BC.GAME promotional banner

Bitget Hack Explained: Full Timeline, $388M Loss and Recovery Updates

17–25 minutes

Last Updated:

October 1, 2026

iPhone displaying the Bitget app on the Apple App Store

Bitget Hack Explained: Full Timeline, $388M Loss and Recovery Updates

iPhone displaying the Bitget app on the Apple App Store

Bitget Hack Explained: Full Timeline, $388M Loss and Recovery Updates

Disclosure: The author trades primarily on Bitget, is an affiliate of the Bitget Builders Program, and a completer of the Blockchain4Youth Learning Hub program.

Crypto exchange Bitget suffered a security breach on September 24, 2026, after an attacker exploited a vulnerability in a third-party security product and gained unauthorized access to critical systems within the exchange’s wallet infrastructure. The incident resulted in approximately $388 million in unauthorized crypto transfers across multiple blockchains.

According to the exchange, the attacker obtained high-level internal credentials and used them to issue fraudulent withdrawal commands that bypassed existing risk controls. The affected infrastructure involved portions of the exchange’s hot and warm wallets, while private keys and cold wallets were not compromised.

The exchange temporarily suspended withdrawals, engaged Mandiant and SlowMist for independent forensic investigations, and activated its User Protection Fund to cover the financial impact. Both security firms subsequently released findings that broadly aligned with the attack path Bitget had previously disclosed.

As of October 1, Bitget has resumed BTC, ETH and USDT withdrawals under its phased restoration plan, published an updated Proof of Reserves showing a 131% overall reserve ratio, and replenished its Protection Fund to more than $300 million.

The remaining withdrawal phase, covering other supported tokens, fiat and peer-to-peer (P2P) services, is scheduled for October 2 at 08:00 UTC.

This report consolidates the incident timeline, confirmed attack method, affected assets, independent investigation findings, user protection measures, withdrawal updates, fund recovery efforts and outstanding questions.

Bitget Hack: Key Facts at a Glance

Incident DetailConfirmed or Reported Information
Incident dateSeptember 24, 2026
First unauthorized transfers18:31 UTC
Initial loss estimate$351.6 million
Revised financial impactApproximately $387.5 million to $388 million
Root causeVulnerability in third-party security infrastructure
Attack methodCompromised credentials and forged wallet withdrawal commands
Affected infrastructurePortions of hot and warm wallets
Private keys compromised?No, according to Bitget
Cold wallets affected?No, according to Bitget
Individual user balancesReported unaffected
Independent investigatorsMandiant and SlowMist
Proof of Reserves131% overall, September 29 snapshot
Protection FundReplenished above $300 million on September 30
Withdrawal restorationSeptember 28 to October 2, in phases
Recovery statusAsset tracing, freezing and recovery ongoing

Table 1. Summary of the September 2026 Bitget Security Incident

The financial impact was initially estimated at $351.6 million, then revised to $387.5 million after additional transaction reconciliation. The larger figure includes assets tied to the original breach and does not represent a separate attack after containment.

What Happened in the September 24 Bitget Hack?

The incident began when an attacker exploited a vulnerability in a third-party security product connected to Bitget’s internal infrastructure.

The attacker gained access to privileged internal credentials and subsequently used that access to reach the exchange’s production wallet environment. The attacker then constructed and submitted fraudulent withdrawal commands to the wallet system.

These commands manipulated the normal authorization process, allowing abnormal cryptocurrency transfers to proceed without passing the expected risk-control checks.

Unlike an attack involving stolen private keys, this breach targeted the operational systems that initiate and approve withdrawals.

Bitget said the attack path was subsequently identified, the underlying vulnerability remediated and affected access isolated. The exchange also reported that its cold wallets remained unaffected.

Why Did the Attacker Start With Small Transfers?

The first two unauthorized transactions involved:

  • 0.84 ETH from an Ethereum hot wallet.
  • 93 TRX from a TRON hot wallet.

Both transactions were below the platform’s configured risk-control threshold and did not trigger an immediate system alert.

The attacker subsequently initiated substantially larger transfers across multiple blockchain networks.

The incident exposed a weakness in how abnormal withdrawal commands could be executed after the attacker obtained privileged backend access, rather than a direct compromise of users’ login credentials.

