Bitget Exchange
Bitget
Data verified on unchanged since the sources
Worth it if you want copy trading and a broad listing (800+ coins), backed by a $300M user protection fund.
Avoid it if oversight comes first for you: the Seychelles base offers weaker protection than Coinbase or Kraken.
A custodial exchange known for copy trading and a very broad lineup, with 800+ assets, futures up to 200x leverage and a $300M user protection fund. The downside is its Seychelles base and a weaker regulatory footprint than Coinbase or Kraken.
Data & conditions
| Maker / Taker fee | 0.1% / 0.1% |
|---|---|
| Markets | Spot + Derivatives |
| Max leverage | 125× |
| Supported assets | 800+ |
| Fiat on-ramp | Yes |
| Staking / Earn | Sì, prodotti Earn e staking disponibili |
| Fund custody | Custodial (platform holds funds) |
| KYC | Full |
| Supported countries | EEA, APAC, LATAM, MENA, AFRICA · 100+ countries |
| Regulator | FinCEN, VASP Poland, Lithuania, Bulgaria, El Salvador |
| OAM Italy registration | Yes |
| Segment | B2C |
| MiCA / License status | VASP multi-paese pending |
Strengths
- Copy trading leader; 800+ crypto; $300M protection users; 200x leverage futures.
- No notable sovereignty advantage documented.
Weaknesses
- Sede Seychelles; regulation inferiore a Coinbase/Kraken.
- Custodial: the platform holds your funds and can freeze or lose them.
- Full KYC required: verified identity, zero pseudonymity.
- Subject to regulation (pending): reporting to authorities and freezes on order.
Verdict
The good rating reflects breadth and baseline protection: 800+ assets, 0.10% fees and a $300M user protection fund that cushions extreme events. What caps the score is the regulatory framing, still pending and Seychelles-based, weaker than Coinbase or Kraken: for the ordinary user the lineup is rich but oversight is thinner.
Custodial with full KYC and a privacy score of 3: funds stay with the exchange and identity is verified, so on self-custody and privacy the judgment drops sharply. The 200x leveraged futures and copy trading are engagement levers, not sovereignty tools, and move nothing on the trustless front.
Promp's editorial rating based on real fees and net annual cost. Promp reviews third-party products independently.
"Sovereignty" rating: score computed on privacy/anonymity (30%), fund control (20%), censorship resistance (20%), trustless/auditability (20%) and costs (10%). Same data, different weights.
Reputation
What happened to people who used Bitget Exchange, and what users say. External signals: they do not feed the promp.it rating.
Incidents & regulatory actions
Notable incidentsDocumented events with consequences still open. Each entry carries a source and a date.
-
Hack / funds theft Critical $352M ● open
Unauthorised transfers from Bitget's hot wallets: about 351.6 million dollars across seven chains, withdrawals still suspended. Backend system compromised, private key theft ruled out
On 24 September 2026 at 18:31 UTC, Bitget's security systems detected unauthorised transfers from some of the exchange's hot wallets. Three hours later, at 21:30 UTC, CEO Gracy Chen published the official security notice: "Estimated funds affected: approximately $351.6 million", with cold wallets declared intact ("Bitget operates a three-tier wallet architecture — the breach contained only a portion of the hot wallet and warm wallet layers") and the loss declared fully covered by the User Protection Fund, which the company says holds over 464 million dollars. The official @bitget account relayed the notice at 21:34 UTC, the Chinese version at 21:32, and at 22:28 UTC the CEO went live. Deposits and trading remain operational; withdrawals are suspended as a precaution. UPDATE, 25 SEPTEMBER. In the hours that followed the company said considerably more than it had promised, and it is worth separating what it has established from what it suspects. The attack vector, undisclosed yesterday, is now stated: at 00:43 UTC on 25 September Chen wrote that "the attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out". In other words the transfers were signed by the exchange's own normal procedure, which saw them as legitimate. The company states that private key compromise is ruled out — the difference between a signing stack broken into and a signing stack deceived — and declares the bleeding stopped: "No further unauthorized transfers are possible". How the intrusion happened remains under investigation, however: the root cause has not been found, and the full technical report promised within 24 hours has not yet appeared. The scope is far wider than it looked yesterday, and that dissolves most of the gap between the figures. In the three-hour-plus livestream summarised by the CEO at 05:42 UTC, Bitget