Bitget Reports $351.6 Million Loss After Attack on Wallet Infrastructure

Date: 2026-09-26
news-banner

Bitget Reports $351.6 Million Loss After Attack on Wallet Infrastructure

The exchange says attackers manipulated transfer data inside a wallet backend rather than stealing private keys. Withdrawals remain paused while the company investigates and repairs its systems.


Key Points

  • Bitget reported a $351.6 million loss after unauthorized transfers were detected on September 24.
  • CEO Gracy Chen says the attack involved a compromised wallet backend and falsified transaction data; the company has ruled out a private-key breach.
  • Hot and warm wallets were affected. Bitget says its cold wallets remain secure and its user protection fund can cover the loss.

Bitget is investigating a security breach that led to the loss of approximately $351.6 million in digital assets. The exchange detected unauthorized movements from some of its hot wallets at 18:31 UTC on September 24. In a subsequent explanation, CEO Gracy Chen said the attackers gained access to a critical system behind the exchange's wallet operations and submitted falsified transfer data through its authorization process.

How the transfers passed through the system

According to Chen, the evidence so far does not point to stolen private keys. Those keys are the cryptographic credentials used to authorize movements of digital assets. Instead, the alleged intrusion targeted a backend component that prepares or handles transaction information before a transfer is approved. This distinction helps explain the reported mechanism, although Bitget has yet to publish a full technical account of how the attackers entered the system.

The immediate security question is how falsified transfer data reached the authorization process.

Incident analysis based on Bitget's public account

The incident extended beyond hot wallets, which stay connected to support day-to-day transactions, into Bitget's warm-wallet layer. Warm wallets sit between frequently used online funds and offline storage. Chen said the exchange's cold wallets were unaffected and that it had stopped any further unauthorized outflows. The company has not yet disclosed the precise method used to compromise the backend.

Withdrawals paused during the review

Bitget has kept deposits and trading available but suspended withdrawals while technical teams review and strengthen the affected systems. Chen did not provide a date for withdrawals to resume, saying the exchange would announce a timeline once it could confirm one.

The company says its User Protection Fund contains more than $464 million and is sufficient to absorb the reported loss. Bitget also says customer account balances remain accurate and assets are protected. These are the exchange's statements; the public has not yet seen the promised technical report explaining the breach in detail.

What the investigation still needs to establish

The central unanswered issue is the path into the wallet backend and the controls that allowed fabricated transaction data to be processed. A complete incident report should clarify the affected systems, the sequence of unauthorized transfers and the changes made before withdrawals reopen. Until then, the distinction between intact private keys and compromised transaction infrastructure describes Bitget's current findings, rather than a final independent assessment.

advertisement image

Leave Your Comments