AI Trading Guru
News

Bitget CEO Confirms $352M Hack Used Spoofed Transfers, Not Stolen Private Keys

Omkar Godbole 25.09.2026

Attack Method Explained

Chen stated that attackers compromised a critical backend system within Bitget’s digital wallet architecture. Using this access, they falsified transaction data and triggered the company’s internal authorization process, allowing funds to be moved to external accounts. She emphasized that private keys, essential for signing and validating financial operations, were not stolen or exposed during the incident.

Technical Distinction Matters

This clarification is important because private key theft has been the main cause of major financial losses in crypto history. To illustrate the difference, Chen compared it to traditional banking. Each cryptocurrency wallet has two types of keys: a public key, similar to a bank account number that can be shared to receive funds, and a private key, which acts like a secret password combined with a safe code, proving ownership and authorizing spending. If private keys had been copied, attackers could have continued signing new transfers and draining funds long-term. However, in Bitget’s case, the situation was different.

Analogy to Banking Fraud

Chen described the security breach as the digital equivalent of submitting fake withdrawal slips at a bank’s teller window. The safe keys did not leave the building. Instead, someone entered the office that prepares documents, created papers that appeared official, and sent them through the same approval window the bank uses daily. For the system processing approvals, the transaction appeared as a normal and legitimate payment.

Losses Contained, Withdrawals Suspended

Although the outflow of funds was a major issue, Chen confirmed that losses were contained. She stated that no further unauthorized transfers are possible, and the specific method of system intrusion remains under active investigation. A full technical report will be published once details are definitively confirmed.

User Protection Fund Covers Losses

Chen noted that Bitget’s User Protection Fund holds over $464 million, an amount that fully covers the losses from the hack. „User funds are safe,” she wrote. „Your account balances are correct, and assets are protected.”

Deposit and Trading Open, Withdrawals Frozen

Currently, deposits and trading remain open for users. However, withdrawals have been suspended. Bitget has frozen them as a preventive measure while awaiting the completion of the security review. Chen did not provide a precise timeline for resuming withdrawals. She explained that multiple technical teams are working in parallel to fix systems and strengthen security. The company will announce a timeline immediately once confirmed, refusing to commit to a timeframe it cannot guarantee.

Broader Crypto Market Context

Beyond Bitget news, the crypto market has recently been marked by other significant events. Authorities in New York have filed a lawsuit against Polymarket, alleging it operates an illegal betting business. Additionally, the U. S. Federal Reserve has advanced proposals to implement the GENIUS Act regarding stablecoins. Elsewhere, someone attempted to sell Ondo Finance following the death of founder Nathan Allman. A coalition formed by Bullish, Alpaca, and Apex Fintech has emerged to promote tokenized securities backed by issuers. The U. S. Commodity Futures Trading Commission (CFTC) has stated that U. S. commodity firms can invest in tokenized assets and use blockchain ledgers. Debates around tokenizing securities continue, highlighting a gap that no single entity can fill alone. Finally, Bitcoin’s price recently surpassed a key long-term moving average, an important technical indicator for traders.

Share:

More stories: