The point
A crypto hack takes whatever its target was holding, so the place a coin sits decides what a breach can reach. Bitget lost $351.6 million from hot and warm wallet layers while its cold wallets stayed secure, and NEAR Intents lost about $3.8 million to a bug in its deposit system. The coins sat in different places, and each breach took what its own place held.
Where can a holder's coins sit, and what does a hack take at each place?
A coin sits in one of four places: an exchange's hot wallet, an exchange's cold storage, a cross-chain bridge or protocol, or the holder's own wallet. A hack takes what is reachable from the place it breaks into. A hot wallet is a wallet connected to the internet so it can pay out withdrawals quickly. Cold storage is a wallet kept offline.
An exchange's hot wallet
A hot wallet holds the working balance an exchange needs to process withdrawals, so it is online all day. That makes it the easiest place to attack and the place where a breach pays out fastest.
On 24 September 2026 Bitget reported unauthorized transfers of $351.6 million from portions of its hot wallets. Its chief executive, Gracy Chen, said private keys were not compromised. Her account, as reported, was that attackers breached the wallet services backend, forged transfer details and triggered Bitget's own signing process to authorize the transfers (source: Protos).
An exchange's cold storage
Cold storage is offline, so an attacker cannot reach it through a web service. An exchange keeps most customer assets there and moves a small amount at a time to the hot wallet.
In the Bitget incident the cold wallets were reported as unaffected, and the targeted layers were the hot and warm wallets (source: Bankless). The breach reached a system that could request money to move, and it never needed to reach the vault itself.
A cross-chain bridge or protocol
A bridge or a cross-chain trading system is software that moves value between blockchains. Its funds sit inside smart contracts, which are programs that hold and release money by rule. A bug in the rule is a way in.
NEAR Intents, a cross-chain trading system, reported an exploit on 1 October 2026 that caused about $3.8 million in losses. The project attributed it to a bug in how its Omni deposit and withdrawal system interacted with its smart contract. It patched the contract and paused services, along with some deposits and withdrawals. CoinDesk noted the vulnerability involved the cross-chain infrastructure and not the underlying NEAR blockchain (source: CoinDesk).
The holder's own wallet
A wallet the holder controls can't be drained by a breach of an exchange or a bridge, because the keys sit with the holder. The risks move to the holder's side: a lost seed phrase, a copied key, a signature approved on a fake site. Nobody reimburses these, because there is no operator to ask.
Why do large losses cluster at hot wallets, bridges and contracts?
They cluster there because those places are connected to something an attacker can talk to. A hot wallet answers requests to move money. A bridge's contract answers calls from anyone. Cold storage answers nothing.
Neither incident read for this piece began in cold storage. CoinDesk's report on NEAR Intents listed other large incidents of 2026, citing DefiLlama data. Liquid Network lost about $320 million, Drift $295 million and Kelp $293 million, alongside Bitget at over $350 million (source: CoinDesk). This piece reads two of those incidents and makes no claim about the others.
One more detail from the Bitget reports shows why speed matters after a breach. Lookonchain, as reported by Bankless, said the attackers swapped most of the stolen EVM assets into 67,982 ETH, worth roughly $183 million. Ether is harder to freeze than a token an issuer controls (source: Bankless).
What does "we will reimburse" depend on?
A promise to reimburse depends on what stands behind it: a reserve fund, an insurer or the platform's own balance sheet. The promise is worth the size and the access of that backing, so it helps to know which one it is.
Bitget said the full loss falls within its User Protection Fund, which it said holds over $464 million. The arithmetic: $464 million ÷ $351.6 million = 1.32, so the stated fund is about one and a third times the stated loss (source: Protos). Withdrawals were paused while the investigation ran.
NEAR Intents said affected funds will be reimbursed in full. The CoinDesk report does not say what pays for it, so a holder reading it knows the promise and not the backing.
Take a ₹25 lakh crypto holding spread as follows. ₹10 lakh sits on an exchange, ₹5 lakh sits in a token held through a cross-chain protocol, and ₹10 lakh sits in the holder's own wallet. This is an illustration, not a real portfolio.
