Crypto

Bitget $352M hack: spoofed transfers, keys still intact

· Geeknewz Author

Physical Bitcoin coin resting on a dark surface

Bitget says attackers drained about $351.6 million from exchange wallets overnight without ever stealing private keys. CEO Gracy Chen's explanation, posted after systems flagged unauthorized hot-wallet transfers at 18:31 UTC on September 24, is that someone compromised a wallet backend, spoofed transaction data, and walked forged requests through Bitget's normal authorization path. Cold wallets stayed offline and intact, withdrawals are frozen, and deposits and trading are still open.

That "keys intact" line is meant to calm users, and it should, up to a point. A private-key theft means an attacker can keep signing forever. A spoofed-backend path means the vault combination never left the building, but the paperwork window did. Chen compared it to slipping forged withdrawal slips through a bank's own teller. The loss is still real money. The attack surface is different, and it is one exchanges talk about less than seed phrases.

What Bitget confirmed

The company's security notice and Chen's follow-up to CoinDesk line up on the basics. Hot wallets and the warm-wallet buffer were hit, while cold storage was not. Abnormal destination addresses were flagged and reported. Authorities and on-chain security firms are involved. A full technical report is promised once the intrusion method is confirmed. Chen has not given a date for when withdrawals resume, only that Bitget will not invent a window it cannot keep.

Blockhead and other outlets independently relayed the same $351.6 million figure and the private-key denial. No independent forensic report is public yet, so treat the attack-vector details as Bitget's account until third-party firms publish.

How this sits in the recent hack calendar

Large exchange incidents keep clustering around hot-wallet operational systems rather than cold-storage theater. Bitget's own three-tier description (hot for instant liquidity, warm as a semi-connected buffer, cold offline) is standard industry language. The uncomfortable part of Chen's account is that the warm layer was reached too. That buffer exists specifically so hot wallets are not the only internet-facing cash drawer, which means a backend compromise that can spoof authorizations can skip past the mental model of "only a little hot money was at risk."

Until a third-party firm publishes address trails and timing, treat the $351.6 million figure and the private-key denial as company statements backed by a public notice, not as closed forensics. CoinDesk and Blockhead both reported those claims within hours of each other, which improves confidence that the messaging is consistent, not that every technical detail is verified.

Protection-fund math (inputs shown)

Bitget says its User Protection Fund holds more than $464 million and will cover the loss. Using the company's own floors:

InputFigureSource
Estimated loss$351.6MBitget security notice
User Protection Fund>$464MBitget / Chen
Coverage ratio132%$464 ÷ $351.6 ≈ 1.319
Buffer after full cover~$112.4M$464 − $351.6

If the fund is only barely above $464 million, that buffer shrinks fast once you subtract investigation costs, market moves on remaining assets, and any loss figure that revises upward. The ratio still clears 100% on the published numbers, which is better than many historic exchange failures that offered IOUs. It does not restore withdrawals while the security review runs, and it does not answer how a "critical backend" in the wallet stack got compromised in the first place.

Geeknewz verdict

If you hold funds on Bitget, the company's claim that balances are accurate and cold wallets are safe is the line to watch against on-chain evidence over the next few days. Keep deposits light until withdrawals reopen and a technical report lands. For everyone else, the lesson is not "keys good, everything fine." Hot and warm wallet authorization systems are part of the vault. Spoofed transfer data that looks like a normal payout is enough. Exchanges that advertise insurance funds should publish how those funds are held, who can tap them, and how fast they refill after a hit this size.

Sources: Bitget security notice; CoinDesk; Blockhead.