Binance Square
#bitgetbreachforgedrequestsnotstolenkeys

bitgetbreachforgedrequestsnotstolenkeys

81,171 views
992 Discussing
Coinstar
·
--
🚨 The largest crypto hack of 2026: Bitget loses $351.6 million Hackers stole approximately $351.6 million in assets, making this incident the largest crypto exploit of the entire year. The attackers did not steal private keys. Instead, they compromised the hot wallet backend infrastructure, falsified internal transaction histories, and fraudulently initiated withdrawals. The primary targets were AVAX, BNB, ETH, and stablecoins (USDC, USDT). The hackers immediately began converting the funds to Ethereum via bridges to complicate tracking. Analysts at Arkham Intelligence were the first to spot the massive on-chain anomaly. Bitget management has temporarily suspended withdrawals to conduct security checks. Cold wallets, which hold the vast majority of assets, remain unaffected. Trading and deposits continue to function normally. Exchange CEO Gracy Chen officially guaranteed that 100% of user losses will be fully covered by the User Protection Fund. The fund's current reserves exceed $464 million, allowing the exchange to close the financial gap independently. Cybersecurity experts suspect that North Korean-linked hacker groups orchestrated the exploit. #BitgetBreachForgedRequestsNotStolenKeys #ETH #BNB $ETH $AVAX $BNB {future}(BNBUSDT) {future}(AVAXUSDT) {future}(ETHUSDT)
🚨 The largest crypto hack of 2026: Bitget loses $351.6 million

Hackers stole approximately $351.6 million in assets, making this incident the largest crypto exploit of the entire year.

The attackers did not steal private keys. Instead, they compromised the hot wallet backend infrastructure, falsified internal transaction histories, and fraudulently initiated withdrawals.

The primary targets were AVAX, BNB, ETH, and stablecoins (USDC, USDT). The hackers immediately began converting the funds to Ethereum via bridges to complicate tracking. Analysts at Arkham Intelligence were the first to spot the massive on-chain anomaly.

Bitget management has temporarily suspended withdrawals to conduct security checks. Cold wallets, which hold the vast majority of assets, remain unaffected. Trading and deposits continue to function normally.

Exchange CEO Gracy Chen officially guaranteed that 100% of user losses will be fully covered by the User Protection Fund. The fund's current reserves exceed $464 million, allowing the exchange to close the financial gap independently.

Cybersecurity experts suspect that North Korean-linked hacker groups orchestrated the exploit.

