Another major centralized exchange has suffered a massive security breach.
On September 24, crypto exchange Bitgetâ detected unauthorized transfers from parts of its hot-wallet infrastructure, with approximately $351.6 million worth of crypto affected. The exchange temporarily suspended withdrawals while its security team investigates the incident.
And the latest information makes this attack particularly interesting.
The hackers may NOT have stolen Bitgetâs private keys
According to an update from Bitget CEO Gracy Chen, preliminary findings indicate that the attackers compromised a critical backend system within Bitgetâs wallet infrastructure.
The attackers were allegedly able to spoof transaction data and trigger Bitgetâs authorization process, allowing funds to be transferred out. Bitget says its investigation has so far ruled out a private-key compromise.
Thatâs an important distinction.
Crypto security discussions often focus heavily on protecting private keys, but an exchange is made up of much more than wallets. Backend infrastructure, transaction authorization systems and internal controls can potentially become attack surfaces as well.
How much was stolen?
Bitget currently estimates approximately $351.6M in assets were affected.
On-chain observers initially spotted large amounts of ETH, USDT, USDC, AVAX, BNB and other assets moving from Bitget-linked wallets toward newly created addresses. Some of the assets were subsequently swapped on-chain.
Bitget says the breach affected only portions of its hot and warm wallet layers, while its cold wallets remained secure.
Are Bitget users losing their money?
For now, Bitget says user balances remain protected.
The exchange says its User Protection Fund currently holds more than $464 million, enough to cover the estimated $351.6 million affected by the incident.
Withdrawals were temporarily suspended as a security precaution, while deposits and regular exchange trading remained operational. Bitget also said law enforcement and blockchain-security companies had been contacted.
North Korea suspected?
Thereâs another developing angle.
Chen has said preliminary evidence suggests a North Korean hacking group may be responsible, citing IP-related clues associated with VPN infrastructure reportedly used by such actors. This remains a preliminary attribution rather than a confirmed finding, so it should be treated cautiously until the investigation is completed.
Why this hack matters
The bigger story isnât simply that another exchange lost hundreds of millions of dollars.
If Bitgetâs preliminary explanation is confirmed, the attackers didnât necessarily need to steal the keys protecting the wallets.
They allegedly attacked the system that tells the wallets what transactions to authorize.
That highlights an uncomfortable reality for centralized exchanges:
Your private keys can be secure while the infrastructure surrounding them can still be vulnerable.
The industry has spent years improving cold storage, multisig systems and Proof-of-Reserves. The next major security battle may increasingly be about protecting the backend infrastructure connecting all of those systems together.
For users, the coming hours will be important. Bitget has promised a full incident report covering the root cause and corrective measures.
$351.6 million affected. Withdrawals suspended. Private keys reportedly uncompromised.
Now the biggest question is exactly how the attackers got inside â and whether any other infrastructure remains exposed.
This story is developing. Information may change as Bitget releases additional findings.
#Bitget #CryptoHack #CryptoNews #Bitcoin #Ethereum #CyberSecurity #BinanceSquare
