Bitget's $352 million hack happened via spoofed transfers, not private keys, CEO Gracy Chen says
Reported by CoinDesk · AI-assisted summary by ChikoCorp AI News Desk

AI-generated summary based on the linked source; not independently verified. This is not investment advice. Verify market-moving details at the original publisher before acting. See our editorial policy, AI content policy, and financial disclaimer.
Summary
Bitget lost $351.6 million after attackers compromised a backend wallet system, spoofed transaction data, and triggered authorized transfers without accessing the exchange's private keys, CEO Gracy Chen confirmed. The breach affected hot and warm wallets, but cold wallets remained secure. Withdrawals have been suspended pending a security review, though deposits and trading continue.
Why it matters
The source highlights that the attack vector did not involve private key theft, a common cause of large crypto losses, suggesting a less alarming method akin to forged withdrawal slips rather than stolen vault keys. Bitget's User Protection Fund of over $464 million will cover the loss, aiming to protect user funds and maintain trust.
Key context
The hack was detected when unauthorized transfers from hot wallets were flagged on September 24. Hot wallets are online and handle immediate liquidity, while warm wallets serve as semi-connected buffers topping up hot wallets, and cold wallets are fully offline storage. The attackers exploited backend wallet infrastructure rather than cryptographic secrets, indicating a system intrusion rather than a cryptographic breach.
Key numbers and entities
Bitget, CEO Gracy Chen, a $351.6 million hack, over $464 million in Bitget’s User Protection Fund. The breach date was September 24, 18:31 UTC.
What remains unclear
The exact method by which the system intrusion occurred is still under active investigation. No timeline has been provided for when withdrawals will resume. A full technical report on the incident has not yet been released.