Cryptocurrency exchange Bitget suffered a $351.6 million loss during an overnight security breach. Chief Executive Officer Gracy Chen explained that perpetrators faked transfer requests to extract assets instead of stealing private keys.
“The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out,” Chen wrote on X. “Private key compromise has been ruled out.”
This distinction is significant and points toward a less catastrophic intrusion method. Private key hacks have accounted for several of the sector’s most devastating financial disasters.
Every digital wallet contains a pair of keys. A public key functions like a bank account number that can be freely shared to receive funds. A private key acts as the secret token confirming ownership and validating expenditures, functioning similarly to a password combined with a safe combination. Should those private keys become duplicated, malicious actors can continually sign new transactions to empty the balances.
Chen emphasized that this scenario did not occur here.
She likened the security incident to passing fraudulent withdrawal slips right through a banking institution’s teller window. The vault credentials never departed the premises. An unauthorized party gained access to the office preparing the paperwork, generated official-looking documents, and routed them through the standard approval channel the company utilizes every day. The validation system perceived the requests as legitimate payouts.
Nevertheless, Chen confirmed that the outflow has been halted.
“Loss containment is confirmed. No further unauthorized transfers are possible. The specific method of system intrusion remains under active investigation. A full technical report will follow once confirmed,” she stated.
The breach
The security event came to light when Bitget systems detected unauthorized withdrawals originating from specific platform hot wallets at 18:31 UTC on September 24. Hot wallets maintain an active internet connection to facilitate rapid asset movement. For trading platforms, these serve as temporary liquidity centers, comparable to online cash registers handling instant trades, deposits, and withdrawals.
Chen noted that the intrusion additionally impacted the warm-wallet architecture. This layer serves as a semi-connected buffer positioned between automated hot wallets and fully offline cold storage systems. It replenishes hot wallets when funds diminish and removes surplus deposits from the internet to prevent excessive capital exposure.
The cold wallets, representing Bitget’s offline storage facility, “remain fully secure.”
She further mentioned that Bitget maintains a User Protection Fund valued at over $464 million, which completely covers the deficit. “User funds are safe,” she noted. “Your account balances are accurate and your assets are protected.”
Trading activities and deposits remain operational. Withdrawals do not. Bitget temporarily halted them “as a precautionary measure, pending security review.”
She refrained from providing an exact timeframe for when withdrawals will be reinstated.
“Multiple technical teams are working in parallel on system remediation and security hardening,” she wrote. “We will announce a timeline as soon as one is confirmed — we will not commit to a window we cannot guarantee.”
Originally published at https://www.coindesk.com/markets/2026/09/25/bitget-s-usd351-million-hack-happened-via-spoofed-transfers-not-private-keys-ceo-gray-chen-says.