BITGET $352M HACK EXPLAINED: Forged Requests, NOT Stolen Keys! Everyone is panicking about private keys. But Bitget CEO Gracy Chen just confirmed something scarier. What Actually Happened: ❌ Private keys were NOT stolen (cold, hot & warm wallets safe) ❌ User withdrawal requests were NOT forged ✅ Hackers breached a CRITICAL backend system ✅ They spoofed transaction data ✅ They triggered Bitget's OWN authorization process to move $351.6M Think of it like this: "They didn't crack the vault, they forged the paperwork." The vault keys never left the building, someone just created fake official slips. Current Status: Detected at 18:31 UTC, Sep 24 Cold wallets secure $464M User Protection Fund will cover the loss CEO links attack to North Korea" is saying that the attackers allegedly did not steal the wallet private keys themselves. Instead, they are reported to have broken into an important internal system, faked transaction details, and caused Bitget’s own approval process to authorize the movement of funds. In simpler terms, the security problem was not that the “vault key” was taken, but that the system was tricked into treating fake instructions as legitimate ones.
The “forged paperwork” comparison helps explain the difference clearly. If someone steals a private key, that usually means they directly control the wallet. But if they forge internal transaction data, they may be able to get the company’s own system to sign and process transfers without ever holding the actual key. That points to a deeper weakness in backend controls, internal verification, or transaction approval design.
The post also says cold wallets were safe and that the loss would be covered by the User Protection Fund, which is meant to reassure users that customer assets are not necessarily gone because of this incident. The mention of North Korea should be understood as an attribution claim from the CEO, not a final publicly proven conclusion.
So the main idea is: this was being presented not as a classic “private keys got stolen” hack, but as a case where the exchange’s internal transaction authorization flow was allegedly manipulated. That can be especially concerning because it suggests the attackers may have exploited trust inside the system rather than