LIVEBTC $84,090 ↘ -0.08%ETH $2,676 ↘ -0.47%SOL $116.30 ↗ +1.01%XRP $1.53 ↗ +1.55%BNB $774.22 ↗ +0.16%HYPE $92.01 ↘ -0.89%ZEC $1,544 ↗ +1.35%STRK $0.04 ↘ -0.95%TSLAX $379.96 ↗ +0.58%SPCXB $148.73 ↗ +0.23%BTC $84,090 ↘ -0.08%ETH $2,676 ↘ -0.47%SOL $116.30 ↗ +1.01%XRP $1.53 ↗ +1.55%
Markets2 hours ago

Bitget says $352M theft came through faked transfer requests, not stolen keys

The exchange's CEO ruled out private-key compromise, saying intruders hijacked a backend wallet system and spoofed transaction data to trigger its own approval process.

Illustration · generated, not a photograph

Why it mattersThe breach shows an exchange's internal authorization stack can be weaponized even without private-key theft, though Bitget has not yet explained how the intruders got in.

Bitget lost $351.6 million in an overnight breach, and the exchange says the attackers did it by masquerading as legitimate internal transactions rather than by stealing the cryptographic secrets that control its wallets.

CEO Gracy Chen laid out the mechanism in posts on X. "The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out," she wrote. "Private key compromise has been ruled out."

The distinction is significant for how worried Bitget's users should be. A private key is the secret string that lets whoever holds it sign transfers from a wallet; if an attacker copies one, they can keep pulling funds indefinitely. Bitget's servers, by contrast, were tricked into approving outgoing payments themselves — an intrusion into the machinery that prepares withdrawals, not a theft of the master credentials.

Chen confirmed the bleeding has stopped. "Loss containment is confirmed. No further unauthorized transfers are possible," she wrote, adding that the specific intrusion method is still being investigated and that a full technical report will come once verified.

Per CoinDesk, the trouble first appeared at 18:31 UTC on Sept. 24, when Bitget's monitoring flagged unauthorized outgoing transfers from several of its exchange hot wallets — internet-connected accounts exchanges use as short-term liquidity pools for trading and withdrawals. Chen said the attackers also penetrated the warm-wallet tier, a semi-connected middle layer that refills hot wallets and sweeps surplus deposits toward fully offline storage. Cold wallets, which hold the bulk of user funds offline, "remain fully secure," she said.

The shortfall is covered. Bitget's User Protection Fund holds over $464 million, exceeding the amount taken, and Chen assured customers their displayed balances are correct and their assets protected. "User funds are safe," she wrote.

Not all services are back to normal. Deposits and trading continue, but withdrawals remain frozen "as a precautionary measure, pending security review," with no committed restart date. "We will announce a timeline as soon as one is confirmed — we will not commit to a window we cannot guarantee," Chen said. Multiple technical teams are working simultaneously on remediation and security hardening, she added.

Private-key thefts sit behind some of the largest losses in crypto history, which is why the ruling-out of that vector is likely to reassure both users and counterparties. But the breach demonstrates that even without key compromise, an exchange's internal authorization stack can be weaponized against itself — and Bitget still has not explained how the intruders got in.

What happens nextBitget says a full technical report will be released once verified, and a withdrawal-restart timeline will be announced as soon as one is confirmed.

Source reporting

The outlets whose reporting this account was written from.

Written from the reporting and primary documents credited at the foot of this story. Facts are credited to the outlet or document that established them. How Chainpress works

Emailhttps://www.chainpress.co/article/bitget-says-352m-theft-came-through-faked-transfer-requests-not-cp
Report a correction →
Bitgethacksecurityexchange

Related coverage

View all →