Complete Bitget Hack Timeline: September 24 to October 2

The sequence below combines Bitget’s supplied incident chronology with its publicly announced recovery milestones. The September 24 technical timestamps are presented as approximate.

Date and Time (UTC)Event
September 24, 18:31First unauthorized withdrawals: 0.84 ETH and 93 TRX.
18:58-20:09Attacker initiates 17 large transfers valued at approximately $360 million.
19:05Reconciliation system detects a significant discrepancy; risk controls automatically block withdrawal requests.
19:14Bitget activates its highest-level P0 emergency response.
19:40Technical containment measures begin.
20:40Wallet team begins transferring funds to cold storage while investigating possible private key exposure.
20:54Withdrawals are disabled platform-wide.
20:55-21:23Seven additional transfers, valued at approximately $28 million, are initiated.
21:44Wallet withdrawal and signing services are shut down, and related access is isolated.
September 25, 08:43Security team identifies the incident’s root cause.
September 25, 13:42Legal team reports the incident to law enforcement in the relevant jurisdiction.
September 26, 04:00Withdrawal restoration schedule is confirmed following remediation and security checks.
September 28, 08:00BTC withdrawals begin resuming.
September 29, 08:00ETH withdrawals begin resuming across designated networks.
September 29, 09:00Updated Proof of Reserves snapshot records a 131% overall reserve ratio.
September 30, 08:00USDT withdrawals begin resuming across designated networks.
September 30Bitget publishes an update on the independent Mandiant and SlowMist findings.
September 30Protection Fund is replenished to more than $300 million.
October 2, 08:00Scheduled restoration of remaining tokens, fiat and P2P services.

Table 2. Detailed Timeline of the Bitget Hack and Recovery Process

When Were the Unauthorized Transfers Fully Contained?

Bitget shut down its wallet withdrawal services, including signing services, at approximately 21:44 UTC on September 24.

This was a more comprehensive containment step than simply disabling customer withdrawals through the platform interface.

According to Bitget, no additional unauthorized transfers associated with the incident have been identified following containment.

However, stopping the active attack did not automatically mean that the withdrawal infrastructure was ready to reopen. The exchange still needed to complete remediation and security validation before restoring customer access.

How Much Was Stolen From Bitget?

The estimated financial impact of the hack was revised from approximately $351.6 million to $387.5 million, commonly rounded to $388 million.

The initial disclosure reflected information available during the early response. The revised amount incorporated additional reconciliation and classification of affected transactions, including assets on Zcash and TRON.

The updated figure refers to the same September 24 incident, not another $36 million theft that happened after the breach was contained.

Which Blockchains and Assets Were Affected?

The incident details identify 11 affected blockchain networks and 12 crypto assets.

Affected BlockchainsAffected Assets
EthereumXRP
XRP LedgerETH
ZcashUSDT
TRONZEC
ArbitrumUSDC
OptimismUSDT0
BaseXAUt
BNB Smart Chain (BSC)BNB
AvalancheAVAX
AlgorandTRX
CelestiaALGO, TIA

Table 3. Blockchain Networks and Cryptocurrency Assets Involved in the Bitget Incident

The network list and asset list are separate inventories; each row does not indicate that the asset in the right column was stolen from the blockchain directly opposite it.

The incident affected specific exchange wallet infrastructure rather than the underlying security of every listed blockchain.

What Did the Independent Mandiant and SlowMist Reports Find?

Bitget engaged two external cybersecurity firms to investigate the incident independently:

  • Mandiant, part of Google Cloud.
  • SlowMist, a blockchain security company.

On September 30, Bitget announced that both investigations reached broadly the same conclusion about the attack path.

Their findings identified compromised third-party security infrastructure as the entry point that ultimately enabled unauthorized access to the exchange’s wallet environment. The investigations also provided additional technical details about different stages of the breach.

Mandiant Findings: Privileged Access and Lateral Movement

According to the investigation, Mandiant found that the attacker first gained unauthorized privileged access to security infrastructure.

From there, the attacker moved laterally into Bitget’s production wallet environment and ultimately gained control of the wallet job server.

This explains how an attacker could initiate withdrawal operations without directly stealing crypto private keys.

SlowMist Findings: Zero-Day Vulnerability and Forged Withdrawal Tool

SlowMist identified suspicious activity involving two third-party security products and a wallet application host.

Its investigation found that a service running on one of the security products was affected by a zero-day vulnerability.

