In a significant security incident that has sent ripples through the digital asset ecosystem, crypto exchange Bitget has confirmed a massive security breach resulting in the loss of approximately $351.6 million. The incident, which unfolded late on September 24, saw attackers infiltrate the exchange’s internal systems to orchestrate unauthorized transfers. Despite the substantial scale of the financial loss, Bitget CEO Gracy Chen has moved to reassure the global user base, emphasizing that the breach did not involve the theft of private keys, the cryptographic bedrock that governs the ownership of digital assets.
Anatomy of the Breach
The breach was first identified by Bitget’s internal monitoring systems at 18:31 UTC on September 24, when the exchange detected anomalous outbound activity originating from several of its hot wallets. In the immediate aftermath, the exchange moved to contain the situation. According to statements released by Gracy Chen on the social media platform X, the attackers successfully compromised a critical backend system within the exchange’s wallet infrastructure.
Rather than bypassing the security protocols through a conventional cryptographic attack—such as brute-forcing or stealing private keys—the perpetrators employed a more sophisticated method of deception. By gaining access to the backend, they were able to spoof transaction data, effectively tricking the exchange’s internal authorization mechanisms into believing that the requested transfers were legitimate.
"The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out," Chen explained in her statement. She explicitly ruled out the possibility of a private key compromise, a distinction that carries significant weight in the context of cybersecurity.
To understand the nature of this attack, one must consider the standard architecture of a digital wallet. Every crypto wallet relies on a dual-key system: the public key, which serves as an address that can be shared for receiving funds, and the private key, which acts as the ultimate digital signature required to authorize spending. If a private key is compromised, an attacker effectively gains full, unrestricted control over the assets held within that wallet. By confirming that private keys remained secure, Bitget suggests that the underlying cryptographic security of their vaults remained intact, and the breach was instead a failure of the internal verification and authentication layers that sit above the blockchain protocols.
Chen likened the breach to a sophisticated case of identity fraud within a traditional financial institution. In this analogy, the vault keys—the private keys—never left the possession of the bank. Instead, an intruder managed to infiltrate the administrative office responsible for processing internal withdrawal requests. By creating paperwork that appeared perfectly legitimate and submitting it through the bank’s standard approval window, the attacker was able to trick the institution’s automated teller systems into authorizing the payout. To the internal systems tasked with verifying the transactions, the outflow appeared to be a routine, authorized event.
Containment and Operational Status
Following the detection of the unauthorized transfers, Bitget initiated immediate containment procedures. As of the most recent updates from the exchange, the outflow has been successfully halted, and no further unauthorized transactions have been identified.
"Loss containment is confirmed. No further unauthorized transfers are possible," Chen stated. While the immediate threat has been mitigated, the specific technical entry point used by the attackers remains under active investigation. The exchange has deployed multiple technical teams to conduct a deep-dive forensic analysis, with the promise that a comprehensive technical report will be released to the public once the findings have been verified.
The breach primarily affected Bitget’s hot wallet layer, which serves as a temporary, internet-connected liquidity hub for the exchange to facilitate rapid trades, deposits, and withdrawals. The attackers also managed to gain access to the "warm-wallet" layer—a semi-connected buffer system that acts as a bridge between the highly accessible hot wallets and the secure, fully offline cold storage vaults. Crucially, Chen confirmed that Bitget’s cold storage—the offline vault where the vast majority of user assets are kept—remains fully secure and unaffected by the intrusion.

In response to the incident, Bitget has taken the difficult but necessary step of freezing all user withdrawals as a precautionary measure. This decision remains in effect while the exchange conducts a rigorous security review and continues to harden its infrastructure against future threats. While deposits and trading remain operational, the exchange has not provided a definitive timeline for when withdrawal services will be restored.
"Multiple technical teams are working in parallel on system remediation and security hardening," Chen noted. "We will announce a timeline as soon as one is confirmed—we will not commit to a window we cannot guarantee."
Impact on Users and Financial Solvency
For many users, the primary concern following such a high-profile hack is the safety of their personal assets. Bitget has attempted to address these anxieties by highlighting its robust financial backing. According to the exchange, its User Protection Fund—a dedicated reserve set aside to compensate for exactly these types of scenarios—holds more than $464 million. This amount is sufficient to cover the total losses incurred during the breach, which stands at $351.6 million.
"User funds are safe," Chen assured customers. "Your account balances are accurate and your assets are protected."
The ability of an exchange to honor its commitments during a crisis is often a test of its long-term viability. By utilizing the User Protection Fund, Bitget intends to absorb the financial impact of the hack without shifting the burden onto its users. This strategy is a common, though significant, move for major centralized exchanges seeking to maintain market confidence and regulatory standing following a security lapse.
The incident serves as a stark reminder of the complexities involved in managing large-scale cryptocurrency infrastructure. As exchanges grow in size and complexity, the surface area for potential attacks expands. While the industry has made strides in securing private keys through multi-signature and threshold signature schemes, the "backend" systems that manage the flow of data and authorize these transactions remain a critical point of failure.
The distinction between a "key compromise" and a "backend system compromise" is a recurring theme in the history of crypto hacks. Historically, private key theft has been responsible for some of the most catastrophic losses in the industry’s short history. However, as infrastructure has become more robust, attackers have increasingly turned their attention toward the periphery of these systems—targeting the internal processes, API integrations, and administrative dashboards that serve as the interface between the human operators and the cryptographic code.
Bitget’s investigation into how the attackers managed to spoof transaction data through the backend system will likely be closely scrutinized by security researchers and the broader crypto community. The findings could lead to new industry standards regarding how authorization processes are audited and how internal backend systems are isolated from the critical wallet infrastructure.
For now, the situation at Bitget remains one of active remediation. The exchange is balancing the need for transparency with the logistical requirements of a massive, multi-faceted security audit. While the financial loss is substantial, the firm’s reliance on its insurance-like protection fund and its commitment to a transparent reporting process will be the primary metrics by which the market judges the exchange’s recovery in the coming weeks. As the investigation progresses, the focus for the company will be twofold: restoring full functionality for its users and demonstrating that the internal vulnerabilities exploited during the breach have been permanently sealed.

