
Bitget CEO Gracy Chen said the exchange’s $351.6 million security incident was caused by a compromise of its wallet backend, with attackers spoofing transaction data instead of obtaining private keys.
The attackers breached a critical component of Bitget’s wallet infrastructure, manipulated transaction information and then used the platform’s existing authorization process to approve unauthorized transfers, Chen said on X.
“The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out,” Chen wrote. She said investigators had ruled out the possibility that Bitget’s private keys were compromised.
The distinction is important because private keys provide the cryptographic authorization needed to move crypto assets. Public keys can be shared, but private keys must remain secret. An attacker who obtains a private key can generally use it to sign transactions and transfer funds.
Chen likened the incident to forged withdrawal instructions being processed by a bank while the actual vault keys remain secure. The attacker, in this case, allegedly manipulated the information presented to the authorization system rather than taking control of the underlying signing keys.
Bitget said it has stopped the unauthorized outflows and confirmed that no further transfers can be made through the affected process. The exchange is still investigating how the attacker gained access and said it will release a detailed technical report after the investigation is complete.
Bitget is registered and headquartered in Seychelles and is among the top 10 crypto exchanges by trading volume. The company says it has more than 125 million users globally and supports hundreds of cryptocurrencies, along with tokenized stocks, commodities, foreign exchange and precious metals. Its self-custodial Bitget Wallet has more than 100 million users, while Bitget had about 1,900 employees in 2025.
The incident was detected at 18:31 UTC on Sept. 24 after Bitget identified unauthorized transfers from some of its hot wallets. These wallets remain connected to online infrastructure and handle liquidity for trading, deposits and withdrawals.
The attackers also reached the exchange’s warm-wallet layer, which operates between online hot wallets and offline cold storage. Bitget said its cold wallets were not affected and remain secure.
Chen said Bitget’s User Protection Fund contains more than $464 million, enough to cover the reported $351.6 million loss. She also maintained that user account balances and assets remain protected.
Deposits and trading continue to operate, while withdrawals remain suspended as the exchange completes its security review. Bitget has not set a reopening time for withdrawals and said its technical teams are working on remediation and additional security measures.





