Bitget revealed that a $351.6 million breach was not a private-key theft. According to CEO Gracy Chen, attackers broke into a critical wallet backend, fed forged transfer data into the exchange’s own approval process, and walked funds out of hot and warm wallets as if the payouts were routine.
Crypto Exchange Hack : Bitget’s $352 Million Breach Came From Spoofed Transfers, Not Stolen Keys
Bitget revealed that a $351.6 million breach was not a private-key theft. According to CEO Gracy Chen, attackers broke into a critical wallet backend, fed forged transfer data into the exchange’s own approval process, and walked funds…
Crowdfund Insider
Publisher
Sep 25, 2026 at 7:41 PM UTC · 4 min de leitura

Cold storage, she said, was untouched.
The incident was first flagged at 18:31 UTC on September 24, 2026.
Withdrawals remain paused while deposits and trading continue, and Chen said a user protection fund of more than $464 million is large enough to absorb the loss.
That distinction actually matters.
A stolen private key is the crypto equivalent of a copied vault combination: the thief can keep signing new transfers until every exposed address is emptied and rebuilt.
Chen has ruled that scenario out. What failed instead was the machinery that tells a signer what to approve.
Once a backend system can invent a transfer that looks internally valid, the keys never have to leave the building.
Media outlets in general compared the method to sliding forged withdrawal slips through a bank’s own teller window.
To the approval layer, the paperwork looked official. The funds still left.
Spoofed transactions in crypto are not one trick.
Article Intelligence
Topics
Related Coverage
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
