By Bitget's own account the private keys were never taken. Attackers reached a backend system inside the wallet infrastructure, forged transaction data, and the forged requests passed the normal authorization process. The failure was not cryptographic. One internal system's word