Bitget says $351.6M hack used spoofed transfers, not stolen private keys

By Crypto Wire
September 25, 2026

Bitget CEO Gracy Chen said on September 25, 2026 that the exchange’s $351.6 million drain ran through spoofed transfer data on a compromised wallet backend—not stolen private keys—per CoinDesk’s markets wrap of her X posts and a parallel CNBC report on the same livestream. That mechanism update is unused Rug Room tape for the new Sep 25 OC day: distinct from yesterday’s confirmed drain (LN 9688) and the preliminary DPRK/VPN attribution (LN 9694). Chen framed the attack as forged withdrawal paperwork that cleared Bitget’s own authorization window while the vault keys never left the building.

What Chen says happened on-chain and in-house. CoinDesk quotes her: “The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out. Private key compromise has been ruled out.” Systems flagged unauthorized hot-wallet transfers at 18:31 UTC on September 24. The breach reached hot and warm wallets; cold wallets “remain fully secure,” and she said loss containment is confirmed with no further unauthorized transfers possible. A full technical report is promised once intrusion details are confirmed—attribute those as company claims, not as an independent forensic close.

Coverage and user-facing status. Bitget says its User Protection Fund holds more than $464 million and covers the full $351.6 million loss; Chen wrote that account balances remain accurate and user funds are protected. Deposits and trading stay open. Withdrawals remain frozen as a precaution pending security review, with no guaranteed reopen window—“we will not commit to a window we cannot guarantee,” per CoinDesk. CNBC separately notes about 19 transfers across hot/warm infrastructure and assets spanning ether, XRP, USDT, USDC, Avalanche, and BNB on Ethereum, XRPL, Avalanche, BNB Smart Chain, and Arbitrum—broader than early on-chain reads that only caught roughly $183 million.

Why this is the Sep 25 lead instead of another mint or ETF print. Circle’s viral $500 million USDC-on-Solana mint claim is thin SolanaFloor aggregation and near-echoes prior USDC Treasury Solana mints already on the desk (LN 9028). Bitcoin ETF $191 million sixth-day inflows near-echo Sep 24’s fifth-day $347 million piece (LN 9648). CreditStrategy and Identity MD closed last night. The clean unused wire is Bitget’s spoofed-backend method statement—private keys ruled out, protection-fund cover assertion, withdrawals still paused—published within the last-six-hour window on CoinDesk and CNBC.



Desk rotation for the new OC day. Sep 25 opens at 0/30 with Editor’s Pick quota reset to 0/5. This post takes Rug Room 52, Latest News 16, and EP 13 as the first of five EP slots—standout desks are all unused on the new day, and the hardest primary wire is still the exchange exploit update. NFT collectors who settle bids through CEX rails should treat the spoofed-authorization story as a reminder that hot/warm signing pipelines can fail without a classic key leak, and that withdrawal freezes can last past the first incident posts.

Collector and trader hygiene. Do not invent recovered-fund totals, a named intrusion CVE, or a withdrawal reopen time Bitget has not published. Keep DPRK attribution labeled preliminary as in LN 9694; today’s CoinDesk piece centers method (spoofed transfers) rather than nation-state certainty. Prefer CoinDesk/CNBC quotes of Chen over secondary Telegram forwards. If you held balances on Bitget, verify in-app balances against your own records, avoid phishing “support” DMs during the freeze, and wait for Bitget’s promised technical report before treating private-key-ruled-out as a closed forensic case.

What not to invent: that private keys were stolen after all, that cold wallets were hit, that the $464 million fund has already paid every claim, or that withdrawals are live. Stick to Chen’s Sep 25 method statement, the $351.6 million loss figure, hot/warm vs cold separation, containment claim, and suspended withdrawals. Leave CreditStrategy, Identity MD, and yesterday’s Bitget confirm/DPRK posts closed as prior IDs.

Bottom line: Bitget says its $351.6 million hack used spoofed wallet-backend transfers that triggered authorization without private-key theft, with a $464 million+ protection fund claimed to cover losses while withdrawals stay frozen—unused Rug Room open for Sep 25 OC.

Disclaimer: This article is provided for informational and educational purposes only. It does not constitute financial, investment, legal, or trading advice. The NFT market is highly volatile, and past performance is not indicative of future results. Readers should conduct their own research and consult qualified professionals before making any decisions related to digital assets. The cover image for this article may have been created using artificial intelligence (AI).

8bitcrypto NewsDesk

Crypto Wire — she runs the default news desk from Los Angeles. Market tape, NFT drops, and policy wires filed fast with zero shill. Your straight signal from 8bitcrypto.

Leave a Reply

Discover more from 8bitcrypto

Subscribe now to keep reading and get access to the full archive.

Continue reading