#BitgetBreachForgedRequestsNotStolenKeys #ETH #BNB $ETH $AVAX $BNB
206 Atlas:
Bitget’s cold wallet defense failed if hot wallets were compromised. The market pricing BGB down while altcoins rise confirms this is an isolated failure, not systemic risk.LSK's 600% pump is likely a liquidity trap for retail chasing the squeeze. Chasing low-cap NOM here ignores the extreme volatility risk of these setups.A $464M fund cannot fully cover a $351.6M loss after operational costs and panic liquidity drains. This guarantee is likely insufficient.
#bitgetbreachforgedrequestsnotstolenkeys 🚨 Security Update: Bitget Breach Involves Forged Requests, Not Stolen Keys The Breakdown: The crypto community has been closely monitoring recent security events following an incident involving Bitget, where approximately $351.6 million was affected through unauthorized transfers. However, leadership has confirmed that private keys were not stolen. Instead, attackers compromised a backend wallet system and spoofed transaction data to push fake requests through normal authorization pipelines. Cold storage remains entirely secure, and the exchange's protection fund is positioned to cover the losses. What This Means for the Market: Incidents like this shift industry focus heavily toward backend system hardening and infrastructure security. While withdrawals remain temporarily paused for safety reviews, trading and deposits continue to operate normally, prompting traders to keep a sharp eye on risk management and exchange liquidity flows. Highlighted Tradeable Coins to Watch: $BTC (Bitcoin): The ultimate macro market benchmark; watching how overall liquidity responds and holds key support levels during exchange security updates. $ETH (Ethereum): Vital smart-contract asset heavily monitored for on-chain volume shifts and market-wide sentiment changes. $BNB (Binance Coin): Key ecosystem token tracking exchange sector dynamics, trading volume trends, and broader platform utility. How are you navigating your portfolio security and current market conditions? Let's discuss in the comments below! 👇 {spot}(BTCUSDT) {spot}(ETHUSDT) {spot}(BNBUSDT) #Bitget #CryptoSecurity #BlockchainSecurity #CryptoNews
#bitgetbreachforgedrequestsnotstolenkeys
🚨 Security Update: Bitget Breach Involves Forged Requests, Not Stolen Keys
The Breakdown: The crypto community has been closely monitoring recent security events following an incident involving Bitget, where approximately $351.6 million was affected through unauthorized transfers. However, leadership has confirmed that private keys were not stolen. Instead, attackers compromised a backend wallet system and spoofed transaction data to push fake requests through normal authorization pipelines. Cold storage remains entirely secure, and the exchange's protection fund is positioned to cover the losses.
What This Means for the Market: Incidents like this shift industry focus heavily toward backend system hardening and infrastructure security. While withdrawals remain temporarily paused for safety reviews, trading and deposits continue to operate normally, prompting traders to keep a sharp eye on risk management and exchange liquidity flows.
Highlighted Tradeable Coins to Watch:
$BTC (Bitcoin): The ultimate macro market benchmark; watching how overall liquidity responds and holds key support levels during exchange security updates.
$ETH (Ethereum): Vital smart-contract asset heavily monitored for on-chain volume shifts and market-wide sentiment changes.
$BNB (Binance Coin): Key ecosystem token tracking exchange sector dynamics, trading volume trends, and broader platform utility.
How are you navigating your portfolio security and current market conditions? Let's discuss in the comments below! 👇
#Bitget #CryptoSecurity #BlockchainSecurity #CryptoNews
206 Atlas:
Spoofing backend requests bypasses key security, exposing critical infrastructure flaws that cold storage cannot mitigate.
·
--
Bearish
🚨 BITGET $352M HACK EXPLAINED: Forged Requests, NOT Stolen Keys! Everyone is panicking about private keys. But Bitget CEO Gracy Chen just confirmed something scarier. What Actually Happened: ❌ Private keys were NOT stolen (cold, hot & warm wallets safe) ❌ User withdrawal requests were NOT forged ✅ Hackers breached a CRITICAL backend system ✅ They spoofed transaction data ✅ They triggered Bitget's OWN authorization process to move $351.6M Think of it like this: "They didn't crack the vault, they forged the paperwork." The vault keys never left the building, someone just created fake official slips. Current Status: Detected at 18:31 UTC, Sep 24 Cold wallets secure $464M User Protection Fund will cover the loss CEO links attack to North Korea via IP clues What do you think - Should CEXs make their backend open-source? $AVAX $TRX $XRP {future}(XRPUSDT) {future}(TRXUSDT) {future}(AVAXUSDT) #Bitget #BitgetHack #CryptoSecurity #BreakingNews #BinanceSquare #bitgetbreachforgedrequestsnotstolenkeys
🚨 BITGET $352M HACK EXPLAINED: Forged Requests, NOT Stolen Keys!
Everyone is panicking about private keys. But Bitget CEO Gracy Chen just confirmed something scarier.
What Actually Happened:
❌ Private keys were NOT stolen (cold, hot & warm wallets safe)
❌ User withdrawal requests were NOT forged
✅ Hackers breached a CRITICAL backend system
✅ They spoofed transaction data
✅ They triggered Bitget's OWN authorization process to move $351.6M
Think of it like this: "They didn't crack the vault, they forged the paperwork." The vault keys never left the building, someone just created fake official slips.
Current Status:
Detected at 18:31 UTC, Sep 24
Cold wallets secure
$464M User Protection Fund will cover the loss
CEO links attack to North Korea via IP clues
What do you think - Should CEXs make their backend open-source?
$AVAX $TRX $XRP
#Bitget #BitgetHack #CryptoSecurity #BreakingNews #BinanceSquare #bitgetbreachforgedrequestsnotstolenkeys
·
--
Bullish
#bitgetbreachforgedrequestsnotstolenkeys Bitget’s $352M drama: Forged requests, not stolen keys! Devs, are you sweating yet? 🤦‍♂️🛡️ So, Bitget spilled the tea on their recent hack! The attackers didn't steal their private keys; they simply outsmarted the backend system by forging transaction requests! It’s like a thief walking into a bank with a perfectly forged signature from the manager, and the vault just opened itself! 🏦🔑 This is a massive wake-up call for all blockchain devs and major exchanges, including Binance, to double-check their backend security infrastructure before another exploiter gets creative! 💻💥 What should smart traders do? 🛠️ 📌 Keep your guard up: Don't put all your funds into a single exchange. 🛡️ Diversify your assets: Spread your portfolio into trusted tokens to minimize potential platform risks. Disclaimer: This is personal opinion, not financial advice. 👇 Click and trade below to support me: 💰 $BNB {future}(BNBUSDT) | 💰 $BTC {future}(BTCUSDT) | 💰 $ETH {future}(ETHUSDT) 📌 Referral Code: VINHTOCDO 🔗 Join Binance: [https://www.binance.com/register?ref=VINHTOCDO](https://www.binance.com/register?ref=VINHTOCDO) #BitgetBreach #CryptoSecurity #BackendHacks #VINHTOCDO #TradingSafety #CryptoNews
#bitgetbreachforgedrequestsnotstolenkeys
Bitget’s $352M drama: Forged requests, not stolen keys! Devs, are you sweating yet? 🤦‍♂️🛡️
So, Bitget spilled the tea on their recent hack! The attackers didn't steal their private keys; they simply outsmarted the backend system by forging transaction requests! It’s like a thief walking into a bank with a perfectly forged signature from the manager, and the vault just opened itself! 🏦🔑
This is a massive wake-up call for all blockchain devs and major exchanges, including Binance, to double-check their backend security infrastructure before another exploiter gets creative! 💻💥
What should smart traders do? 🛠️
📌 Keep your guard up: Don't put all your funds into a single exchange.
🛡️ Diversify your assets: Spread your portfolio into trusted tokens to minimize potential platform risks.
Disclaimer: This is personal opinion, not financial advice.
👇 Click and trade below to support me:
💰 $BNB
| 💰 $BTC
| 💰 $ETH
📌 Referral Code: VINHTOCDO
🔗 Join Binance: https://www.binance.com/register?ref=VINHTOCDO

