How Hackers Drained $351.6m From Bitget Without Stealing Private Keys

 How Hackers Drained $351.6m From Bitget Without Stealing Private Keys

Cryptocurrency exchange Bitget has lost approximately $351.6 million after hackers compromised part of its wallet infrastructure, but the exchange says the attackers did not obtain its private keys.

Bitget detected unauthorised transfers from some of its hot wallets at 18:31 UTC on Thursday, September 24, and immediately activated its emergency response procedures.



The exchange later confirmed that the incident affected portions of its hot and warm wallet layers, while its cold wallets remained secure.

The breach has raised questions about how such a large amount of cryptocurrency could be moved without the attackers gaining access to the private keys normally used to authorise transactions.

How the hackers moved the money

Bitget CEO Gracy Chen said the attackers compromised a critical backend system within the exchange’s wallet infrastructure.

They then allegedly manipulated transaction information and used the compromised system to trigger Bitget’s normal authorisation process.

In other words, according to the preliminary findings, the attackers did not need to steal the private keys themselves. They manipulated the system that supplied transaction information to the authorisation process, allowing unauthorised transfers to be approved.



Bitget said its investigation had ruled out private-key compromise, although the specific method used to initially gain access to the backend system remained under investigation.

The distinction is important because private-key theft would potentially give an attacker a direct means of authorising further transactions.

$351.6m moved from Bitget wallets

Bitget initially confirmed that approximately $351.6 million in assets had been affected.

The exchange said the unauthorised transfers were confined to parts of its hot and warm wallet infrastructure.

Hot wallets are connected to online systems and are commonly used to facilitate transactions, while cold wallets are kept offline or with stronger isolation.



Bitget said its cold wallets remained fully secure throughout the incident.

Blockchain researchers had initially tracked more than $170 million moving from Bitget-associated wallets to a newly created address before the exchange confirmed the wider scale of the incident.

Bitget freezes withdrawals

Following the attack, Bitget temporarily suspended cryptocurrency withdrawals while its security teams carried out a review.

The exchange said deposits and trading remained operational, while withdrawals would resume after the security review and system remediation were completed.



Bitget has not given customers a fixed time for when withdrawals will return.

The exchange said abnormal transfer addresses had been identified and reported, while law-enforcement agencies and blockchain security firms had been notified and brought into the investigation.

Bitget says user funds are protected

Despite the size of the loss, Bitget said customers’ account balances remain accurate and their assets are protected.

The company said the entire estimated loss falls within its User Protection Fund, which it valued at more than $464 million in its incident notice.

That means the $351.6 million loss is below the amount Bitget says it has available in the protection fund.

The fund is designed to provide an additional layer of protection against cybersecurity incidents and other losses affecting eligible users.

Bitget therefore says the hack does not mean customers have lost the balances displayed in their accounts.

What Bitget is investigating

While the exchange says it has identified the compromised part of its infrastructure, the precise method used by the attackers to enter the backend system has not yet been fully established.

Bitget initially said it would not speculate about the attack vector until its investigation was complete.

The company has promised a fuller incident report covering the root cause and corrective measures.

There have also been reports suggesting a possible connection to North Korean hacking operations. However, that attribution remains an investigative lead rather than an established finding. Bitget CEO Gracy Chen has referred to similarities involving IP addresses and VPN use, but the investigation has not conclusively identified the attackers.

What the Bitget hack shows about crypto security

The incident highlights a security problem that goes beyond protecting private keys.

Even when the keys themselves remain secure, a compromised system surrounding the authorisation process can potentially manipulate the information used to initiate legitimate-looking transactions.

That is what makes the Bitget incident significant: according to the exchange’s preliminary account, the attackers did not simply obtain a key and transfer the money. They compromised part of the infrastructure that tells the wallet system what transactions to authorise.

Bitget says the vulnerability has been contained and that no further unauthorised transfers are possible.

The exchange is now working on system repairs and additional security measures before restoring withdrawals.