$352M Gone: Bitget's Hack Had Nothing to Do With Private Keys

The attackers never touched a private key, and that's the most terrifying part.

Bitget CEO Gray Chen confirmed on X that the exchange lost $351.6 million after hackers compromised the wallet backend and spoofed transaction data, not by stealing keys the way most people assume crypto hacks work. The private keys were fine. The money was gone anyway.

How They Did It

Spoofed transfers mean the attackers manipulated transaction data at the infrastructure level, making fraudulent outflows look like legitimate ones. The backend processed them without raising flags. By the time anyone noticed something was wrong, $351.6 million had already moved.

This is not a story about a weak password or a leaked seed phrase. This is a story about attackers finding a layer most exchanges assume is safe because it sits below the keys themselves. That assumption just cost Bitget more than a third of a billion dollars.

Why This Changes Everything

The entire security conversation in crypto has been built around one idea: control your keys, control your coins. Hardware wallets, seed phrase storage, multi-sig setups, all of it assumes that if the keys are safe, the funds are safe.

Bitget's hack breaks that assumption wide open.

If a backend can be compromised and transaction data can be spoofed at that level, then the attack surface for centralized exchanges is dramatically larger than most users, and apparently most exchanges, have been accounting for. You can have perfect key management and still lose everything if the system processing your transactions has been manipulated.

What Bitget Is Saying

Chen has not disclosed whether user funds are at risk or whether the exchange has the reserves to cover the loss. That silence is notable. A $351.6 million hole is not a rounding error, even for a major exchange. The next 48 to 72 hours of communication from Bitget will tell traders a lot about the actual damage and whether withdrawals could face any friction.

What You Should Watch Right Now

First, monitor Bitget's on-chain reserve data across any third-party transparency dashboards. If reserves start moving in ways that don't match stated figures, that is a signal.

Second, treat this as a reminder that exchange risk is real and concentrated. Any meaningful holdings sitting on a centralized platform are exposed to risks that have nothing to do with your personal security habits.

Third, watch for contagion sentiment across mid-tier exchanges. Hacks of this size historically trigger brief withdrawal spikes across multiple platforms as users move to cold storage.

The hack that didn't need your keys just became the most important security story in crypto right now.