#BitgetBreach #CryptoSecurity #BackendHacks #VINHTOCDO #TradingSafety #CryptoNews
·
--
Bullish
#bitgetbreachforgedrequestsnotstolenkeys BITGET BREACH: FORGED TRANSFER REQUESTS, NOT STOLEN PRIVATE KEYS Bitget has confirmed a major security incident involving approximately $351.6M in affected funds. But there’s a critical detail: The attackers reportedly did NOT steal Bitget’s private keys. Instead, Bitget CEO Gracy Chen said attackers breached a backend wallet-service system and used that access to forge transfer information and invoke the authorization/signing process. KEY FACTS • Approximately $351.6M in funds were affected • The incident was detected at 18:31 UTC on September 24 • Portions of Bitget’s hot and warm wallet infrastructure were affected • Bitget says cold wallets remained secure • Withdrawals were temporarily suspended during the security review • Deposits and trading remained operational • Bitget says its User Protection Fund holds more than $464M and covers the reported loss WHY THIS MATTERS This incident highlights an important exchange-security risk: protecting private keys alone is not enough. Backend systems, transaction-generation logic, authorization workflows and signing infrastructure can also become critical attack surfaces. Bitget says investigators are still determining exactly how the backend system was compromised, with a full incident report expected. For traders, the key takeaway is simple: Exchange security is an entire system — not just a private-key problem. This remains a developing incident, so additional details may change as the investigation progresses. $QI $PHA $ARK {future}(ARKUSDT) {future}(PHAUSDT) {spot}(QIUSDT)
#bitgetbreachforgedrequestsnotstolenkeys
BITGET BREACH: FORGED TRANSFER REQUESTS, NOT STOLEN PRIVATE KEYS
Bitget has confirmed a major security incident involving approximately $351.6M in affected funds.
But there’s a critical detail:
The attackers reportedly did NOT steal Bitget’s private keys.
Instead, Bitget CEO Gracy Chen said attackers breached a backend wallet-service system and used that access to forge transfer information and invoke the authorization/signing process.
KEY FACTS
• Approximately $351.6M in funds were affected
• The incident was detected at 18:31 UTC on September 24
• Portions of Bitget’s hot and warm wallet infrastructure were affected
• Bitget says cold wallets remained secure
• Withdrawals were temporarily suspended during the security review
• Deposits and trading remained operational
• Bitget says its User Protection Fund holds more than $464M and covers the reported loss
WHY THIS MATTERS
This incident highlights an important exchange-security risk: protecting private keys alone is not enough.
Backend systems, transaction-generation logic, authorization workflows and signing infrastructure can also become critical attack surfaces.
Bitget says investigators are still determining exactly how the backend system was compromised, with a full incident report expected.
For traders, the key takeaway is simple:
Exchange security is an entire system — not just a private-key problem.
This remains a developing incident, so additional details may change as the investigation progresses.
$QI $PHA $ARK
206 Atlas:
Forged signatures bypassing hot wallet controls is a systemic failure, not just a key theft. This exposes the fragility of centralized signing infrastructures.
You think forged requests mean no real risk That’s comforting but ignores how exchanges get pressured If they’re forging requests the system is broken not the keys Traders don’t care why the exploit happened only that it worked I’m watching how fast they patch and respond Not the narrative around stolen keys or not If they release the full forensic report and it shows zero system flaws Then I’ll admit I overreacted You think it’s safe #BitgetBreachForgedRequestsNotStolenKeys #CryptoNews
You think forged requests mean no real risk
That’s comforting but ignores how exchanges get pressured

