Bitget says $351.6 million hack used spoofed transfers, not stolen private keys
Bitget says forged transfer requests drained $351.6 million
Crypto exchange Bitget says it lost $351.6 million in an overnight hack. An exchange is a platform where people trade and hold crypto. The company says the attackers did not steal private keys, the secret codes that prove ownership of crypto and approve spending.
Bitget CEO Gracy Chen described the attack as forged withdrawal slips being pushed through the exchange's own approval process. In her comparison, the vault keys never left the building. Someone got into the office that prepares the paperwork, made it look official, and sent it through the normal approval window.
The main points
- Bitget puts the loss at $351.6 million, while the article's headline rounds it to $352 million.
- Attackers got into a backend part of the exchange's wallet system, faked transaction data and triggered the approval process that moves funds, according to Chen.
- Bitget says private keys were not compromised.
- Some hot wallets and the warm-wallet layer were affected; offline cold wallets stayed secure.
- The exchange says further unauthorized transfers have been stopped, deposits and trading remain open, and withdrawals are paused during a security review.
What Gracy Chen said on X
Chen posted about the breach on X. She said: "The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out." She added that private key compromise had been ruled out.
She also said: "Loss containment is confirmed. No further unauthorized transfers are possible. The specific method of system intrusion remains under active investigation. A full technical report will follow once confirmed."
How the breach was noticed
Bitget's systems flagged unauthorized transfers from some exchange hot wallets at 18:31 UTC on Sept. 24. A hot wallet stays connected to the internet so funds can move quickly. For an exchange, it works like an online cash drawer that handles instant trades, deposits and withdrawals.
Chen said the attack also reached the warm-wallet layer, which is only partly connected to the internet.
What the exchange says is confirmed
- Private keys were not taken, according to Bitget.
- Offline cold wallets, which are kept disconnected from the internet, stayed secure.
- No further unauthorized transfers are possible, the exchange says.
- The exchange's User Protection Fund, which it says holds more than $464 million, will cover the loss.
- Deposits and trading are still open. Withdrawals are suspended pending a security review.
What is still unclear
Bitget has not explained how the attackers got into the wallet backend. Chen said the specific method of intrusion is still under investigation and that a full technical report will follow once it is confirmed.
Why the type of attack matters
Chen's statement that private keys were not involved points to a less alarming kind of attack than a key theft. A private key is like a password and a vault combination in one. If one is copied, an attacker can keep signing new transfers and draining funds.
A separate CoinDesk report linked in the article said private keys, not smart contracts, accounted for about 40% of the roughly $16 billion lost in crypto hacks.
What happens next
Withdrawals will stay paused until Bitget completes its security review. The exchange says a full technical report will be published once the method of intrusion is confirmed.
Background on Bitget
Bitget is officially registered and headquartered in the Seychelles and is one of the top 10 crypto exchanges in the world by trading volume, according to the article. It said the exchange had roughly 1,900 employees as of 2025, and that its separate self-custodial Bitget Wallet, where users control their own keys, has passed 100 million users.