Home/News/Bitget's $352 million hack happened via spoofed transfers, not private keys, CEO Gray Chen says

Bitget's $352 million hack happened via spoofed transfers, not private keys, CEO Gray Chen says

CoinDeskPublished on 4 hours ago

Bitget lost $351.6 million after attackers compromised a wallet backend, spoofed transaction data, Chen said on X.

Bitget's $352 million hack happened via spoofed transfers, not private keys, CEO Gray Chen says

Bitget lost $351.6 million after attackers compromised a wallet backend, spoofed transaction data, Chen said on X.

Bitget lost $351.6 million after attackers compromised a wallet backend, spoofed transaction data and triggered the exchange’s authorization process, though the company said its private keys were not compromised. The breach affected hot and warm wallets, but Bitget said its offline cold wallets remained secure and that it had stopped further unauthorized transfers. Bitget said its $464 million-plus User Protection Fund would cover the loss, while deposits and trading remain open and withdrawals are suspended pending a security review.

Crypto exchange Bitget lost $351.6 million in an overnight hack. CEO Gracy Chen said attackers faked transfer requests to drain funds but did not steal “private keys.”

“The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out,” Chen wrote on X. “Private key compromise has been ruled out.”

That distinction matters and points to a less alarming attack vector. Private key hacks have driven some of the industry's biggest losses.

Every crypto wallet has two keys. The public key is like a bank account number and can be shared so someone can send funds in. The private key is the secret string that proves ownership and authorizes spending, closer to a password and a vault combination in one. If those private keys are copied, an attacker can keep signing new transfers and draining funds.

Chen said that is not what happened here.

She described the breach as the digital version of slipping forged withdrawal slips through a bank’s own teller window. The vault keys never left the building. Someone got into the office that prepares the slips, created paperwork that looked official, and sent it through the same approval window the bank uses every day. To the system doing the approving, it looked like a normal payout.

The outflow, however, has been stopped, Chen confirmed.

“Loss containment is confirmed. No further unauthorized transfers are possible. The specific method of system intrusion remains under active investigation. A full technical report will follow once confirmed,” she said.

The breach

The breach surfaced when Bitget’s systems flagged unauthorized transfers from some exchange hot wallets at 18:31 UTC on Sept. 24. A hot wallet stays connected to the internet so funds can move quickly. For an exchange, it is a temporary liquidity hub, analogous to an online cash drawer that handles instant trades, deposits, and withdrawals.

Chen said the hack also reached the warm-wallet layer. That is a semi-connected buffer between the automated hot wallets and fully offline cold storage. It tops up the hot wallet when balances run low and pulls excess deposits off the internet so too much capital is not left exposed.

Newsletters

The cold wallets, Bitget’s offline vault, “remain fully secure.”

She added that Bitget’s User Protection Fund holds more than $464 million and covers the full loss. “User funds are safe,” she wrote. “Your account balances are accurate and your assets are protected.”

Deposits and trading are still open. Withdrawals are not. Bitget froze them “as a precautionary measure, pending security review.”

She did not put a clock on when withdrawals will resume.

“Multiple technical teams are working in parallel on system remediation and security hardening,” she wrote. “We will announce a timeline as soon as one is confirmed — we will not commit to a window we cannot guarantee.”

1New York sues Polymarket, alleging it is running an illegal gambling operation6 hours ago 2U.S. Federal Reserve moves on proposals to implement GENIUS Act for stablecoins7 hours ago 3Crypto exchange Bitget says $352 million affected in a hack, claims user funds are 'safe'7 hours ago 4Someone was trying to sell Ondo Finance after founder Nathan Allman's death9 hours ago 5Bullish, Alpaca and Apex Fintech form coalition to push issuer-backed tokenized stocks9 hours ago 6U.S. commodities firms can invest in tokenized assets, use blockchain records: CFTC9 hours ago 7The stock token debate, and the gap nobody can close alone9 hours ago 8Bitcoin just topped a key long-term moving average. Here's what it might mean10 hours ago 9Crypto casino Duelbits goes offline after $7 million hot wallet hack13 hours ago 10Bitcoin’s bear markets are getting milder. Bull markets may be next14 hours ago

The Definitive Stablecoin Landscape Series: Asia Pacific

The Definitive Stablecoin Landscape Series: Asia Pacific

As stablecoins move into regulated finance, APAC is becoming a key proving ground. This report maps the region’s rules, use cases, and RLUSD’s role.

As stablecoins move into regulated finance, APAC is becoming a key proving ground. This report maps the region’s rules, use cases, and RLUSD’s role.

Why it matters:

As stablecoins move into regulated finance, APAC is becoming a key proving ground. This report maps the region’s rules, use cases, and RLUSD’s role.

Crypto exchange Bitget says $352 million affected in a hack, claims user funds are 'safe'

Bitcoin just topped a key long-term moving average. Here's what it might mean

Bitcoin’s bear markets are getting milder. Bull markets may be next