If they’re forging requests the system is broken not the keys
Traders don’t care why the exploit happened only that it worked

I’m watching how fast they patch and respond
Not the narrative around stolen keys or not

If they release the full forensic report and it shows zero system flaws
Then I’ll admit I overreacted

You think it’s safe

#BitgetBreachForgedRequestsNotStolenKeys #CryptoNews
🚨 BITGET BREACH: FORGED REQUESTS — NOT STOLEN KEYS A major security incident involving Bitget has put crypto exchange security back in the spotlight. ⚠️ 💰 Reported impact: ~$351.6M 🔐 Private keys: Bitget says they were not stolen ⚙️ Attack method: Manipulated/forged transaction requests 🛡️ Response: Security investigation and protective measures 📌 Why it matters: Crypto security isn't only about protecting private keys. If an attacker can manipulate the systems that create or authorize transactions, massive losses can still happen. 🔥 The big question: Are centralized exchanges secure enough when their backend authorization systems are targeted? #Binance #CryptoInvesting $BNB #BitgetBreachForgedRequestsNotStolenKeys
🚨 BITGET BREACH: FORGED REQUESTS — NOT STOLEN KEYS

A major security incident involving Bitget has put crypto exchange security back in the spotlight. ⚠️

💰 Reported impact: ~$351.6M
🔐 Private keys: Bitget says they were not stolen
⚙️ Attack method: Manipulated/forged transaction requests
🛡️ Response: Security investigation and protective measures

📌 Why it matters:
Crypto security isn't only about protecting private keys. If an attacker can manipulate the systems that create or authorize transactions, massive losses can still happen.

🔥 The big question:
Are centralized exchanges secure enough when their backend authorization systems are targeted?

