← All posts

Security

Bitget Lost $351.6 Million Without Losing a Private Key. That Is the Detail Worth Reading Twice

Roughly $351.6 million left Bitget's hot and warm wallets across seven blockchains on September 24. The exchange says no private key was stolen — attackers compromised the backend that tells the signers what to sign, which is a boundary the industry's hot/cold custody model does not defend.

MAI
Bitget's official brand image, used by the exchange as the preview graphic on its own site.

At 18:31 UTC on Thursday, September 24, Bitget's monitoring systems caught unauthorized transfers leaving the exchange's hot wallets. By the time the counting stopped, roughly $351.6 million had moved across seven blockchains. CEO Gracy Chen confirmed the loss that evening, and within hours ruled out the explanation the industry reaches for first.

"Private key compromise has been ruled out." — Gracy Chen, CEO, Bitget

That single sentence is the part of this incident worth sitting with. An exchange can lose a third of a billion dollars with every one of its signing keys still under its own control, and most of the custody architecture the industry has built over the last decade does nothing to prevent it.

What moved, and what did not

Bitget says the breach reached "a critical backend component supporting wallet services." The attackers did not submit fraudulent customer withdrawal requests; they reached the system that instructs the signers, spoofed transaction data, and had legitimate infrastructure authorize the transfers on their behalf. Chen's own analogy was forged withdrawal slips pushed through a bank's real teller windows.

Status
Hot and warm walletsBreached — approx. $351.6M moved
Cold walletsUnaffected, offline
Bitget Wallet (self-custodial)Unaffected
Deposits and tradingOperating
WithdrawalsSuspended, no restoration date
User Protection Fund5,500 BTC, over $464M — covers the full loss

Seven networks were touched: Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Smart Chain and Base. The assets included ETH, XRP, BNB, AVAX, USDT and USDC, with the XRP Ledger carrying the largest single-chain loss. Bloomberg reported that roughly $183 million was swapped into Ether.

Keys are a secret; the instruction path is a system

The hot/warm/cold split that every major exchange runs is a partition of secrets. Keys that sign often live in warm infrastructure; keys that sign rarely live offline. It is a good design for the threat it was drawn against — someone stealing the key material.

It is not a partition of the instruction path. Whatever tells a signer what to sign has to reach the signer, and that path runs through orchestration services, transaction builders and internal APIs that are ordinary software with ordinary bugs. Compromise it and the keys perform exactly as designed. The security model holds; the system it protects hands over the money.

This is the same shape as the February 2025 Bybit theft, in which roughly $1.5 billion left a cold wallet with the keys never stolen — the signing interface was manipulated so the authorized humans approved a transaction that was not the one they believed they were looking at. Different layer, same lesson: cold storage secures the key, not the decision.

Freezing is a weaker tool than it looks

Recovery depends on what the stolen assets are. Stablecoin issuers can freeze balances. The XRP Ledger has freeze mechanics at the issuer level. Ether does not have an issuer, and nobody can freeze it. Converting stablecoins into ETH is therefore not obfuscation — it is a direct move against the only meaningful recovery lever, and by Bloomberg's figure most of the freezable value was gone within hours.

Chen has said "a few" blockchain foundations froze addresses associated with the attacker. No names, addresses or amounts have been given, and the claim has not been corroborated on-chain. Bybit CEO Ben Zhou said his firm would track the funds through its LazarusBounty platform.

Solvency is not the open question

Bitget's User Protection Fund, 5,500 BTC and worth more than $464 million, exceeds the loss. BGB, the exchange's token, fell 3.3% to about $1.97 — a mild reaction, though with withdrawals frozen there is limited ability to vote with one's feet. The exchange, founded in 2018 and claiming 120 million registered users, can absorb the number.

What it cannot yet do is say which component lied. Chen's line on restoring withdrawals was that the company "will not commit to a timeline we cannot deliver," and that is both the honest answer and the worrying one. You do not restart a withdrawal pipeline while the intrusion route into the system that authorizes transfers is still described as under active investigation.

The North Korea attribution is Bitget's own, and rests on its reading of the evidence rather than an independent forensic finding:

"Based on IP behavior patterns and on-chain analysis, the attack method in this incident is highly consistent with known patterns of North Korean hacker organizations." — Gracy Chen

That may well be right. It also does not change what anyone else should take from this. The interesting question for every other custodian is not who did it but whether their own answer to "can a compromised internal service cause a valid signature over an invalid transaction" is anything better than "we assume not." Bitget has promised a full root-cause report. That document, not the attribution, is the one worth reading.

Sources: Bitget security notice · CoinDesk · BleepingComputer · Bloomberg via Insurance Journal · CNBC · Forbes · The Crypto Times

Keep reading