Spoofed Transfers Drain Bitget Wallets in $352M Hack
Crypto exchange Bitget suffered a massive breach worth $352 million on September 24, 2026. According to CEO Gracy Chen, the hackers did not steal any private keys but instead managed to break into a critical wallet backend and fed forged transfer data into the exchange's own approval process.
The attackers then walked funds out of hot and warm wallets as if they were routine payouts, leaving cold storage untouched. The incident was first flagged at 18:31 UTC on September 24, 2026.
Chen emphasized that stolen private keys are the crypto equivalent of copied vault combinations, allowing thieves to keep signing new transfers until every exposed address is emptied and rebuilt.
The Bitget CEO ruled out this scenario, stating that the machinery that tells a signer what to approve failed instead. This allowed the attackers to invent a transfer that looked internally valid without needing to leave the building.
Industry reaction has been blunt, with on-chain researcher Specter tying some of the stolen XRP flow to an earlier cluster associated with the July AFX theft, which had already been linked to a North Korea-aligned unit. Chen separately stated that investigators saw IP and VPN patterns matching a Democratic People's Republic of Korea group and called this attribution 'very likely', while stressing it is not yet confirmed.
Bitget is one of the more active centralized exchanges in the market, with multi-billion-dollar daily turnover, a large derivatives book, and a prominent copy-trading franchise. Platforms of this size sit at the junction of retail savings, market-maker inventory, and cross-chain operational wallets.