Bitget lost $351.6 million overnight. The exchange’s CEO said the attackers never got the keys to the vault. They got the paperwork office.
“The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out,” Bitget CEO Gracy Chen said in a post on X. “Private key compromise has been ruled out.”
That one line carries most of the weight in her statement. And if it holds up under the technical report she’s promised, it changes how you should read this breach.
Why the private key detail matters
Private key hacks have driven some of the industry’s biggest losses. So a breach that didn’t touch them points to a less alarming attack vector.
Every crypto wallet has two keys. The public key works like a bank account number: you can share it so people can send you funds. The private key is the secret string that proves ownership and authorizes spending. Think of it as a password and a vault combination rolled into one.
Copy someone’s private keys and you can keep signing new transfers until the wallet is empty. Chen said that isn’t what happened at Bitget.
Forged slips through the teller window
Chen compared the breach to someone sliding forged withdrawal slips through a bank’s own teller window. The vault keys never left the building. The attacker got into the office that prepares the slips, made paperwork that looked official and pushed it through the same approval window the bank uses every day.
To the system doing the approving, it looked like a normal payout. That’s the uncomfortable part. Bitget’s authorization process worked exactly as designed. It just trusted data it shouldn’t have.
How the attacker got into that backend system is still unknown. “Loss containment is confirmed. No further unauthorized transfers are possible. The specific method of system intrusion remains under active investigation. A full technical report will follow once confirmed,” Chen said.
Hot wallets first, then the warm layer
Bitget’s systems flagged unauthorized transfers from some of the exchange’s hot wallets at 18:31 UTC on Sept. 24. A hot wallet stays online so money can move fast. For an exchange, it’s a temporary liquidity hub, something like an online cash drawer that handles instant trades, deposits and withdrawals.
The damage didn’t stop there. Chen said the hack also reached the warm-wallet layer, a semi-connected buffer that sits between the automated hot wallets and fully offline cold storage. It refills the hot wallet when balances run low and pulls excess deposits offline so too much capital isn’t left exposed.
Bitget’s cold wallets, its offline vault, “remain fully secure,” Chen said.
The $464 million backstop
Chen said Bitget’s User Protection Fund holds more than $464 million, enough to cover the full loss. That leaves a cushion of a bit over $112 million after the $351.6 million hit, if the fund is tapped for all of it.
“User funds are safe,” Chen said. “Your account balances are accurate and your assets are protected.”
Reassuring words are cheap after a hack, though. What you can check is what the exchange lets you do right now. Deposits and trading are still open. Withdrawals aren’t.
No date for withdrawals
Bitget froze withdrawals “as a precautionary measure, pending security review.” Chen gave no timeline for when they’ll come back.
“Multiple technical teams are working in parallel on system remediation and security hardening,” Chen said. “We will announce a timeline as soon as one is confirmed,” she said, adding: “we will not commit to a window we cannot guarantee.”
That’s an honest answer, and a frustrating one if your coins are sitting on the platform. You can still deposit and trade, but you can’t take anything out.
If you hold funds on Bitget, don’t treat the open deposit button as a sign things are back to normal. Wait for the technical report Chen promised and a firm withdrawal date before you send in anything new.