The exchange's security notice declined to name an attack vector, and hours later its chief executive said the attacker spoofed transaction data through a compromised backend system, ruling out private key theft. Withdrawals remain suspended, and the loss is close to 76 percent of the User Protection Fund Bitget says covers it.
Bitget has told users that the roughly $351.6 million taken from its hot and warm wallets on Thursday did not leave through a stolen key. The attacker "compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out," chief executive Gracy Chen said in a statement reported by CoinDesk, adding that "private key compromise has been ruled out."
The exchange's systems flagged the transfers at 18:31 UTC on Thursday. Its security notice went up just over three hours later, put the estimated funds affected at approximately $351.6 million, said the hot and warm wallet layers were involved and that cold wallets "remain fully secure," and then declined to go any further: "We will not speculate on the attack vector until the investigation is complete." By that point the outflows were already public. Nineteen minutes before the notice appeared, The Block reported more than $170 million leaving Bitget wallets for an unidentified address, using Arkham Intelligence data, and noted that the receiving address had already begun swapping the assets on chain.
What Chen described is a different failure from the one most exchange reassurances are written to answer. A stolen key lets an attacker sign transfers the exchange never approved. Spoofed transaction data that clears an internal authorization path produces transfers the exchange approved itself, believing them genuine. Chen's own comparison was to forged withdrawal slips pushed through a bank's ordinary counter rather than a break-in at the vault. On that account the statement that cold wallets are secure is both accurate and beside the point, because the keys were never the target. The defect sat in the system that decides which instructions the signing infrastructure should honor.
Losses of that shape have been among the year's stranger ones. A hijacked LayerZero delegate on Base and BNB Chain turned an approveAndCall into a mint function and printed $49 billion of unbacked SAND before The Sandbox froze its bridges, though actual extraction came to about $675,000. BNB Chain's Pasteur fork in August closed a loophole that let a bridge accept the same validator signature twice. In each case the contracts and the keys behaved exactly as written, and what failed was the check on whether an instruction was real.
On-chain tracking by the security firm SlowMist, reported by Blockhead, spreads the loss across nine tokens moved in 19 transfers. The largest component is about 102.9 million XRP, worth roughly $157 million, followed by 31,890 ether at about $86 million, with USDT, USDC, tokenized gold, BNB, AVAX and TRX making up the rest. Those dollar figures are struck at the time of the transfers rather than against live prices.
Bitget says the whole amount falls inside its User Protection Fund, which it puts at more than $464 million. Set against the $351.6 million estimate, that leaves roughly $112 million of headroom, which is about a quarter of the fund, and makes the loss itself close to 76 percent of it. Both inputs are Bitget's own. The fund has been reported as bitcoin-denominated, and if that is still its composition then the $464 million is not a fixed sum but a figure that moves with bitcoin's price, and the headroom narrows as the price falls. Bitget has not published the fund's current holdings alongside this incident.
Withdrawals remain suspended while deposits and trading stay open, which is the part users can actually observe. Chen said loss containment is confirmed and that no further unauthorized transfers are possible, and gave no restart date: "We will not commit to a timeline we cannot deliver," she said in an update on Friday. She also said that some parties had already frozen the attacker's wallet addresses, without naming them or putting a figure on what was frozen, and those freezes have not been independently confirmed on chain. Bitget's notice says law enforcement and on-chain security firms have been notified and engaged, and names none of them.
Attribution is being handled more loosely than the rest. On a livestream Chen said some of the IP addresses used in the attack closely matched VPN patterns associated with a North Korea-linked group, while stressing that the attackers' identity was not confirmed, and said Bitget does not believe the breach was an inside job. That is a lead rather than a finding, and the base rate behind it is high: in TRM Labs' tally at the end of April, North Korean operations accounted for 76 percent of 2026's crypto hack losses by value from just two attacks.
BGB, Bitget's exchange token, was down 3.3 percent over 24 hours at $1.97 as of 07:22 UTC on Friday, according to CoinGecko. Holders cannot move it off the exchange while withdrawals are off, which limits how much that price says about anything.
Bitget's notice promised a full incident report, including root cause analysis and corrective actions, within 24 hours of publication, which puts it due late on Friday. Chen has described the attack vector in public statements ahead of that report, while the notice itself still declines to name one.