September 25, 2026

Real-Time Crypto Insights, News And Articles

Bitget CEO Says $352M Hack Used Spoofed Transfers, Not Stolen Keys

Bitget suffered a $351.6 million loss after attackers breached a backend component of its wallet infrastructure and manipulated transaction information, CEO Gracy Chen said on X.

Chen said the attackers did not obtain Bitget’s private keys. Instead, they compromised a critical wallet backend, altered transaction data and used the exchange’s existing authorization process to approve unauthorized fund transfers.

“The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out,” Chen wrote. “Private key compromise has been ruled out.”

The distinction is significant because direct private-key theft has been responsible for some of the crypto industry’s largest security losses.

Crypto wallets rely on public and private keys. A public key can be shared to receive assets, while a private key acts as the secret credential required to authorize transactions. If an attacker obtains a private key, they can potentially sign additional transactions and continue moving funds without the owner’s approval.

Chen said Bitget’s private keys were not compromised in this incident.

She compared the attack to forged withdrawal instructions being passed through a bank’s normal approval system. Rather than gaining access to the bank’s vault keys, an attacker would compromise the system responsible for preparing withdrawal documents and make the requests appear legitimate to the process that approves them.

Bitget has since contained the unauthorized outflows, Chen said.

“Loss containment is confirmed. No further unauthorized transfers are possible. The specific method of system intrusion remains under active investigation. A full technical report will follow once confirmed,” she said.

Bitget is officially registered and headquartered in Seychelles and ranks among the world’s 10 largest cryptocurrency exchanges by trading volume.

The exchange serves more than 125 million users globally and offers trading across hundreds of crypto assets, as well as tokenized stocks, commodities, foreign exchange and precious metals including gold. Its self-custodial Bitget Wallet has also surpassed 100 million users.

The company had approximately 1,900 employees as of 2025.

How the breach unfolded

Bitget detected unauthorized transfers from some of its exchange hot wallets at 18:31 UTC on Sept. 24, according to Chen.

Hot wallets remain connected to the internet, allowing exchanges to process deposits, withdrawals and trades quickly. They effectively function as an online liquidity pool for day-to-day transactions.

The attack also affected Bitget’s warm-wallet layer, Chen said. Warm wallets operate between internet-connected hot wallets and offline cold storage, providing a buffer that can replenish hot wallets when needed while moving excess assets away from online systems.

Bitget’s cold wallets, which hold assets in offline storage, “remain fully secure,” Chen said.

The CEO also said Bitget’s User Protection Fund contains more than $464 million, enough to cover the reported loss. She assured customers that account balances remained accurate and user assets were protected.

Deposits and trading remained available following the incident, while withdrawals were suspended as a precaution during the security review.

Chen did not provide a specific timeline for restoring withdrawals. She said several technical teams were working simultaneously on remediation and additional security measures, with Bitget planning to announce a reopening schedule once it could confirm one.

The company said it would not provide a withdrawal timeline until it could guarantee the stated window.

About The Author