No private keys were stolen here. That detail matters more than the $351.6 million headline, because it changes what kind of problem this actually is.
Bitget CEO Gracy Chen confirmed the attacker compromised a backend system within the wallet infrastructure, spoofed transaction data, and triggered the exchange's own authorization process to move funds out, rather than obtaining keys directly. The breach hit hot and warm wallets, detected at 18:31 UTC on September 24. XRP was the largest single asset taken, Lookonchain estimates 102.93 million tokens worth $157.48 million. Cold wallets, Bitget says, remain fully secure and untouched.
The response has been fast on paper. Emergency protocols activated within minutes, withdrawals suspended pending a security review while deposits and trading stayed open, and Chen says the full loss falls within Bitget's User Protection Fund, holding over $464 million. Law enforcement and on-chain security firms have been notified, flagged addresses already identified. Chen has also said preliminary IP and VPN similarities point toward possible North Korean involvement, though she's stopped short of confirming it.
Context that matters, this is now the largest single crypto theft of 2026, surpassing the roughly $320 million taken from Blockstream's Liquid Network on September 6, making September the costliest month for crypto hacks this year.
My honest read: a compromised authorization process rather than stolen keys is a somewhat more containable failure mode, an infrastructure or access control gap rather than a cryptographic compromise, and cold wallet separation held. Whether funds are genuinely safe still depends on that protection fund actually paying out as promised.
What I'm watching: the full technical report Chen promised, and whether withdrawals resume once the review clears, she's explicitly said she won't commit to a timeline she can't guarantee.
#BTC Price Analysis# #Altcoin Season# $BTC $ETH
Bitget CEO Gracy Chen confirmed the attacker compromised a backend system within the wallet infrastructure, spoofed transaction data, and triggered the exchange's own authorization process to move funds out, rather than obtaining keys directly. The breach hit hot and warm wallets, detected at 18:31 UTC on September 24. XRP was the largest single asset taken, Lookonchain estimates 102.93 million tokens worth $157.48 million. Cold wallets, Bitget says, remain fully secure and untouched.
The response has been fast on paper. Emergency protocols activated within minutes, withdrawals suspended pending a security review while deposits and trading stayed open, and Chen says the full loss falls within Bitget's User Protection Fund, holding over $464 million. Law enforcement and on-chain security firms have been notified, flagged addresses already identified. Chen has also said preliminary IP and VPN similarities point toward possible North Korean involvement, though she's stopped short of confirming it.
Context that matters, this is now the largest single crypto theft of 2026, surpassing the roughly $320 million taken from Blockstream's Liquid Network on September 6, making September the costliest month for crypto hacks this year.
My honest read: a compromised authorization process rather than stolen keys is a somewhat more containable failure mode, an infrastructure or access control gap rather than a cryptographic compromise, and cold wallet separation held. Whether funds are genuinely safe still depends on that protection fund actually paying out as promised.
What I'm watching: the full technical report Chen promised, and whether withdrawals resume once the review clears, she's explicitly said she won't commit to a timeline she can't guarantee.
#BTC Price Analysis# #Altcoin Season# $BTC $ETH

