Bitget's $352 million hack happened via spoofed transfers, not private keys, CEO Gray Chen says

Crypto exchange Bitget said attackers stole $351.6 million after compromising a wallet backend and spoofing transaction data to trigger authorized transfers, but the company maintains that private keys were not taken. Bitget reported the breach affected its hot and warm wallets, while offline cold wallets remained secure and further unauthorized transfers have been halted.

By AI Newsroom· Reviewed by Pranav, Founder & Editor-in-ChiefPublished about 1 hour agoUpdated about 1 hour ago0 views
Bitget's $352 million hack happened via spoofed transfers, not private keys, CEO Gray Chen says

Why It Matters

If confirmed, the intrusion demonstrates an attack method that impersonates internal transaction requests rather than seizing private keys, highlighting a different vulnerability in exchange infrastructure that can still produce large losses. The incident also tests exchange protections: Bitget says its User Protection Fund will cover the shortfall and trading remains open while withdrawals are paused for review.

Key Facts

  • Amount lost: $351.6 million
  • Discovery time: 18:31 UTC on Sept. 24
  • Source of breach: Compromised wallet backend that spoofed transaction data
  • Private keys: Bitget says private key compromise ruled out
  • Wallets affected: Hot and warm wallets compromised; cold wallets remain secure (offline)

Bitget disclosed that attackers drained $351.6 million after gaining access to a critical backend system in its wallet infrastructure and using it to fabricate transaction data that passed the exchange’s authorization process. CEO Gracy Chen wrote on X that the operation mimicked legitimate transfer requests rather than obtaining or copying private keys, which the company says were not compromised. According to Bitget, the incident was detected when systems flagged unauthorized transfers from several hot wallets at 18:31 UTC on Sept. 24. The attackers’ activity extended into the warm-wallet layer, a semi-connected buffer used to top up hot wallets and move excess funds off the internet, but did not reach the exchange’s cold wallets, which Bitget says remain fully secure. Chen described the exploit as akin to forging withdrawal paperwork inside a bank and sending it through normal approval channels; from the authorizing systems’ perspective the transfers appeared legitimate. Bitget also reported that the outflow has been stopped and no further unauthorized transfers are possible while the method of intrusion is under active investigation. Bitget said its User Protection Fund, which holds more than $464 million, will cover the loss and that user account balances are accurate. The exchange has kept deposits and trading open but suspended withdrawals as a precaution pending a security review, with multiple technical teams working on remediation and security hardening. A detailed technical report will be published after confirmation of findings.

Keep Reading