#Binance #CryptoInvesting $BNB
#BitgetBreachForgedRequestsNotStolenKeys
#BitgetBreachForgedRequestsNotStolenKeys 🚨 Bitget Breach Update: Forged Requests, Not Stolen Keys! ​Crypto exchange Bitget recently suffered a massive $351.6 million security breach. However, CEO Gracy Chen confirmed that private keys were never stolen. ​Instead, hackers infiltrated a backend wallet system, spoofing transaction data to push fake withdrawal requests through normal authorization channels. Think of it like slipping forged paperwork right through a teller window. ​Cold storage remains entirely safe, and Bitget’s $464 million user protection fund completely covers the loss. While withdrawals are temporarily paused for security checks, trading and deposits continue normally. 🛡️📉 ​What are your thoughts on this backend attack vector? #QNTRises39% #CFTCUpdatesGuidanceOnTokenizedAssets #NYAndPolymarketSueEachOther #Nadeemgujjar143 @Helen_Alek @Square-Creator-f3ffb6967ae3 @qpl5557 $BTC {spot}(BTCUSDT) $BNB {spot}(BNBUSDT) $ADA {spot}(ADAUSDT)
#BitgetBreachForgedRequestsNotStolenKeys
🚨 Bitget Breach Update: Forged Requests, Not Stolen Keys!
​Crypto exchange Bitget recently suffered a massive $351.6 million security breach. However, CEO Gracy Chen confirmed that private keys were never stolen.
​Instead, hackers infiltrated a backend wallet system, spoofing transaction data to push fake withdrawal requests through normal authorization channels. Think of it like slipping forged paperwork right through a teller window.
​Cold storage remains entirely safe, and Bitget’s $464 million user protection fund completely covers the loss. While withdrawals are temporarily paused for security checks, trading and deposits continue normally. 🛡️📉
​What are your thoughts on this backend attack vector?
#QNTRises39%
#CFTCUpdatesGuidanceOnTokenizedAssets
#NYAndPolymarketSueEachOther
#Nadeemgujjar143
@Hani Era @aasho @HK七匹狼
$BTC
$BNB
$ADA
#BitgetBreachForgedRequestsNotStolenKeys EXCLUSIVE: THE BITGET $351.6M HACK MAY HAVE LEFT A BIGGER CLUE Everyone is talking about the possible North Korea connection. But the more interesting clue may be hiding on-chain. 👀 🔎 What investigators are seeing: • Bitget says ~$351.6M was affected across its wallet infrastructure • The attacker reportedly compromised a backend wallet system, spoofed transaction data and triggered the normal authorization process • Private keys were NOT compromised, according to Bitget • Around 102.97M XRP — roughly $157M — was among the largest stolen portions • On-chain analyst Specter says the stolen XRP can be traced to funds connected to the $24M AFX exploit from July • That AFX incident has been associated with the TraderTraitor/Lazarus ecosystem And there’s another clue: Bitget CEO Gracy Chen says some attacker IP/VPN patterns resemble infrastructure previously associated with a North Korea-linked group. ⚠️ But this is NOT final attribution yet. The real question now is: Did the same North Korea-linked operation move from the AFX exploit to Bitget? If the XRP trail + infrastructure evidence is independently confirmed, this could turn the Bitget incident from a massive exchange hack into another major Lazarus-linked operation. 💰 Bitget says its $464M+ User Protection Fund can cover the affected amount, while withdrawals remain suspended during the security review. 👀 Watch the XRP wallets. The blockchain may reveal who is behind the attack before the official investigation does. #Bitget #XRP #CryptoHack #LazarusGroup #NorthKorea #CryptoSecurity #CryptoNews
#BitgetBreachForgedRequestsNotStolenKeys
EXCLUSIVE: THE BITGET $351.6M HACK MAY HAVE LEFT A BIGGER CLUE
Everyone is talking about the possible North Korea connection.
But the more interesting clue may be hiding on-chain. 👀
🔎 What investigators are seeing:
• Bitget says ~$351.6M was affected across its wallet infrastructure
• The attacker reportedly compromised a backend wallet system, spoofed transaction data and triggered the normal authorization process
• Private keys were NOT compromised, according to Bitget
• Around 102.97M XRP — roughly $157M — was among the largest stolen portions
• On-chain analyst Specter says the stolen XRP can be traced to funds connected to the $24M AFX exploit from July
• That AFX incident has been associated with the TraderTraitor/Lazarus ecosystem
And there’s another clue:
Bitget CEO Gracy Chen says some attacker IP/VPN patterns resemble infrastructure previously associated with a North Korea-linked group.
⚠️ But this is NOT final attribution yet.
The real question now is:
Did the same North Korea-linked operation move from the AFX exploit to Bitget?
If the XRP trail + infrastructure evidence is independently confirmed, this could turn the Bitget incident from a massive exchange hack into another major Lazarus-linked operation.
💰 Bitget says its $464M+ User Protection Fund can cover the affected amount, while withdrawals remain suspended during the security review.
👀 Watch the XRP wallets.
The blockchain may reveal who is behind the attack before the official investigation does.
#Bitget #XRP #CryptoHack #LazarusGroup #NorthKorea #CryptoSecurity #CryptoNews
#bitgetbreachforgedrequestsnotstolenkeys 🚨 The Real Story Behind the Bitget Breach 🚨 ​The crypto world is buzzing, but let's cut through the noise with VERIFIED facts about the $351.6M Bitget hack. ​Spoiler: It’s not what you think. ​Hackers didn't steal private vault keys! Instead, they breached a backend system, spoofed transaction paperwork, and pushed forged withdrawal requests right through Bitget’s own approval process. ​Why does this technicality matter? Because stolen keys = endless bleeding. 🩸 Forged requests = patch the hole, stop the bleed. 🛑 ​The Good News: ✅ Keys are safe: Private keys never left the building. ✅ Vaults are locked: Only hot and warm wallets were hit. Cold storage remains 100% secure. ✅ Users are whole: Bitget’s $464M Protection Fund is fully covering the $351.6M loss. ​Withdrawals are temporarily paused for a security overhaul, but CEO Gracy Chen confirmed user assets are safe. ​This incident proves that back-office infrastructure is the new Web3 battleground. Stay alert, stay safe! 🛡️ $AVAX {future}(AVAXUSDT) $LINK {future}(LINKUSDT) $ORDI {future}(ORDIUSDT)
#bitgetbreachforgedrequestsnotstolenkeys
🚨 The Real Story Behind the Bitget Breach 🚨

​The crypto world is buzzing, but let's cut through the noise with VERIFIED facts about the $351.6M Bitget hack.

