Bitget CEO Details $352M Hack, Says Private Keys Were Not Compromised
Bitget CEO Gracy Chen said a $351.6 million security breach at the crypto exchange involved a compromised wallet backend and spoofed transaction data, rather than stolen private keys.
Chen said attackers gained control of a critical backend component within Bitget’s wallet infrastructure. They allegedly altered transaction information and used the exchange’s normal authorization mechanism to process unauthorized transfers.
“The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out,” Chen wrote on X. She said the investigation had ruled out a compromise of Bitget’s private keys.
Private keys are the confidential credentials that authorize crypto transactions, while public keys are used to receive assets and can be shared. If a private key is stolen, an attacker can use it to sign transactions and move funds.
Chen said the incident was instead similar to an attacker creating fraudulent withdrawal instructions that appeared legitimate to a bank’s processing system while the actual vault keys remained untouched.
Bitget said it has contained the unauthorized transfers and that no further transfers can be made through the affected process. The exchange continues to investigate the initial system intrusion and plans to publish a technical report after confirming the details.
The Seychelles-registered exchange is among the top 10 crypto platforms by trading volume. Bitget says it serves more than 125 million users worldwide and offers hundreds of crypto assets, as well as tokenized stocks, commodities, foreign exchange and precious metals. Its self-custodial Bitget Wallet has more than 100 million users, while the company had approximately 1,900 employees in 2025.
Bitget detected unauthorized activity at 18:31 UTC on Sept. 24 involving several hot wallets. These wallets remain connected to online systems and provide liquidity for trading, deposits and withdrawals.
The breach also extended to the warm-wallet layer, which sits between online hot wallets and offline cold storage. Bitget said its cold wallets remained secure.
Chen also pointed to Bitget’s User Protection Fund, which holds more than $464 million. She said the fund is sufficient to cover the reported loss and that user balances and assets remain protected.
Trading and deposits remain operational, but withdrawals have been temporarily suspended while the exchange completes its security review. Bitget has not announced when withdrawals will resume, saying technical teams are continuing remediation and security-hardening work.
Share this content:













