#bitgetbreachforgedrequestsnotstolenkeys BITGET BREACH: FORGED TRANSFER REQUESTS, NOT STOLEN PRIVATE KEYS
Bitget has confirmed a major security incident involving approximately $351.6M in affected funds.
But there’s a critical detail:
The attackers reportedly did NOT steal Bitget’s private keys.
Instead, Bitget CEO Gracy Chen said attackers breached a backend wallet-service system and used that access to forge transfer information and invoke the authorization/signing process.
KEY FACTS
• Approximately $351.6M in funds were affected
• The incident was detected at 18:31 UTC on September 24
• Portions of Bitget’s hot and warm wallet infrastructure were affected
• Bitget says cold wallets remained secure
• Withdrawals were temporarily suspended during the security review
• Deposits and trading remained operational
• Bitget says its User Protection Fund holds more than $464M and covers the reported loss
WHY THIS MATTERS
This incident highlights an important exchange-security risk: protecting private keys alone is not enough.
Backend systems, transaction-generation logic, authorization workflows and signing infrastructure can also become critical attack surfaces.
Bitget says investigators are still determining exactly how the backend system was compromised, with a full incident report expected.
For traders, the key takeaway is simple:
Exchange security is an entire system — not just a private-key problem.
This remains a developing incident, so additional details may change as the investigation progresses.
$QI $PHA $ARK