Bitget CEO Says Spoofed Backend Data, Not Stolen Keys, Triggered the $351.6 Million Hack
Bitget CEO Gracy Chen said attackers compromised a backend system within the exchange’s wallet infrastructure and spoofed transaction data to trigger its own authorization process Chen said p
A
AnonymousCryptoCompass newsroom
September 27, 2026
3 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for markets coverage.
Bitget CEO Gracy Chen said attackers compromised a backend system within the exchange’s wallet infrastructure and spoofed transaction data to trigger its own authorization process
Chen said private key compromise has been ruled out and that loss containment is confirmed, with no further unauthorized transfers possible
She said cold wallets remain fully secure and that multiple technical teams are working in parallel on remediation, with no firm timeline promised until one can be guaranteed
Bitget CEO Gracy Chen posted on her official X account the exchange’s first detailed account of how attackers moved roughly $351.6 million out of its hot wallet infrastructure a day earlier. “The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out,” Chen wrote, adding that “private key compromise has been ruled out.”
The distinction matters because a stolen private key and a spoofed authorization process point to very different failure modes. A private key compromise would mean the signing credentials themselves were exposed, a scenario that typically forces an exchange to rotate every key tied to the affected wallets. Chen’s account instead describes attackers manipulating the data an internal approval system trusted, tricking it into approving transfers it should have rejected, while the underlying keys stayed secure the entire time.
On the scope of the damage, Chen wrote that “loss containment is confirmed. No further unauthorized transfers are possible,” though she added that “the specific method of system intrusion remains under active investigation.” That phrasing draws a line between stopping the bleeding, which Bitget says it has done, and fully understanding how the attacker got in, which the company says is still being worked out.
Chen also moved to reassure users directly, writing “user funds are safe. Your account balances are accurate and your assets are protected,” and separately confirming that “cold wallets remain fully secure,” meaning the incident stayed confined to the hot and warm wallet layers used for day-to-day liquidity rather than the offline reserves holding the bulk of customer assets.
On next steps, Chen said “multiple technical teams are working in parallel on system remediation and security hardening,” while declining to commit to a specific restoration date: “we will announce a timeline as soon as one is confirmed. We will not commit to a window we cannot guarantee.” That approach mirrors the hourly-update commitment Bitget made in its original security notice, favoring frequent partial updates over a single delayed statement once every detail is confirmed.
Quant‘ın yerel tokeni QNT, son 24 saatte %75 yükselerek $180 seviyesine çıktı. Token son bir haftada ise yaklaşık %185 değer kazandı ve gün içinde kısa süreliğine $190 seviyesini de aştı. Ser
The federal appeals court for the 6th circuit ruled Friday in favor of Ohio and Tennessee against Kalshi. States can apply their sports betting laws to the platform’s contracts, a second loss
TLDR: Capital B CEO Alexandre Laizet says the U.S. government will not sell its Bitcoin reserve holdings. Capital B says it will keep buying Bitcoin as quickly and accretively as possible for