- ₹10 lakh ÷ ₹25 lakh = 40 percent depends on an exchange's custody and its promise to reimburse.
- ₹5 lakh ÷ ₹25 lakh = 20 percent depends on one protocol's contract holding.
- ₹10 lakh ÷ ₹25 lakh = 40 percent depends on the holder's own key discipline.
Sixty percent of the holding, ₹15 lakh, sits where somebody else's code or custody is in the path. If the operator covers a hack at either place, the holder loses nothing, and if the operator cannot, the holder carries the loss.
What can a holder check on a proof of reserves page?
A proof of reserves page shows what a platform says it holds, usually with a cryptographic method that lets a third party confirm the balance. It answers one question: are the assets there. How the wallets are guarded is a separate question, and it is the one a hack asks.
Two checks come before any trust in one. Ask whether the page covers the assets the platform owes customers, and ask whether anyone outside the platform can verify the figure. Qatobit has written separately on reading one. See how to read a proof of reserves attestation.
What should a holder ask any platform?
Five questions cover the four places and the promise behind them.
- What share of customer assets sits in hot wallets at any time, and what is the rule that caps it?
- Who can authorize a withdrawal, and what checks sit between a request and the signature?
- What backs a promise to reimburse: a reserve fund of a stated size, an insurer, or the balance sheet?
- What does the proof of reserves page cover, and who can check it?
- What happens to withdrawals during an incident? Bitget paused them and NEAR Intents paused services and some deposits and withdrawals, so the answer is part of the product.
A good answer names a number and a mechanism. "Our users' funds are safe" names neither.
How Qatobit holds user assets
Qatobit uses institutional custody. It publishes live Proof of Reserves, available at any time, and user assets are insured. The platform's design separates user funds from operational funds, with the accounting accessible whenever a user wants to verify. The accounting is not behind a request form or a quarterly cycle.
None of this means a holding cannot lose value. Crypto investments carry market risk, and the value of an investment can rise or fall. Custody answers where the assets are held, and market risk is a separate question.
A Crypto Index is a curated basket of digital assets, so an investor in one holds the basket and not a set of coins to store. Qatobit offers four QSI Crypto Indices (QSI Core, QSI Growth, QSI VRION and QSI GEQ8), three of which hold crypto, each rebalanced monthly on a published methodology.
Where to go next
Where a coin sits is half of the question, and the other half is what the platform owes in return. Does proof of reserves prove your crypto basket is backed takes the second half. Four checks for choosing a crypto exchange in India turns the five questions above into a comparison method.
Frequently asked questions
What does a crypto hack take?
A crypto hack takes the assets held at the place it breaks into. Bitget lost $351.6 million from hot and warm wallets, and NEAR Intents lost about $3.8 million through a contract bug. Cold storage and a holder's own wallet were not the entry point in either case.
What is a hot wallet?
A hot wallet is a crypto wallet connected to the internet so it can process withdrawals quickly. Exchanges keep a working balance there. Being online makes it the easiest wallet to attack, so exchanges try to keep it small.
Are coins in cold storage safe from hackers?
Cold storage is offline, so a web service cannot reach it, and Bitget's cold wallets were reported unaffected in its 2026 incident. Safe from one kind of attack is not safe from every risk, because the people and processes that move coins out of cold storage can be targeted too.
If an exchange says it will reimburse, is my money covered?
A reimbursement promise is as good as what stands behind it. Bitget named a User Protection Fund of over $464 million against a $351.6 million loss, a ratio of 1.32. NEAR Intents promised full reimbursement without naming the source in the report read.
Does a proof of reserves page mean a platform cannot be hacked?
No. A proof of reserves page shows what a platform holds, and a hack goes through how the wallets are guarded. Both questions matter, and a page answers only the first.
Crypto investments are subject to market risk. Not financial advice.
“A better allocation begins with a better explanation.”
Qatobit principle
Published construction. Fixed cadence. Versioned control.



