits into "can the venue be breached" and "what happens to users when something breaks." Bitget's stated answers are the most quantified in the second tier: a protection fund that averaged $561M through April 2025 (launched 2022 at $300M), monthly Merkle-tree PoR reporting a 191% overall reserve ratio, and ISO 27001:2022 certification. Vendor figures — but verifiable ones: the fund sits in disclosed on-chain wallets, and the PoR lets users self-verify inclusion.

The unbreached core — and the honest caveat

There is no documented theft of user funds from Bitget's exchange — eight years operating with no Bybit-style incident on record. That earns the same honest caveat this corpus gives every unbreached custodian: a clean record is evidence the defenses have worked so far, not proof of what survives a Lazarus-grade attempt; Bybit was also "unbreached" right up until it became the largest heist in history. What Bitget can legitimately claim beyond rhetoric is the stated mitigation stack — the fund and the PoR are sized against exactly the tail risk the record can't yet answer.

April 20, 2025: the VOXEL rollback

Bitget's documented stress event was market-integrity, not theft — and it's instructive precisely because it shows how the venue behaves when it has to pick winners. Around 08:00–08:30 UTC on April 20, 2025, the VOXEL/USDT perpetual market showed abnormal activity — price spikes, volume briefly exceeding Bitcoin's daily total, orders executing in ways that suggested a professional arbitrage group exploiting the contract (Bitget later alleged >$20M illicit profit and sent eight legal letters). Bitget suspended the contract, froze the suspect accounts, rolled back irregular trades within ~24 hours, compensated users who lost money in the window, and committed to airdropping recovered funds back to the user base.

The irony that makes it worth a full section: weeks earlier Bitget CEO Gracy Chen had publicly criticized Hyperliquid for delisting JELLY during its own manipulation event, warning such interventions "could undermine trust in exchanges." Then Bitget faced the same choice and made the same class of call — freeze, reverse, compensate — which this page reads neither as hypocrisy nor heroism but as the honest admission every centralized venue eventually makes: when the market misbehaves badly enough, the venue steps in, and your protection is the quality of its after-action compensation, not the fiction that intervention never happens.

The BitKeep precedent: paying for someone else's hack

Bitget's wallet arm carries the incident the exchange doesn't. In December 2022, BitKeep — a multi-chain wallet Bitget had invested in and later acquired, now Bitget Wallet — suffered a supply-chain attack: a compromised APK distributed outside official channels let attackers drain roughly $8 million from users who had installed the poisoned build. Bitget's response is the detail that matters on this page: it committed to and completed full reimbursement of affected users — covering a loss on a product it was in the process of acquiring, from an attack vector (a sideloaded APK) that technically sat outside its own infrastructure.

That's a stronger safety signal than a policy page: a venue that pays for adjacent losses it could have disputed has demonstrated the reimbursement reflex at least once for real money. It also draws the honest boundary — Bitget Wallet is a separate product with separate risk (a self-custody wallet whose exposure is build integrity and user-side phishing, not exchange custody), and the fund/PoR figures belong to the exchange, not the wallet.

Where Bitget stands

The dated read: the most-instrumented second-tier custodian — nine-figure on-chain protection fund, 191% monthly-verified reserves, ISO certification, one market-integrity rollback handled with compensation, and one wallet-arm incident it covered voluntarily. The gaps are the standing custodial set plus two honest qualifications: the record is young (2018), and the fund's dollar figure floats with the market — $561M averaged in a strong month tells you less than what it holds in a deep drawdown. Compared to the set: less proven than Kraken, better instrumented than most of its tier, and the only venue here that has now both criticized a rollback and executed one — which is to say, it knows exactly what it owes you when the market breaks.

Frequently asked questions

Has Bitget ever been hacked?

No documented theft of user funds from the exchange exists — breach-free since its 2018 founding per both the record and the vendor. The adjacent incident is BitKeep (now Bitget Wallet): a December 2022 compromised-APK supply-chain attack drained ~$8M; Bitget reimbursed affected users in full despite the attack sitting outside its exchange infrastructure. The honest frame: a clean exchange record plus a demonstrated willingness to pay — and the standing caveat that "unbreached" is a trailing statistic, as Bybit proved.

What is the Bitget Protection Fund?

A dedicated self-insurance reserve launched in 2022 at $300M, held in disclosed on-chain wallets, sized to cover user losses from security incidents or abnormal events. It averaged ~$561M through April 2025 (range $496M–$617M — it floats with asset prices). It's the same instrument class as Binance's SAFU: real, verifiable, and meaningful precisely because it's pre-committed rather than a post-incident promise — with the honest caveat that its USD value is only as durable as the market it's denominated in.

What is Bitget's proof of reserves?

Monthly Merkle-tree attestations reporting a 191% overall reserve ratio (April 2025) across major assets — users can self-verify their balance's inclusion. It proves the assets existed at the checkpoint, which is real transparency; it does not disclose liabilities beyond client balances or guarantee behavior under stress — the universal PoR caveat this family applies to Kraken, OKX, and Binance equally.

What was the VOXEL incident?

April 20, 2025, ~08:00–08:30 UTC: abnormal trading in the VOXEL/USDT perpetual — Bitget says a professional arbitrage group manipulated the contract (alleged >$20M illicit profit; eight legal letters issued). The venue suspended the contract, froze suspect accounts, rolled back irregular trades within ~24h, compensated losing users, and pledged to airdrop recovered funds to the user base. Weeks earlier its CEO had criticized Hyperliquid's JELLY intervention — Bitget then made the same class of call. Read it as: even principled venues intervene when markets break; compensation quality is the real safety metric.

Is Bitget legit or a scam?

Legitimate — a top-tier global custodian since 2018 with verifiable machinery most "scam" venues never bother building: on-chain protection fund, monthly self-verifiable PoR, ISO 27001:2022, and a documented history of compensating users it didn't strictly have to (BitKeep). The scam-shaped risks that do attach to its name are the usual impersonation layer — clone sites, fake "Bitget support" DMs — not the venue itself.

Should you keep funds on Bitget?

Same custodial rule as every venue in this family: it's a trading surface, not a vault. Bitget's stated mitigation stack (fund + PoR + certification) is the second tier's strongest on paper, and its incident behavior has been compensatory both times it was tested — but no protection fund covers a failure mode that outgrows the fund, and the record is eight years, not Kraken's fourteen. Trade on it if the features fit; withdraw what you're holding.

NexFlow is an educational risk tool, not financial advice. On-chain data can be incomplete or manipulated; a clean check is a dated snapshot, not a guarantee. Always do your own research. Free · no signup · a NexFlow product