BNB $775.17 +0.33%
XRP $1.53 +1.72%
ETH $2,680.66 -0.17%
BTC $84,232.93 +0.17%
BNB $775.17 +0.33%
XRP $1.53 +1.72%
ETH $2,680.66 -0.17%
BTC $84,232.93 +0.17%
BREAKING
Digital Wallet

Bitget Hit by $351.6 Million Hack Targeting Warm Wallets, Not Private Keys

Bitget's $351.6 Million Hack Hit Warm Wallets, Not Private Keys
Bitget's $351.6 Million Hack Hit Warm Wallets, Not Private Keys

Community Trust ScoreVerified

94%
Real
Verified18 votes
Updated 2 hours ago

Bitget lost $351.6 million overnight. Attackers spoofed transaction requests inside the exchange’s backend infrastructure, draining funds without ever touching private keys — a detail CEO Gracy Chen was quick to flag publicly.

The unauthorized transfers were first spotted at 18:31 UTC on September 24, coming out of Bitget’s hot wallets. Hot wallets sit online permanently, which makes them fast and useful for daily operations but basically the most exposed part of any exchange’s setup. The breach didn’t stop there. It spread into what’s called the warm-wallet layer — a semi-connected buffer zone that sits between the always-online hot wallets and the fully offline cold storage. That middle tier manages liquidity flows, and it’s normally considered safer than a straight hot wallet. Not this time. Attackers found a way into a critical backend system within Bitget’s wallet infrastructure, used that access to fake transaction data, and pushed through fund transfers that looked legitimate enough to pass. No private keys were copied. No cold wallets were touched. Chen confirmed both points.

How the Spoofing Attack Actually Worked

Think of it like fraudulent withdrawal slips slipping past a bank’s approval desk. The system didn’t get robbed at gunpoint — it got tricked into handing money over voluntarily. Private keys, the cryptographic credentials that actually authorize transfers, stayed safe. What got compromised was the process layer sitting above them: the backend logic that validates and routes transaction requests. Attackers spoofed that layer, fed it fake data, and the system did what it was built to do — it processed the transfers.

Advertisement

The specific method of intrusion is still under investigation. A full technical report is pending, and Bitget hasn’t said exactly which vulnerability opened the door. Unclear whether it was a software flaw, a compromised internal credential, or something else entirely. That part’s murky.

Chen said the outflow has been contained. Once the unauthorized transfers were detected, Bitget moved to halt further drainage. Multiple technical teams are now working on system remediation — patching whatever gaps allowed the spoofing to work and reinforcing the broader security architecture.

User Funds and the $464 Million Protection Buffer

Withdrawals are frozen. Trading and deposits are still running, but Bitget pulled the plug on withdrawals as a precaution while the security review plays out. No timeline has been given for when that changes. The exchange said it’ll announce a restart date once it can confirm the system is locked down — and not before.

The good news for users, at least for now: Bitget’s User Protection Fund sits at over $464 million. That’s more than enough to cover the $351.6 million loss, and the exchange says account balances are accurate and intact. The fund exists precisely for situations like this — a reserve pot that backstops user assets when something goes badly wrong at the infrastructure level. Bitget says no user funds are at risk.

Cold wallets remain secure. Chen was firm on that. The offline storage layer — where the bulk of long-term assets typically sit — wasn’t part of the breach. The attack was contained to the hot and warm tiers, both of which carry more exposure by design because they need internet connectivity to function. That’s probably the most important line for anyone holding funds on the platform: the deeper storage didn’t get hit.

It’s worth noting that hacks of this scale aren’t new to the industry. Exchanges have faced infrastructure-level attacks for years, and the warm-wallet layer has been a target before precisely because it’s the hardest zone to fully isolate — it needs to stay semi-connected to do its job. Bitget’s situation fits a pattern that’s become uncomfortably familiar across centralized platforms.

What Bitget Is Doing Right Now

The investigation is ongoing. Bitget has multiple technical teams running parallel workstreams — some focused on figuring out exactly how the spoofing worked, others on hardening the systems to prevent a repeat. Chen has framed the priority clearly: restore security integrity first, then restore full operations.

The exchange is pushing updates to users as new information comes in. Transparency seems to be the stated approach, though the lack of a concrete withdrawal timeline will frustrate anyone who needs access to their funds. Bitget hasn’t specified when normal operations fully resume — just that it won’t happen until the security review clears.

As of the latest update, the $351.6 million outflow is contained, cold wallets are intact, and the User Protection Fund covers the loss.

Frequently Asked Questions

How did attackers steal $351.6 million from Bitget without taking private keys?

Attackers infiltrated a critical backend system within Bitget’s wallet infrastructure, spoofed transaction data, and initiated unauthorized fund transfers — all without ever copying or stealing private keys.

Are Bitget user funds safe after the hack?

Bitget says yes — the User Protection Fund holds over $464 million, which covers the full $351.6 million loss, and account balances remain accurate and unaffected.

Why It Matters

The breach at Bitget underscores the vulnerabilities inherent in the use of hot wallets for cryptocurrency exchanges, where funds are more susceptible to attacks compared to cold storage solutions. This incident may heighten concerns among investors regarding the security protocols of centralized exchanges, potentially impacting user trust and trading volumes in the broader market. As security breaches continue to challenge the cryptocurrency ecosystem, exchanges may need to reassess their risk management strategies to safeguard assets more effectively.

Community Trust IndexModerate Confidence
94%
Real
Real94%6%Fake
18 community signals

James Thorp

James Thorp is a passionate crypto journalist from South Africa specializing in Litecoin, Dash, and emerging digital assets. With years of experience covering the crypto markets, James delivers in-depth analysis and breaking news on altcoins, blockchain adoption, and decentralized payment networks for The Currency Analytics.

Advertisement

Related Stories