CONNECT WITH US
Web3 & Blockchain

Web3 & Blockchain

Bitget's $352 million hack happened via spoofed transfers, not private keys, CEO Gray Chen says

CoinDesk logo

Published on

Add as a preferred source on Google
Bitget's $352 million hack happened via spoofed transfers, not private keys, CEO Gray Chen says

Crypto exchange Bitget lost $351.6 million in an overnight hack. CEO Gracy Chen said attackers faked transfer requests to drain funds but did not steal “private keys.”

“The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out,” Chen wrote on X. “Private key compromise has been ruled out.”

That distinction matters and points to a less alarming attack vector. Private key hacks have driven some of the industry's biggest losses.

Every crypto wallet has two keys. The public key is like a bank account number and can be shared so someone can send funds in. The private key is the secret string that proves ownership and authorizes spending, closer to a password and a vault combination in one. If those private keys are copied, an attacker can keep signing new transfers and draining funds.

She described the breach as the digital version of slipping forged withdrawal slips through a bank’s own teller window. The vault keys never left the building. Someone got into the office that prepares the slips, created paperwork that looked official, and sent it through the same approval window the bank uses every day. To the system doing the approving, it looked like a normal payout.

“Loss containment is confirmed. No further unauthorized transfers are possible. The specific method of system intrusion remains under active investigation. A full technical report will follow once confirmed,” she said.

The breach surfaced when Bitget’s systems flagged unauthorized transfers from some exchange hot wallets at 18:31 UTC on Sept.


Source link

Disclaimer

We strive to uphold the highest ethical standards in all of our reporting and coverage. We TheMorningPulse.fyi want to be transparent with our readers about any potential conflicts of interest that may arise in our work. It's possible that some of the investors we feature may have connections to other businesses, including competitors or companies we write about. However, we want to assure our readers that this will not have any impact on the integrity or impartiality of our reporting. We are committed to delivering accurate, unbiased news and information to our audience, and we will continue to uphold our ethics and principles in all of our work. Thank you for your trust and support.