SlowMist also recovered a highly customized withdrawal tool designed around Bitget’s wallet-processing logic.

Notably, the tool could forge risk-control parameters, construct withdrawal requests and invoke the wallet withdrawal process.

Taken together, the two investigations indicate that the attacker exploited weaknesses in privileged infrastructure and withdrawal authorization rather than obtaining direct control over cold-wallet private keys.

The full technical reports should be consulted for the forensic evidence and precise scope of each investigator’s conclusions. Bitget links both documents in its September 30 investigation update.

Was North Korea’s Lazarus Group Responsible?

Public reporting has discussed possible links between the incident and North Korean hacking groups. However, the technical findings summarized above establish the identified attack path, not a definitive public attribution to a specific individual or organization.

The identity of those responsible should therefore remain separate from the confirmed explanation of how the exploit occurred.

Were Bitget User Funds, Private Keys or Cold Wallets Compromised?

Bitget maintains that the incident did not affect individual user account balances.

The exchange also stated that private keys were not compromised and that cold wallets across its supported blockchains remained secure.

The breach was concentrated within portions of its hot and warm wallet infrastructure.

Understanding Bitget’s Three-Tier Wallet Architecture

Bitget uses three wallet-storage categories, each with a different operational role.

Wallet TypePrimary FunctionConnection and Access
Hot walletRoutine deposits and withdrawalsOnline infrastructure
Warm walletIntermediate asset storage and operationsAdditional authorization controls
Cold walletLonger-term asset protectionOffline storage with stricter manual and multisignature procedures

Table 4. Bitget’s Three-Tier Wallet Infrastructure

The attacker compromised critical backend infrastructure connected to certain hot and warm wallet operations.

According to the exchange’s investigation, cold storage was not affected.

Was Bitget Wallet Also Hacked?

No, according to Bitget’s incident information.

Bitget Wallet is a separate non-custodial product and does not share the affected exchange wallet infrastructure described in this incident.

Users of the non-custodial wallet retain control over their assets onchain.

Do Users Need to Change Passwords or Reset API Keys?

Bitget has stated that users do not need to change account passwords or reset application programming interface (API) keys because of the September 24 incident.

Nevertheless, users should continue following normal account-security practices, including two-factor authentication (2FA) and checking for suspicious login activity.

What Has Bitget Changed After the Security Breach?

After identifying the attack path, Bitget introduced additional infrastructure and operational safeguards. The completed and ongoing measures include the following:

  • Isolating the affected systems.
  • Revoking and reissuing internal credentials.
  • Restructuring access to highly sensitive infrastructure.
  • Introducing additional approvals for critical operations.
  • Strengthening wallet withdrawal verification.
  • Disabling the affected third-party functionality during remediation.
  • Expanding the assessment of third-party security products.
  • Improving abnormal-activity monitoring and alerting.

Bitget said it identified and remediated the vulnerability responsible for the incident before the phased withdrawal restoration began.

These measures address weaknesses identified during the investigation, but they should not be presented as a guarantee that the exchange cannot experience another security incident.

Bitget Proof of Reserves Reaches 131% After the Hack

One of the main concerns following the breach was whether the exchange still held sufficient assets to back customer balances.

Bitget responded by publishing its 47th Proof of Reserves (PoR) update.

Based on the snapshot taken on September 29, 2026, at 09:00 UTC, Bitget reported an overall reserve ratio of 131% across 19 covered assets.

Each asset maintained a reserve ratio above the 100% benchmark, according to the exchange’s disclosure.

What Does a 131% Reserve Ratio Mean?

A 100% reserve ratio represents one-to-one asset coverage for the customer balances included in the disclosure.

A 131% overall ratio means that, using Bitget’s reported calculation and covered assets, the platform held $131 in reserves for every $100 of corresponding customer liabilities at the snapshot time.

It does not mean that every user receives an additional 31%, nor does it prove that all possible operational or financial risks have been eliminated.

The snapshot represents the reserve position at a specific time and should be evaluated alongside its asset coverage and verification methodology.

Proof of Reserves and the Protection Fund Are Not the Same

Bitget’s Protection Fund and Proof of Reserves serve different purposes:

MeasurePrimary Purpose
Proof of ReservesDemonstrates asset coverage against included customer balances
User Protection FundProvides a separate financial safeguard for exceptional incidents

Table 5. Bitget Proof of Reserves Versus User Protection Fund

The Protection Fund should not be confused with the underlying reserves backing customers’ exchange balances.

