Bitget $351.6 million stolen — let’s explain the whole thing in plain language 👇

💡 Think of it like this:
Private key (signing machine): the financial company seal locked in a safe, used to authorize and stamp withdrawals.
Business back-end system: the company’s OA approval system, responsible for submitting and reviewing “withdrawal requests.”

What happened this time?
The hackers didn’t break into the safe to steal the seal (no private key leakage);
Instead, they hacked the company’s OA approval system and forged a large number of seemingly legitimate “withdrawal approval documents”;
Then the automated cashier system, seeing that the approval workflow was “complete and properly processed,” faithfully stamped the seal and executed the transfer.

🔍 Reconstructing the real stolen-chain process:
Upstream system compromised: the hackers infiltrated the critical back-end systems inside the wallet architecture.
Forged transfer data: inside the system, they generated fake withdrawal/transfer requests, successfully bypassing internal checks, and triggering the payout authorization.
Hot/warm wallets execute faithfully: the downstream hot/warm wallet signing module received what appeared to be fully valid “legal instructions,” completed signature broadcasting, and the funds were transferred to the hackers’ address.

📌 Key facts and impact — quick summary:
Scope of damage: about $351.6 million, all concentrated in the hot wallet and part of the warm wallets.
Cold wallet safety: the “underground offline vault (cold wallet)” holding large core assets was not affected in any way.
Are user assets affected? According to official statements, there is a Protection Fund of over $464 million, which can fully cover this loss.

Current status: top-ups and trading are operating normally; withdrawals are temporarily paused while maintenance is ongoing.