The Bitget hack is a good reminder that crypto security isn’t just about protecting private keys.
Around $350M was drained from Bitget’s hot and warm wallets, but according to the exchange, the attackers didn’t actually obtain the private keys.
The more interesting part is how they reportedly compromised a backend wallet system, spoofed transaction data, and got fraudulent transfers through the authorization process.
Bitget CEO Gracy Chen also said preliminary IP/VPN and on-chain patterns look similar to previous North Korea-linked attacks.
That attribution is still being investigated, so I wouldn’t treat it as confirmed yet.
But the bigger takeaway is clear: In crypto, the attack surface isn’t always the wallet itself. Sometimes, it’s the system that tells the wallet what to approve.