Bitget Protection Fund Replenished Above $300 Million

Before the September 24 attack, Bitget’s Protection Fund held 5,500 BTC, valued at approximately $464 million at the time of the initial incident announcement.

Bitget designated the fund to absorb the approximately $388 million financial impact, allowing the exchange to maintain user account balances despite the unauthorized transfers.

A major financial update followed on September 30.

Bitget announced that it had replenished the Protection Fund to more than $300 million, completing its earlier commitment to restore the fund to at least that level within one week.

The exchange said it would use its own capital for the replenishment. The fund’s associated wallet addresses remain publicly available for independent onchain monitoring.

Did the $388 Million Loss Leave Only a Small Protection Fund Balance?

The original $464 million valuation and the $388 million incident estimate cannot be used to determine the fund’s current value by simple subtraction.

The fund holds crypto assets whose market value fluctuates, and Bitget later replenished it.

The relevant updated disclosure is that the Protection Fund exceeded $300 million as of September 30.

Readers who want to inspect its latest value should consult the public wallet addresses through Bitget’s official Protection Fund page.

Why Did Bitget Suspend Withdrawals for Several Days?

The suspension was introduced as a security containment and verification measure.

Because the attacker had accessed critical infrastructure used to initiate withdrawals, Bitget needed to isolate that environment, revoke compromised credentials and validate the affected systems before reopening customer transfers.

The exchange said the pause was unrelated to insufficient customer assets.

Deposits and regular trading continued operating during the broader response, although some individual services experienced temporary restrictions.

The phased approach allowed Bitget to restore assets and networks in groups after completing the relevant security checks.

Complete Bitget Withdrawal Resumption Schedule

Date and Time (UTC)Asset or ServiceSupported Networks
September 28, 08:00BTCBitcoin
September 29, 08:00ETHEthereum, BSC, Arbitrum, Base, Optimism
September 30, 08:00USDTEthereum, BSC, Solana, TRON
October 2, 08:00Other assets, fiat and P2P–

Table 6. Official Bitget Withdrawal Recovery Schedule

Bitget also addressed BTC withdrawals on BNB Smart Chain through a subsequent network-specific restoration announcement.

The October 2 phase remains scheduled as of this article’s October 1 update.

Did VIPs or Institutions Receive Priority Withdrawals?

Bitget said the same restoration schedule applies to all affected users.

The exchange did not establish separate priority withdrawal access for institutions, VIP users, key opinion leaders or its own employees.

What About Bitget Card, Bank Transfers and P2P Trading?

Bitget Card, fiat and P2P services are scheduled to resume alongside the remaining restoration phase on October 2 at 08:00 UTC.

Availability for individual card and bank-transfer methods may vary. Users should rely on the options displayed in their accounts once the relevant services reopen.

How Much of the Stolen Bitget Funds Has Been Frozen or Recovered?

Asset recovery remains a separate process from restoring customer withdrawals.

Bitget has been working with law enforcement, cybersecurity firms, exchanges, blockchain projects and other industry participants to trace assets associated with the attack.

Industry partners had frozen $632,700 as of September 30 at 10:40 AM (UTC+8).

It is also important to distinguish three different categories:

  • Attacker holdings: Assets identified as remaining in attacker-controlled addresses.
  • Frozen funds: Assets whose movement has been restricted through intervention.
  • Recovered funds: Assets successfully returned or otherwise placed back under authorized control.

A reduction in tracked attacker holdings does not automatically mean Bitget has recovered the same amount.

Readers can follow the changing figures through the public fund-tracing dashboard, which Bitget has referenced in its recovery communications.

Bitget Launches a Recovery Bounty Program

Bitget announced a recovery incentive program to encourage individuals, exchanges and other organizations to help identify, freeze or recover stolen assets.

The program provides two distinct bounty categories:

Eligible ContributionPotential Bounty
Successfully freezing affected assets5% of the qualifying frozen amount
Successfully recovering affected assets5% of the qualifying recovered amount

Table 7. Bitget Asset Recovery Bounty Structure

The program covers eligible voluntary contributions, including certain actions that had already resulted in assets being frozen.

