Bitget Responds to a $351.6 Million Security Incident
Unauthorized wallet movements trigger an emergency shutdown
Bitget is investigating one of the largest cryptocurrency exchange security incidents reported in 2026 after roughly $351.6 million was moved without authorization from a limited group of exchange-controlled wallets. The platform temporarily suspended withdrawals while its security team assessed the breach and attempted to contain further losses.
According to information disclosed by Bitget CEO Gracy Chen, the exchange detected suspicious transfers at approximately 18:31 UTC on September 24. Emergency procedures were activated shortly afterward. Independent blockchain researchers had also begun highlighting unusual movements associated with wallets attributed to the exchange.
The emerging explanation makes the Bitget hack particularly noteworthy. Bitget’s preliminary investigation indicates that attackers may not have obtained the private keys traditionally required to authorize cryptocurrency transfers. Instead, the compromise reportedly involved wallet backend infrastructure and manipulated transaction information.
That distinction could have significant implications for exchange security. Protecting cryptographic keys remains essential, but an attacker who compromises the systems responsible for preparing or validating transactions may potentially circumvent safeguards without directly stealing those keys.
Cold storage reportedly remained outside the breach
Bitget said the unauthorized activity was concentrated in a limited number of hot and warm wallets. Its cold wallets and the majority of customer assets were reportedly unaffected.
Those claims remain subject to the exchange’s continuing investigation. Until a complete technical review is available, the precise attack path, total recoverable funds and potential secondary effects cannot be considered settled.
Spoofed Transaction Data Changes the Security Picture
Private-key theft may not have been the attack vector
Many major exchange breaches follow a recognizable pattern: criminals obtain signing credentials, compromise a multisignature process or trick employees into approving malicious transactions. The initial explanation surrounding the Bitget hack points toward a different scenario.
Chen said the preliminary findings suggest the attackers compromised wallet backend systems and used spoofed transactions or transaction data to facilitate unauthorized movements. In practical terms, the vulnerability may have existed in software surrounding the signing process rather than in the cryptography protecting the private keys themselves.
This is why spoofed transactions are an important part of the investigation. A secure key cannot necessarily protect funds if another compromised component causes a legitimate signing system to receive misleading information about what it is approving.
The incident consequently puts hot wallet security back under scrutiny. Exchanges need rapidly accessible liquidity to process deposits and withdrawals, but every online component connected to those wallets creates another potential attack surface.
Wallet architecture matters beyond key custody
Modern exchanges generally use multiple security layers, including withdrawal policies, transaction simulators, allowlists, signing systems and automated risk controls. The effectiveness of that architecture depends on whether each layer can independently identify malicious activity.
A backend compromise can become especially dangerous when separate controls rely on the same corrupted data. Truly independent verification of destination addresses, amounts and transaction payloads can reduce the likelihood that one compromised service becomes a single point of failure.
North Korea Connection Remains a Preliminary Lead
Investigators examine infrastructure clues
Gracy Chen also disclosed that the early investigation identified internet protocol addresses corresponding with VPN selections associated with a North Korean hacking group. That is an investigative lead rather than definitive attribution.
VPN infrastructure can complicate attribution because IP addresses do not necessarily reveal where an attacker is physically located or who controls an operation. Cybersecurity teams typically combine infrastructure evidence with malware signatures, transaction behavior, operational patterns and blockchain fund flows before reaching stronger conclusions.
North Korean state-linked hacking organizations have previously been accused by governments and blockchain investigators of targeting cryptocurrency businesses. That history makes the possibility noteworthy, but it does not by itself prove responsibility for this incident.
Blockchain movements may provide additional evidence
Unlike cash theft, stolen cryptocurrency leaves a public trail when assets travel across transparent blockchains. Investigators can monitor addresses, swaps and transfers while attempting to identify interactions with centralized services or other infrastructure capable of linking blockchain activity to real-world entities.
The Bitget hack could therefore generate considerably more forensic evidence as the funds move. Exchanges can also cooperate by flagging addresses suspected of receiving stolen assets, although recovery becomes harder when attackers use sophisticated laundering techniques or move between networks and assets.
Why Exchange Wallet Security Faces a Broader Test
Online liquidity creates unavoidable trade-offs
The scale of the reported loss highlights an enduring challenge for centralized trading venues. Customers expect rapid withdrawals around the clock, which requires exchanges to maintain operational wallets capable of interacting with blockchain networks. Keeping every asset offline would provide additional isolation but would make normal exchange operations impractical.
That makes hot wallet security a question of limiting exposure rather than eliminating online wallets altogether. Platforms can cap hot-wallet balances, isolate operational environments, apply withdrawal limits and require independent verification before large transactions leave custody.
The reported separation between Bitget’s affected wallets and its cold-storage systems illustrates why tiered custody exists. Even so, a loss approaching $352 million demonstrates that limiting the number of compromised wallets does not necessarily mean limiting the financial impact to a trivial amount.
Spoofing risk calls for independent validation
If spoofed transactions are ultimately confirmed as central to the breach, security teams across the industry may review how transaction details travel from wallet applications to signing infrastructure.
The key question will be whether a signing system independently verifies exactly what will happen onchain or simply trusts information supplied by another backend service. Hardware security modules and protected private keys offer considerable protection, but they cannot compensate for every weakness elsewhere in the transaction pipeline.
What the Incident Could Mean for Bitget Users
Withdrawal restoration will be closely watched
For customers, the immediate concern is when normal withdrawal services resume and whether Bitget can demonstrate that the exploited pathway has been closed. Suspending withdrawals can help contain an active compromise, but prolonged restrictions can also increase uncertainty among users.
Gracy Chen has characterized the investigation as ongoing, meaning early technical conclusions could change as investigators examine logs, infrastructure and blockchain activity. A comprehensive post-incident report would help establish exactly which controls failed and what measures have been introduced afterward.
The Bitget hack also reinforces a basic distinction in centralized exchange custody: balances displayed in an exchange account are controlled through the platform’s infrastructure until users withdraw them to addresses where they personally control the keys.
For the broader market, the most consequential lesson may concern operational security rather than cryptocurrency cryptography itself. If the private keys remained uncompromised while backend manipulation enabled the transfers, exchanges may need to devote even more attention to transaction construction, validation and internal trust boundaries.
Frequently Asked Questions
How much cryptocurrency was reportedly lost in the Bitget incident?
Initial reports place the unauthorized transfers at approximately $351.6 million. Bitget has said only a limited selection of hot and warm wallets was affected, while its cold wallets and most platform assets remained outside the incident. The final loss could depend on the investigation and any subsequent asset recovery.
Were Bitget’s private keys stolen?
According to Bitget’s preliminary account, investigators do not believe stolen private keys were the central cause. The working theory involves a compromised wallet backend and manipulated transaction information. Because the forensic investigation is still developing, that explanation should not yet be treated as a final technical conclusion.
Has North Korea been confirmed as responsible?
No definitive attribution has been established based on the information disclosed so far. Bitget says investigators found IP information associated with VPN choices previously linked to a DPRK hacking group. Such evidence can support an investigation, but stronger attribution normally requires multiple independent technical indicators.
