Bitget revealed that a $351.6 million breach was not a private-key theft. According to CEO Gracy Chen, attackers broke into a critical wallet backend, fed forged transfer data into the exchange’s own approval process, and walked funds out of hot and warm wallets as if the payouts were routine.
Cold storage, she said, was untouched.
The incident was first flagged at 18:31 UTC on September 24, 2026.
Withdrawals remain paused while deposits and trading continue, and Chen said a user protection fund of more than $464 million is large enough to absorb the loss.
That distinction actually matters.
A stolen private key is the crypto equivalent of a copied vault combination: the thief can keep signing new transfers until every exposed…







