Bitget experienced a significant loss of $351.6 million due to a cyberattack that exploited a vulnerability in its wallet backend, as revealed by CEO Gracy Chen on X. The attackers managed to spoof transaction data to execute the unauthorized transfer, but importantly, the exchange's private keys remained secure.

Chen explained that the hackers infiltrated a crucial backend component of the wallet system, enabling them to fabricate transaction requests that triggered the exchange's authorization process for fund transfers. She assured users that there was no compromise of private keys, which has historically been a major source of losses in the crypto space.

"The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out," Chen stated on X. "Private key compromise has been ruled out." This clarification is significant, as breaches involving private keys often result in catastrophic financial losses for exchanges.

In the context of crypto wallets, each has two keys: a public key, which can be shared to receive funds, and a private key, which is kept secret to authorize spending. If an attacker gains access to the private key, they can initiate transfers at will.

Chen likened the breach to a scenario where someone submits forged withdrawal slips through a bank teller's window, emphasizing that the vault keys remained secure. The unauthorized outflow of funds has since been halted, and Chen assured that there would be no further unauthorized transfers. An investigation into the specific methods used for the breach is ongoing, with a comprehensive technical report expected to follow.

Details of the Breach

The breach came to light when Bitget's systems identified unauthorized transfers from certain hot wallets at 18:31 UTC on September 24. Hot wallets are online wallets that facilitate quick transactions, acting as a liquidity source for exchanges. Chen noted that the attack also impacted warm wallets, which serve as a buffer between hot wallets and fully offline cold storage.

Despite the breach, Bitget confirmed that its cold wallets, which are offline and serve as secure vaults for funds, remain fully protected. The exchange also stated that its User Protection Fund, valued at over $464 million, would cover the loss incurred from the hack. "User funds are safe," Chen reassured users, adding that account balances remain intact and assets are protected.

While deposits and trading activities are ongoing, withdrawals have been suspended as a precautionary measure while a security review is conducted. Chen did not provide a timeline for when withdrawals would resume, emphasizing that multiple technical teams are actively working to enhance system security and resolve the situation. "We will announce a timeline as soon as one is confirmed — we will not commit to a window we cannot guarantee," she stated.