Bitget Says $351.6M Hack Hit Wallet Backend, Not Private Keys

Bybit
Blockonomics



All news is rigorously fact-checked and reviewed by leading blockchain experts and seasoned industry insiders.
  • Bitget lost $351.6M after hackers breached its wallet backend.
  • Private keys and cold wallets were not compromised.
  • A $464M+ protection fund will cover the loss. 

Bitget says attackers stole approximately $351.6 million after compromising part of its wallet infrastructure, but the first on-chain reconstruction shows the breach was more complex than a conventional hot-wallet key theft.

CEO Gracy Chen noted in X, that the attacker compromised a critical backend system, manipulated transaction data and caused Bitget’s authorization process to approve fraudulent transfers. She said a private-key compromise has been ruled out, while the exact route into the backend remains under investigation.

The exchange has temporarily suspended withdrawals. Deposits and trading remain available, while Bitget says its $464 million-plus User Protection Fund is sufficient to absorb the loss and keep customer balances intact.

Bitget says the attacker manipulated its wallet backend rather than stealing private keys.

Phemex

XRP was the largest identified asset affected, followed by ETH and several stablecoins.

On-chain activity shows some stolen assets were rapidly converted into ETH through decentralized trading infrastructure.

XRP Accounts for Nearly Half of the Reported Loss

The asset breakdown provides a clearer picture of the $351.6 million breach. On-chain tracking by Arkham cited by Lookonchain in X identified XRP as the largest single component, while ETH and stablecoins accounted for much of the remaining value.

  • XRP: 102.93 million XRP worth approximately $157.48 million
  • ETH: 31,890 ETH worth approximately $85.75 million
  • USDT: approximately $34.75 million
  • USDC: approximately $21.06 million
  • USDT0: approximately $19.67 million
  • XAUt: 3,000 tokens
  • BNB: 12,719 BNB
  • AVAX: 821,012 AVAX
  • TRX: 20.59 million TRX

The multi-chain distribution also helps explain why early estimates were substantially below Bitget’s eventual $351.6 million figure. Initial monitoring captured roughly $180 million to $190 million in suspicious transfers before the much larger XRP component was incorporated into later estimates.

Stolen Stablecoins Were Quickly Turned Into ETH

The attacker did not simply leave all of the transferred assets in their original form.

One newly created wallet used $19.67 million in USDT0 to buy 7,111 ETH on Arbitrum in about six minutes, according to on-chain activity reported after the breach. The trades passed through UniswapX and 1inch Fusion, with execution reportedly reaching roughly 5% above prevailing market prices.

Across Ethereum-compatible networks, stolen stablecoins and other assets were subsequently converted into tens of thousands of ETH. One reconstruction placed the resulting ETH position at roughly 67,982 ETH worth about $183 million.

The rapid conversions are relevant because issuer-controlled stablecoins can potentially be frozen, while native ETH does not have an issuer with equivalent freeze authority.

The XRP portion remained on a separate tracking path because it was not part of those EVM-based conversions.

Bitget Says Its Signing Keys Were Not Compromised

The technical investigation points in a different direction from a straightforward private-key theft.

Chen said attackers gained access to a critical backend component of Bitget’s wallet infrastructure, altered transaction data and triggered the exchange’s authorization process. The transactions were therefore signed by Bitget’s infrastructure even though the underlying instructions were fraudulent.

That makes the distinction between the signing layer and the systems feeding requests into it important.

Possession of a private key would allow an attacker to cryptographically authorize transactions directly. Bitget’s preliminary account instead indicates that its legitimate signing process received manipulated transaction information from a compromised internal system.

The exchange has not yet disclosed how the attacker entered that backend environment.

Bitget’s original security notice was more cautious, saying it would not speculate about the attack vector until its investigation was complete. The backend explanation should therefore still be treated as a preliminary finding from the CEO, rather than a finished forensic conclusion.

What Bitget Users Can and Cannot Do

For customers, the immediate operational impact is concentrated on withdrawals.

Deposits and trading remain operational, but withdrawals are temporarily suspended while Bitget reviews its wallet systems. The exchange has not provided a fixed reopening time.

Bitget says account balances remain accurate and that customer assets are protected. Its User Protection Fund held more than $464 million when the incident was disclosed, compared with the estimated $351.6 million affected by the breach.

Bitget Wallet, the company’s separate self-custodial wallet product, was not affected by the exchange infrastructure breach, according to the company.

For users with positions already open on the exchange, trading remains available. The restriction is on moving assets out of the centralized platform until withdrawals resume.

The Missing Piece Is How the Backend Was Breached

Bitget has identified and flagged addresses associated with the unauthorized transfers and says law enforcement and on-chain security firms are involved in the investigation.

Chen has also discussed preliminary indicators that could point toward North Korean attackers, including IP and VPN patterns. That attribution remains unconfirmed and should not yet be treated as an established finding.

The more consequential unanswered question is the initial entry point.

Bitget’s current explanation describes what happened after the attacker reached its wallet backend: transaction data was manipulated, the authorization system was triggered and assets left the exchange.

It does not yet explain how that internal system was compromised.

That distinction will matter when Bitget publishes its full incident report. Establishing whether the initial access came through compromised credentials, an application vulnerability, a third-party dependency or another route will determine whether the $351.6 million theft exposed a narrow wallet-system weakness or a broader failure in the exchange’s internal security controls.





Source link

Coinmama

Be the first to comment

Leave a Reply

Your email address will not be published.


*