Bitget’s hot wallet was reportedly compromised in an attack involving around $350M in assets.

What makes this incident particularly notable is that the attacker reportedly did not obtain private keys. Instead, a critical wallet backend was compromised, allowing fraudulent transfer data to be created and the signing process to be triggered.

Bitget says its cold wallets remain unaffected, while its $464M+ User Protection Fund is intended to cover the affected amount.

The bigger lesson is clear: crypto security doesn’t end with private keys. The infrastructure connecting wallets, backend systems, transaction data, and signing mechanisms can become a critical attack surface too.

For users, it’s another reminder to think carefully about exchange custody and avoid keeping all of your crypto on a single CEX.

Not your keys, not your crypto. Stay safe.