Bitget CEO Clarifies $352M Hack Was Not Caused by Private Key Theft

Bitget CEO Gracy Chen said the exchange’s $351.6 million security breach resulted from attackers compromising a wallet backend and spoofing transaction data rather than stealing private keys.

According to Chen, the attackers gained access to a critical backend component of Bitget’s wallet infrastructure. They then manipulated transaction information and used the exchange’s existing authorization process to execute unauthorized transfers.

“The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out,” Chen said on X, adding that investigators had ruled out a private-key compromise.

Private keys are the secret credentials used to authorize crypto transactions. While public keys can be shared, private keys must remain confidential because anyone who obtains one can potentially sign transactions and move the associated assets.

Chen described the incident as similar to an attacker forging legitimate withdrawal paperwork inside a bank while leaving the actual vault keys untouched. In Bitget’s case, the manipulation allegedly occurred within the systems responsible for preparing and processing transaction requests.

The exchange said it has contained the unauthorized transfers and that no additional funds can be moved through the compromised process. Bitget is continuing to investigate the initial intrusion and plans to publish a technical report once the findings have been confirmed.

Bitget is registered and headquartered in Seychelles and ranks among the top 10 crypto exchanges by trading volume. The platform says it serves more than 125 million users and supports hundreds of cryptocurrencies, as well as tokenized stocks, commodities, foreign exchange and precious metals. Its self-custodial Bitget Wallet has more than 100 million users, and the company had roughly 1,900 employees in 2025.

The breach was detected at 18:31 UTC on Sept. 24 after unauthorized transfers were identified from several hot wallets. These wallets remain connected to online systems and provide liquidity for activities such as trading, deposits and withdrawals.

The incident also affected the warm-wallet layer, which serves as an intermediate system between online hot wallets and offline cold storage. Bitget said its cold wallets remain secure.

Chen also highlighted Bitget’s User Protection Fund, which holds more than $464 million. She said the fund is sufficient to cover the reported loss and maintained that user balances and assets remain protected.

Trading and deposits remain available, but withdrawals have been temporarily suspended while security checks continue. Bitget has not given a specific timeline for restoring withdrawals, saying its technical teams are focused on remediation and strengthening the exchange’s security systems.