#bitgetbreachforgedrequestsnotstolenkeys
The Bitget Breach Shows Why Exchange Security Is More Than Private Keys
The Bitget breach has a much more interesting lesson than simply saying “$350 million was hacked.”
According to Bitget, the attackers did not steal the exchange’s private keys.
Instead, the incident involved a compromise of a critical backend system within the exchange’s wallet infrastructure. The attackers allegedly manipulated or spoofed transaction data and then used the exchange’s own authorization process to move funds.
Around $351.6 million was affected across parts of Bitget’s hot and warm wallets, while the exchange said its cold wallets remained secure.
That distinction matters.
Private-key protection is one of the most important parts of crypto security, but it isn't the only layer protecting funds.
An exchange also has to ensure that the systems generating, validating and presenting transactions to its signing infrastructure haven't been compromised.
If an attacker can manipulate what an authorized system believes it is signing, the security problem can exist before the private key is ever used.
That's why the incident raises broader questions about exchange architecture.
Security isn't just about protecting keys. It also involves transaction validation, backend integrity, wallet infrastructure, authorization controls and monitoring.
The Bitget incident therefore highlights a different attack surface from the classic private-key theft scenario.
Bitget has said the attack was contained and that a full technical report is expected. That report could be particularly important because the biggest unanswered question isn't simply how much was lost.
It's how the attacker gained control over the transaction-generation layer — and why the existing validation and authorization controls didn't stop the manipulated transactions.
For the broader crypto industry, those details could matter far beyond Bitget.
The real security lesson may be that protecting the key isn't enough if the system deciding what gets signed can also be compromised.

