Bitget lost $351.6M from its hot and warm wallets on September 24. The attacker didn't steal private keys. They broke into a backend system, faked transfer data, and tricked Bitget's own signing process into sending funds out.

Who did it? Bitget CEO Gracy Chen said the attack pattern is highly consistent with North Korean hacker groups, based on IP behavior and on-chain analysis. The stolen funds were swapped for ETH quickly, a common laundering tactic.

How did it happen? The attacker compromised a critical backend system in Bitget's wallet infrastructure, spoofed transaction data, and triggered the authorization process. Private key compromise has been ruled out. This is the digital version of slipping forged withdrawal slips through a bank's own teller window.

Are funds safe? Bitget says yes. The $351.6M loss falls entirely within its User Protection Fund, which holds over $464M. Cold wallets were not affected. Deposits and trading continue. Withdrawals are paused as a precaution, not because of a shortfall.