New Details on Bitget’s $352 Million Attack: Fake Transactions Passed Approval
Bitget CEO Gracy Chen said fake transaction data triggered the exchange’s own approval process in the $351.6 million attack, enabling funds to be transferred out.
It was previously reported that private keys were not stolen in the Bitget attack. Chen’s new details reveal how the attackers nevertheless carried out the transfers: A critical backend system in the wallet infrastructure was compromised, and the fake transaction data generated through it activated the exchange’s authorization process.
According to this account, instead of obtaining the wallets’ private keys and transferring funds directly, the attackers used the exchange’s own transaction approval mechanism. However, it is still unclear exactly how the system was initially breached. Chen said the investigation is ongoing and that a detailed technical report will be published once the findings have been verified.
Which Wallets Were Affected by the Attack?
The exchange detected the unauthorized transfers on September 24 at 21:31 Turkey time. According to Chen, the attack affected internet-connected hot wallets as well as the intermediate wallet layer that facilitates the flow of funds between hot wallets and offline storage. The company said its cold wallets were safe.
Chen reported that unauthorized outflows had been stopped and further unauthorized transfers prevented. Bitget said its user protection fund, which it reported held more than $464 million in assets, would cover the entire loss and that user balances were protected.
Deposits and trading remain available, while withdrawals have been suspended pending a security review. The exchange has not yet provided a timeline for when withdrawals will resume, saying its technical teams are continuing their work to repair and strengthen the system’s security.