Midterms 2026See who we think should earn your vote, based on our standardsThe guide →
WRITTEN IN PLAIN AMERICAN ENGLISH.
CLAY TRIBUNE.
Advertisement

Bitget’s $352 Million Hack Happened Via Spoofed Transfers, Not Stolen Private Keys

Bitget's $352 million hack came via forged transactions, not stolen private keys, per CEO Gracy Chen. Here's how the breach worked.

By mitch·4 min read
A cracked digital vault screen with cryptocurrency symbols glows red as a shadowy figure manipulates code on a monitor.

Bitget lost $351.6 million to hackers who faked transaction data rather than stealing the exchange’s private keys, according to CEO Gracy Chen. The breach hit hot and warm wallets, but cold storage remained untouched.

Chen detailed the attack on X. She said the hacker broke into a critical backend system within Bitget’s wallet infrastructure, used it to forge transaction data, and triggered the exchange’s own authorization process to move funds out. The private keys themselves were never taken, she said.

“The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out,” Chen wrote. “Private key compromise has been ruled out.”

Advertisement

How the Hack Worked

Each crypto wallet holds two keys. A public key functions as a bank account number, something anyone can hand over to accept money. The private key serves as the proof of possession, combining the role of both a password and a vault combination, giving the holder authority to spend. Should an outsider get hold of those private keys, they could sign off on new transactions and run down the balance without permission.

Chen said that is not what happened here.

The intrusion was compared to a digital imitation of placing counterfeit withdrawal forms through a bank’s own teller station. The vault keys were never taken from the premises. A person gained access to the room where the forms are prepared, produced documents that appeared genuine, and passed them through the same approval opening the bank uses daily. For the system checking the documents, they seemed like a standard payment.

The outflow has been stopped, she confirmed.

She said “Loss containment is confirmed. No further unauthorized transfers are possible. The specific method of system intrusion remains under active investigation. A full technical report will follow once confirmed,”.

The Breach Surface

Bitget’s systems detected unauthorized transfers from some exchange hot wallets at 18:31 UTC on Sept. 24, which is when the breach was discovered. Because hot wallets remain connected to the internet, funds can move quickly. They function as a temporary liquidity hub for exchanges, much like an online cash drawer that handles instant trades, deposits, and withdrawals.

The hack also affected the warm-wallet layer, Chen said. That is a semi-connected buffer that sits between the automated hot wallets and fully offline cold storage. Its job is to top up the hot wallet when balances run low and pull excess deposits off the internet so too much capital is not left exposed.

The cold wallets, Bitget’s offline vault, “remain fully secure.”

What Bitget Is Covering

Bitget’s User Protection Fund holds more than $464 million and covers the full loss, Chen said. “User funds are safe,” she wrote. “Your account balances are accurate and your assets are protected.”

Trading and deposits remain available, but withdrawals have been frozen. Bitget put a hold on them “as a precautionary measure, pending security review.”.

She did not put a clock on when withdrawals will resume.

“Multiple technical teams are working in parallel on system remediation and security hardening,” she wrote. “We will announce a timeline as soon as one is confirmed — we will not commit to a window we cannot guarantee.”

The Key Numbers

  • Loss: $351.6 million
  • Fund covering the loss: $464 million-plus
  • Breach flagged: 18:31 UTC on Sept. 24
  • Wallet layers affected: hot and warm wallets
  • Cold wallets: remain fully secure
  • Withdrawals: suspended, pending security review

Why This Matters

The difference between a spoofed transaction attack and a private key compromise matters greatly. Losses tied to private key hacks have reached some of the industry’s largest sums. Once an attacker holds the private key, they can go on signing fresh transfers and drawing down funds without end.

The attacker did not manage to obtain any private keys in this instance. Instead, they managed to deceive Bitget’s own systems into authorizing the transfers themselves. This points toward a vulnerability rooted in how the systems were built rather than a matter of keys being taken, and it suggests the breach was more about engineering than theft.

Trading is still going on, and the exchange says its cold storage is secure. It has stopped further unauthorized transfers, limited the loss, and confirmed the funds are covered by the protection fund.

Users face a split situation: they can keep adding money to their accounts, but they cannot take any out until the review process concludes. Bitget has not given a timeline for when that will occur.

Even exchanges with significant protection funds can be exposed to complex engineering attacks, as this incident demonstrates. The good news is that so long as the private keys remain secure, the harm remains contained.

It’s reassuring to know that the vault keys never got out of the building. Although the system was compromised, the highest-level secrets were kept safe.

Source material: “Bitget's $352 million hack happened via spoofed transfers, not private keys, CEO Gray Chen says,” CoinDesk.

The Notebook

Get the Notebook.

The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

We send one note to confirm. Every issue has a one-click way out.

Advertisement

Leave a Reply

Your email address will not be published. Required fields are marked *

As an Amazon Associate, Clay Tribune earns from qualifying purchases.