listed seven chains — Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC and Base — and named XRP, not ETH, as the largest single-chain loss; press that followed the livestream puts it at roughly 102.9 million XRP (about 157.5 million dollars) and 31,890 ETH (about 85.8 million), alongside USDT, USDC, USDT0, Tether Gold, BNB, AVAX and TRX. Last night the on-chain analysts who first flagged the movements — Bubblemaps, Arkham, the DCF GOD account — counted between 183 and 192 million: they were watching the Ethereum side, barely a quarter of the declared total. The two numbers were not contradictory, they measured different things. It remains true that the 351.6 million is the company's own estimate and that nobody has independently verified it. On who did it, the company offers a hypothesis and presents it as one: on the livestream Chen said the behavioural patterns of the IP addresses and the on-chain signatures are consistent with techniques used by North Korea-linked groups, while stressing the attribution is not confirmed; on-chain investigators following the case point to the Lazarus Group. Read it for what it is: a suspicion voiced by the victim, not a fact established by an authority. Bitget also says it has contacted the foundations of every affected chain and that some have already frozen the attacker's addresses. One point worth putting in writing, because much of the smaller press headlined the opposite: Bitget Wallet, the self-custody wallet, runs on infrastructure completely separate from the exchange and the company states it was not affected. Headlines about a "Bitget Wallet breach" confuse the exchange's on-chain wallets with the product called Bitget Wallet: they are two different things, and in the second the keys sit on the user's device. What we verified ourselves rather than reporting: overnight between 24 and 25 September we queried a public Ethereum node on the two destination addresses named by the analysts — 0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee, the main one, and 0x469Ac1406dE92f82C0563477240a3627057425DC, the secondary — at block 26050895: they are effectively empty (0.008793 ETH, 0.001090 USDT and 0.002613 USDC on the first; 0.000716 ETH and no stablecoins on the second). The funds are not sitting there, they have already moved. That is the figure that supports the "ongoing" label better than any headline. Where things stand at 07:42 CEST on 25 September: withdrawals remain suspended and the company gives no restoration window ("we will not commit to a timeline we cannot deliver"); no reimbursement has been made. On capacity, Bitget has raised the stakes, declaring over 464 million dollars of protection fund "all held in publicly verifiable wallets" plus over a billion in its own assets, with user funds covered 1:1 and "all figures verifiable on-chain": that is a step up from yesterday, when the fund was just a number — but the announcement does not list the addresses, no third party has yet performed that verification, and announced coverage is not a completed refund.
↗ source
verified on
Public reviews
-
App Store ↗
4.6/5
5,442 reviews
Exact figure from the US App Store ('Bitget- Trade bitcoin & crypto', BG LIMITED, id 1442778704) via the iTunes Lookup endpoint.
Weighted average across 1 public review platform (5,442 reviews in total), weighted by volume. This is not our rating: it is those platforms’ average.
FAQ
What are Bitget Exchange's fees?
On Bitget Exchange, spot fees are maker 0.1% / taker 0.1%. They drop with monthly volume and VIP tier.
Is Bitget Exchange regulated in Europe?
Bitget Exchange's MiCA authorisation is in progress. It is listed in the Italian OAM register. Licence: VASP multi-country.
Does Bitget Exchange publish Proof of Reserves?
Bitget Exchange publishes Proof of Reserves. No third-party reserve audit is documented. Reserve transparency is a critical factor after the FTX collapse.
Can I send transfers to third-party IBANs from Bitget Exchange?
No, Bitget Exchange is an exchange and does not allow transfers to third-party IBANs: fiat withdrawals return to a bank account in your own name.
Does Bitget Exchange support derivatives and futures?
Bitget Exchange offers derivatives trading, with up to 125x leverage.
Sources
- Official service page Maker/taker fees · Regulatory framework · Derivatives · Founders · +14 Data verified on Jun 15, 2026
- organismo-am.it Data verified on Jun 15, 2026
- pitchbook.com Stock ticker · Stock listing · IPO date Data verified on Jun 15, 2026
- tracxn.com Investors Data verified on Jun 15, 2026
Update history
🔔 Notify me of changes
If you sign up from here we earn a commission, at no extra cost to you. It doesn’t change the rating: we tell you so you can check us.