Advertisement

Bitget’s $352M Breach Involved Spoofed Transfers, CEO Says

Bitget lost $351.6 million in a security breach after attackers compromised part of its wallet backend and manipulated transaction data, CEO Gracy Chen said.

Chen said the attackers did not gain access to Bitget’s private keys. Instead, they breached a critical backend system, spoofed transaction information and used the exchange’s existing authorization process to move funds.

“The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out,” Chen wrote on X. She added that a private-key compromise had been ruled out.

The distinction is important because stolen private keys have been behind some of the crypto industry’s largest security breaches. A private key is the secret credential required to authorize transactions, while a public key can be shared to receive funds. If an attacker obtains a private key, they can use it to sign transactions and transfer assets.

Chen compared the incident to someone forging legitimate-looking withdrawal instructions inside a bank while leaving the vault keys untouched. In Bitget’s case, the attacker allegedly manipulated transaction information before it reached the normal authorization process.

Bitget said the unauthorized outflows have been contained and that no additional transfers can be made. The exchange is still investigating how the attackers entered its systems and said a full technical report will be released once the findings are confirmed.

The exchange, which is registered and headquartered in Seychelles, ranks among the top 10 crypto exchanges by trading volume. Bitget says it serves more than 125 million users worldwide and offers hundreds of crypto assets along with tokenized stocks, commodities, foreign exchange and precious metals. Its self-custodial Bitget Wallet has more than 100 million users, while the company had around 1,900 employees in 2025.

Bitget detected unauthorized transfers from some hot wallets at 18:31 UTC on Sept. 24. Hot wallets remain connected to online systems and are used to support trading, deposits and withdrawals. The incident also involved the exchange’s warm-wallet layer, which operates as an intermediate buffer between hot wallets and offline cold storage.

Bitget said its cold wallets remain secure. The exchange also pointed to its User Protection Fund, which holds more than $464 million and, according to Chen, is sufficient to cover the reported loss.

Deposits and trading remain available, while withdrawals have been suspended as a security precaution. Bitget has not provided a timeline for restoring withdrawals, saying multiple technical teams are working on remediation and additional security measures.