# Bitget Says $352 Million Hack Used Spoofed Transfers, Not Private Keys

By Simon Yoon

Canonical URL: https://www.tokenpost.com/news/technology/23998
Published: 2026-09-25T05:13:16.000Z
Updated: 2026-09-25T05:13:16.000Z

Bitget CEO Gracy Chen said attackers moved approximately $351.6 million through spoofed transfers after compromising a backend system in the exchange’s wallet infrastructure, rather than stealing private keys.

“Private key compromise has been ruled out,” Chen said.

Bitget detected the unauthorized transfers at 2:31 p.m. ET (18:31 UTC) on Sept. 24. The breach affected portions of its hot- and warm-wallet layers, while the exchange said its cold wallets remained secure.

Bitget suspended withdrawals during its security review but kept deposits and trading operational. The exchange also said its User Protection Fund held more than $464 million, exceeding the estimated loss.

Chen said the incident had been contained and that no further unauthorized transfers were possible. She said the attacker compromised a critical backend system, altered transaction data and triggered Bitget’s authorization process.

Hot wallets connect to the internet for routine operations, while warm wallets provide an intermediate layer before offline cold storage. The specific method used to enter the backend system remains under investigation, and Bitget plans to issue a full technical report once the details are confirmed.
