Bitget lost $351.6 million overnight after intruders breached a wallet backend, fabricated transaction data and pushed it through the exchange’s own authorization flow. Chief executive Gracy Chen said private keys were never touched, a distinction that limits the ongoing risk but exposes a different operational vulnerability.

The mechanics

The attacker gained access to a critical internal system that prepares transfer requests, then generated instructions that mimicked legitimate outflows. To the signing layer, the requests looked routine. Chen described the method as analogous to slipping counterfeit withdrawal slips past a teller who recognizes the format but not the forgery. The vault itself remained locked; the compromise occurred in the office that drafts the paperwork.

Wallet tiers affected

Hot wallets, the internet-connected liquidity pool that handles instant deposits, trades and withdrawals, were drained first. The breach also reached the warm-wallet buffer, a semi-connected layer that tops up the hot tier and sweeps excess deposits offline. Cold storage, the fully offline vault, was not accessed. Chen confirmed the outflow has been halted and no further unauthorized transfers are possible.

Coverage and operations

Bitget’s User Protection Fund holds more than $464 million, enough to absorb the full loss. Account balances are unchanged and user assets are protected, Chen said. Deposits and trading remain active. Withdrawals are frozen as a precaution while multiple teams conduct a security review and harden the compromised infrastructure. No timeline for reopening withdrawals has been committed.

What remains unknown

The precise entry point into the backend is still under investigation. A full technical report will follow once findings are confirmed. For now, the exchange is operating with a suspended withdrawal function and a promise to announce a restart window only when it can be guaranteed.