THE BITGET HACK SHOWS THAT SECURITY DOES NOT END WITH PRIVATE KEYS

The Bitget hack is a reminder that crypto security is bigger than simply protecting private keys.

On September 24, attackers moved about $387.5M from Bitget's exchange infrastructure.

Bitget says its private keys were not compromised. Instead, the attacker exploited a backend vulnerability and bypassed security controls to authorize fraudulent transfers.

The more interesting part came after the theft.

The attacker has continued moving funds across chains. On September 28, about 2,390 $ETH worth roughly $6.3M was converted into 75.2 $BTC through THORChain, despite Bitget asking the protocol to block addresses associated with the hack.

At the same time, $NEAR Intents reportedly detected more than $50M in attempted flows linked to the attacker, with its security system blocking most of the activity. About $503K was frozen during execution, while roughly $166K reportedly passed through.

This creates an important lesson for crypto users: decentralization, permissionless infrastructure, and security are not the same thing.

A protocol can be permissionless while still having security mechanisms. But the moment stolen funds move across multiple chains, exchanges, bridges, and swap protocols, responsibility becomes much harder to define.

For users, the lesson is simple: don't judge a platform's security only by whether it uses cold wallets or protects private keys.

Look at the entire system, including backend infrastructure, authorization controls, withdrawal procedures, monitoring, and how quickly suspicious transactions can be detected and contained.

Crypto gives users unprecedented control over assets, but that also means the security architecture behind every transaction matters.

The Bitget incident shows exactly why.