However, actions performed pursuant to court orders, law-enforcement requests or other mandatory legal processes are excluded.

Bitget retains final authority over eligibility, the calculation method and the amount payable. Participation also does not guarantee a reward.

The company has also identified Bybit’s LazarusBounty initiative as a channel supporting broader asset-tracing and recovery efforts.

For details, readers should consult Bitget’s fund tracing and Recovery Bounty Program announcement.

Will Bitget Compensate Users After the Hack?

Bitget says customer account balances were unaffected and that its Protection Fund is covering the direct financial impact of the breach.

However, compensation for indirect losses is a separate issue.

The supplied incident information does not establish a blanket compensation policy for users who experienced missed trading opportunities, liquidations or other consequences of temporarily restricted services.

Affected users should follow individual support procedures and official announcements rather than assume those losses are automatically covered.

What Is the Bitget Alliance Program?

image 13

Separately, Bitget launched its Alliance Program following the security incident.

The four-week initiative runs from September 28 to October 26, 2026, and establishes a user reward pool equal to 30% of eligible net platform transaction fee revenue.

The pool is divided between qualifying trading activity and asset holdings, with rewards distributed in USDT according to the published campaign rules.

It is a user reward initiative, not a direct reimbursement mechanism for stolen assets or trading losses.

Eligibility restrictions apply, including exclusions for certain institutional and professional account categories.

Other Questions Raised by the Bitget Incident

This section addresses additional concerns raised by users following the incident, including law enforcement involvement, personal data security, asset delistings and how the breach compares with other major exchange incidents. 

Did Bitget Report the Hack to Law Enforcement?

Yes. Bitget’s legal team reported the matter to law enforcement on September 25 at approximately 13:42 UTC.

The exchange also stated that it was cooperating with relevant authorities, financial intelligence units and industry participants across multiple jurisdictions.

Was Personal User Data Exposed?

The supplied incident information does not establish a confirmed compromise of individual customer data.

Bitget stated that it would comply with applicable legal and regulatory notification obligations if an investigation confirmed that personal information had been affected.

Did the Incident Cause DOG and SAGA Delistings?

According to Bitget’s supplied explanation, neither delisting decision was initiated as a direct response to the hack.

The SAGA delisting was announced on September 18, while DOG’s project team received notice of its upcoming delisting on September 23.

The security incident nevertheless affected users who needed to withdraw certain assets around those scheduled changes. Bitget said it contacted the affected users.

How Was the Bitget Hack Different From FTX?

The two events involved different reported causes.

Bitget’s September 2026 incident was an external security breach involving compromised infrastructure and unauthorized cryptocurrency transfers.

FTX’s 2022 collapse involved the misuse of customer assets and a broader financial shortfall.

Bitget maintains that customer balances remained unaffected by its incident and subsequently published a 131% overall reserve ratio for its 19 covered assets.

Why Didn’t Bitget Reopen Withdrawals as Quickly as Bybit?

The incidents involved different compromised systems and required different technical recovery procedures.

In Bitget’s case, the attacker accessed infrastructure used to initiate and authorize withdrawals, requiring the exchange to isolate services and validate multiple networks before reopening them.

A direct comparison based only on the number of days withdrawals were unavailable would overlook differences in attack paths and containment requirements.

How to Avoid Bitget Withdrawal Phishing Scams

Major exchange incidents often create opportunities for impersonation and phishing attempts, especially while users wait for services to resume.

Bitget users should be cautious of accounts, emails or direct messages claiming they must complete a separate process to reactivate withdrawals.

A legitimate restoration announcement should not require users to share private keys, recovery phrases or passwords.

Users should do the following:

  • Check the official Bitget Announcement Center.
  • Confirm withdrawal availability directly within their accounts.
  • Use Bitget’s Official Verification tool to check unfamiliar accounts or contacts.
  • Avoid third-party links claiming to provide priority withdrawals.
  • Never transfer funds to an outside address to unlock an existing balance.

No separate migration or wallet activation procedure is required under the published phased withdrawal plan.

What Comes Next After the Bitget Hack?

Bitget’s next milestone is the scheduled restoration of remaining withdrawals, fiat and P2P services on October 2 at 08:00 UTC.

Beyond that, attention will shift toward recovering stolen assets, implementing further security improvements and providing updates on outstanding investigation findings.

