Bitget's $352 million hack happened via spoofed transfers, not private keys, CEO Gray Chen says

Bitget CEO Gray Chen confirmed that a recent $352 million hack was caused by a backend system compromise rather than a private key theft. The attacker spoofed transaction data to bypass authorization, though the company has since contained the breach.
Why it matters
The distinction between private key theft and system spoofing highlights evolving security vulnerabilities in centralized crypto exchange infrastructure.
“The attacker compromised a critical backend system within our wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out,” Chen wrote on X . “Private key compromise has been ruled out.”
That distinction matters and points to a less alarming attack vector. Private key hacks have driven some of the industry's biggest losses.
Every crypto wallet has two keys. The public key is like a bank account number and can be shared so someone can send funds in. The private key is the secret string that proves ownership and authorizes spending, closer to a password and a vault combination in one. If those private keys are copied, an attacker can keep signing new transfers and draining funds.
Chen said that is not what happened here.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in