Even the safest sounding exchange hacks can still wipe you out if attackers just forge the withdrawal requests instead of stealing keys.
You've been there leaving $USDT and alts on a CEX because self-custody feels like extra work. Then a headline like this drops and you start wondering if your funds are actually next.
I was going through the details on this Bitget situation. They clarified it was forged requests not stolen keys, which sounds like a relief at first glance. It still means attackers found a way to impersonate valid API activity and move funds around without ever touching the core private keys.
That's a real warning about how many attack surfaces these platforms have. Right now with Fear and Greed at 72 people are loading up on names like $SUI and $OP , parking everything on exchanges without a second thought. The risk is you find out too late, withdrawals freeze, and you're stuck waiting while the story unfolds.
Self-custody isn't effortless but at least a forged request on someone else's system isn't your problem the same way.
Where do you think this leaves CEX security going forward?
#BitgetBreachForgedRequestsNotStolenKeys #BitgetSays