Crypto exchange Bitget lost $351.6 million in an overnight hack, detected at 6:31 p.m. UTC on Sept. 24. CEO Gracy Chen said attackers spoofed transfer requests to drain funds.
Chen said private keys were not stolen. Attackers compromised a backend system within Bitget's wallet infrastructure, using it to spoof transaction data. This triggered the exchange's internal authorization process, letting funds exit.
A private key compromise allows attackers to sign new transfers indefinitely, indicating a deeper system failure. Bitget's breach points to an intrusion in the authorization layer, akin to forged withdrawal slips.
Chen likened the incident to someone creating official-looking paperwork internally and sending it through a bank's regular approval window. The system processed these as legitimate payouts because the vault keys—the private keys—remained secure and were not copied.
Bitget confirmed loss containment, stopping further unauthorized transfers. The specific method of system intrusion remains under investigation, with a full technical report expected once confirmed.
The hack initially surfaced with unauthorized transfers from some of Bitget's hot wallets. Hot wallets are internet-connected liquidity hubs for instant trades and withdrawals.
The breach also reached the warm-wallet layer, a semi-connected buffer designed to top up hot wallets and pull excess deposits offline. However, Bitget's fully offline cold wallets, which serve as the primary vault for user assets, remained secure.
Bitget, headquartered in Seychelles, ranks among the top 10 cryptocurrency exchanges globally by trading volume. The platform serves more than 125 million users worldwide.
As of 2025, Bitget employed approximately 1,900 individuals. Its self-custodial Bitget Wallet has independently surpassed 100 million users.
Chen assured users their funds are safe. Bitget’s User Protection Fund holds more than $464 million, which covers the full $351.6 million loss. Account balances remain accurate, and assets are protected.
