Bitget revealed that a $351.6 million breach was not a private-key theft. According to CEO Gracy Chen, attackers broke into a critical wallet backend, fed forged transfer data into the exchange’s own approval process, and walked funds out of hot and warm wallets as if the payouts were routine.
Cold storage, she said, was untouched.
The incident was first flagged at 18:31 UTC on September 24, 2026.
Withdrawals remain paused while deposits and trading continue, and Chen said a user protection fund of more than $464 million is large enough to absorb the loss.
That distinction actually matters.
A stolen private key is the crypto equivalent of a copied vault combination: the thief can keep signing new transfers until every exposed address is emptied and rebuilt.
Chen has ruled that scenario out. What failed instead was the machinery that tells a signer what to approve.
Once a backend system can invent a transfer that looks internally valid, the keys never have to leave the building.
Media outlets in general compared the method to sliding forged withdrawal slips through a bank’s own teller window.
[SECURITY NOTICE] Bitget Hot Wallet Incident — September 24, 2026
At 18:31 UTC on September 24, 2026, Bitget's security systems detected unauthorized transfers from some of our hot wallets. Our security team activated emergency response protocols immediately.
What we have…
— Gracy Chen @Bitget (@GracyBitget) September 24, 2026
To the approval layer, the paperwork looked official. The funds still left.
Spoofed transactions in crypto are not one trick.
They sit in a family of attacks that target the path between “someone wants to move money” and “a valid signature appears on-chain.”
In one version, malware or a compromised interface shows operators a harmless payout while the payload they actually sign is something else.
In another, as Bitget now describes, an internal wallet service is hijacked so that fabricated destinations, amounts, and metadata travel through the same authorization pipeline used for everyday withdrawals.
On-chain, the result can look unnervingly normal: sequential nonces, familiar gas settings, and transfers that sit inside an exchange’s live operational pattern rather than arriving from an outside key.
That is why a “no keys stolen” headline is not the same as “the system worked.” The chain accepted valid signatures.
The control plane that decided what those signatures should mean did not.
The closest recent parallel is Bybit’s February 2025 disaster, still the industry’s largest exchange theft at about $1.5 billion.
That attack did not require cracking Bybit’s hardware wallets in the classic sense either.
Investigators later described a poisoned Safe{Wallet} interface: signers believed they were approving a routine cold-to-hot movement; the transaction they signed handed attackers control of the wallet logic.
Both cases share a grim lesson.
Multisig, hardware devices, and offline vaults can all be bypassed if the human or machine doing the approving is shown a lie.
The differences are also instructive. Bybit’s loss came from a third-party signing front end during a cold-wallet rotation.
Bitget’s drain, on current evidence, ran through the exchange’s own wallet backend and hit internet-connected hot and semi-connected warm wallets across several networks, with XRP making up the largest slice.
Early on-chain tallies undercounted the damage because they missed non-EVM legs.
Industry reaction has been blunt. On-chain researcher Specter tied some of the stolen XRP flow to an earlier cluster associated with the July AFX theft, which had already been linked to a North Korea-aligned unit.
Chen separately said investigators saw IP and VPN patterns matching a Democratic People’s Republic of Korea group and called that attribution “very likely,” while stressing it is not yet confirmed.
Bybit CEO Ben Zhou offered operational help, a reminder that the two platforms now share a grim club: large, highly active venues that had to prove solvency in public after a state-scale raid.
Aneirin Flynn, chief executive of cybersecurity firm FailSafe, argued that a theft of this size punctures the story that major exchanges have solved hot-wallet risk, and that even a fully funded backstop still bruises institutional trust.
Retail voices on X returned to the older slogan — keep only what you must on an exchange — because a protection fund is a promise after the fact, not a lock that held.
Bitget is not a fringe venue.
It is one of the more active centralized exchanges in the market, with multi-billion-dollar daily turnover, a large derivatives book, and a prominent copy-trading franchise.
Platforms of that size sit at the junction of retail savings, market-maker inventory, and cross-chain operational wallets.
When their authorization layer can be fooled, the blast radius is not a single user error.
It is a live payment system that other traders treat as infrastructure.
That is why this class of incident should no longer be treated as an occupational hazard the industry shrugs off every few quarters.
After Bybit, every serious operator had a case study in interface and supply-chain spoofing.
After Bitget, they have a case study in backend transfer forgery.
The two attacks are not identical, but they rhyme: the keys can remain “safe” while hundreds of millions still leave.
Containment, Chen said, is complete, and a fuller technical report is promised. Recovery of some funds has been claimed without a published total.
Those are necessary next steps. They are not sufficient ones.
An industry that wants to be treated as financial plumbing cannot keep discovering that the office that prepares the slips was open.
High-volume exchanges need independent verification of what a signer is asked to approve, strict separation between request generation and authorization, anomaly stops that halt coordinated multi-chain waves in minutes rather than hours, and a posture that treats a $350 million “process success” as a failure of design.
Customer coverage funds are a floor, not a strategy. The acceptable standard is simpler: forged transfers should not clear.