While the immediate breach has been contained, continued transparency on fund recovery and security measures will remain important as Bitget works to rebuild user trust.

What this means for you: If you have funds on Bitget and prefer to move them elsewhere after the incident, that’s perfectly understandable, and Bitget has acknowledged that decision. If you choose to stay, the exchange has also introduced the Bitget Alliance Program to reward eligible users who continue holding assets or trading on the platform. It’s separate from the security recovery process, but it shows a tangible effort to recognize users who chose to stay.

Frequently Asked Questions

Need a refresher? Here are the main questions users are asking about the September 2026 Bitget hack, its financial impact and the recovery process.

Was Bitget Hacked on September 24, 2026?

Yes. Bitget experienced unauthorized transfers from portions of its hot and warm wallet infrastructure beginning at approximately 18:31 UTC on September 24 (September 25 in Asia time).

How Much Money Did Bitget Lose?

The revised financial impact was approximately $387.5 million, commonly rounded to $388 million. The initial estimate was $351.6 million.

What Caused the Bitget Hack?

According to Bitget and the subsequent investigation updates, the attacker exploited compromised third-party security infrastructure to obtain privileged access and issue fraudulent wallet withdrawal commands.

Were Bitget Private Keys or Cold Wallets Compromised?

Bitget says private keys were not compromised and its cold wallets remained unaffected.

Did the Hack Affect Customer Account Balances?

Bitget maintains that user account balances were unaffected and that its Protection Fund is covering the breach’s financial impact.

What Did Mandiant and SlowMist Find?

Both investigations broadly aligned with Bitget’s previously disclosed attack path. Mandiant examined the privileged access and movement into production infrastructure, while SlowMist identified additional technical evidence involving third-party security products and a customized withdrawal tool.

What Is Bitget’s Proof of Reserves After the Hack?

The September 29, 2026 snapshot reported an overall reserve ratio of 131% across 19 covered assets, with each maintaining a ratio above 100%.

How Much Is Left in the Bitget Protection Fund?

Bitget announced on September 30 that it had replenished the Protection Fund to more than $300 million. You can check its current market value through the fund’s published onchain addresses.

When Will All Bitget Withdrawals Resume?

The final scheduled restoration phase is October 2, 2026, at 08:00 UTC, covering remaining assets, fiat and P2P services. Verify actual availability on the platform.

Why Did Bitget Suspend Withdrawals?

The exchange said the suspension was necessary to isolate affected wallet infrastructure, revoke compromised credentials and validate withdrawal systems before reopening them.

Does Bitget Offer Compensation for Missed Trades or Liquidations?

The Protection Fund is covering the direct financial impact of the security incident. A general compensation policy for indirect trading losses was not established in the supplied incident information.

How Much of the Stolen Crypto Has Been Recovered?

Recovery efforts are ongoing. The supplied September 30 snapshot recorded approximately $632,700 frozen by industry partners. Frozen assets and successfully recovered assets should not be treated as interchangeable figures.

Is Bitget Wallet Affected by the Exchange Hack?

According to Bitget, its separate non-custodial Bitget Wallet product was not affected by the exchange infrastructure breach.

Is Bitget Safe to Use After the Hack?

Bitget says the identified vulnerability has been remediated, compromised internal credentials have been replaced and additional withdrawal controls have been introduced. Mandiant and SlowMist have also investigated the incident. Users can review those findings, updated reserve disclosures and the status of services when making their own assessment of the platform’s remaining risks.

Where Can I Find Official Bitget Hack Updates?

Bitget maintains an official incident information page, alongside dated security announcements and its public fund-tracing dashboard. Its Announcement Center should be used to verify subsequent changes to withdrawal availability, recovery figures and security disclosures.

Join our growing community

Rickie Sanchez

Author

Rickie Sebastian Sanchez is a content writer and researcher with four years of experience covering the crypto markets. His work has appeared in outlets including Blockzeit, CryptoFlash.Report, Cryptomaten, and CoinAlarm.ai, where he has built a reputation for clear, research-driven reporting on fast-moving market developments. At UseTheBitcoin, Rickie focuses on crypto and TradFi news, airdrop guides, and newsletter management. He holds multiple certifications from Binance Academy and is also a completer of Bitget’s Blockchain4Youth Learning Hub Program. Rickie holds BTC.