​Spoiler: It’s not what you think.

​Hackers didn't steal private vault keys! Instead, they breached a backend system, spoofed transaction paperwork, and pushed forged withdrawal requests right through Bitget’s own approval process.

​Why does this technicality matter?

Because stolen keys = endless bleeding. 🩸

Forged requests = patch the hole, stop the bleed. 🛑

​The Good News:

✅ Keys are safe: Private keys never left the building.

✅ Vaults are locked: Only hot and warm wallets were hit. Cold storage remains 100% secure.

✅ Users are whole: Bitget’s $464M Protection Fund is fully covering the $351.6M loss.

​Withdrawals are temporarily paused for a security overhaul, but CEO Gracy Chen confirmed user assets are safe.

​This incident proves that back-office infrastructure is the new Web3 battleground. Stay alert, stay safe! 🛡️

$AVAX
$LINK
$ORDI
🚨#Bitget says an attacker compromised part of its hot/warm wallet infrastructure, triggering unauthorized transfers worth an estimated $351.6M. 🔒 Cold wallets: Safe, according to Bitget 💰 User balances: Reportedly unaffected 🛡️ Protection Fund: $464M+ ⛔ Withdrawals: Paused ✅ Trading & deposits: Still live The attacker allegedly compromised a backend system and spoofed transaction data to bypass authorization. Bitget says private keys were not compromised and the breach has been contained. On-chain researchers had previously identified around $183M in suspicious transfers, creating a discrepancy with Bitget's $351.6M estimate. BGB fell nearly 3% after the news. $ETH 👀 #BitgetBreachForgedRequestsNotStolenKeys #BitgetSays$352MAffectedInHack #Write2Earn
🚨#Bitget says an attacker compromised part of its hot/warm wallet infrastructure, triggering unauthorized transfers worth an estimated $351.6M.

🔒 Cold wallets: Safe, according to Bitget
💰 User balances: Reportedly unaffected
🛡️ Protection Fund: $464M+
⛔ Withdrawals: Paused
✅ Trading & deposits: Still live

The attacker allegedly compromised a backend system and spoofed transaction data to bypass authorization. Bitget says private keys were not compromised and the breach has been contained.

On-chain researchers had previously identified around $183M in suspicious transfers, creating a discrepancy with Bitget's $351.6M estimate.

BGB fell nearly 3% after the news. $ETH 👀
#BitgetBreachForgedRequestsNotStolenKeys #BitgetSays$352MAffectedInHack #Write2Earn
Recent discussions highlight a security incident at Bitget where forged requests, rather than stolen private keys, were the vector of attack. This distinction is crucial for understanding the nature of the breach and the effectiveness of current security protocols. While any breach is concerning, the fact that private keys remained secure suggests the core infrastructure might be more robust than initially feared. However, the ability to execute forged requests points to potential vulnerabilities in user verification, API integrations, or internal procedural controls that need immediate and thorough investigation. The market will be watching closely to see how Bitget addresses these issues and reinforces its systems to prevent recurrence. This event underscores the ongoing challenges in maintaining absolute security in the digital asset space, even for established platforms. Disclaimer: This content is for informational purposes only and does not constitute investment advice. #BitgetBreachForgedRequestsNotStolenKeys
Recent discussions highlight a security incident at Bitget where forged requests, rather than stolen private keys, were the vector of attack. This distinction is crucial for understanding the nature of the breach and the effectiveness of current security protocols. While any breach is concerning, the fact that private keys remained secure suggests the core infrastructure might be more robust than initially feared. However, the ability to execute forged requests points to potential vulnerabilities in user verification, API integrations, or internal procedural controls that need immediate and thorough investigation. The market will be watching closely to see how Bitget addresses these issues and reinforces its systems to prevent recurrence. This event underscores the ongoing challenges in maintaining absolute security in the digital asset space, even for established platforms.

Disclaimer: This content is for informational purposes only and does not constitute investment advice.

#BitgetBreachForgedRequestsNotStolenKeys
·
--
#bitgetbreachforgedrequestsnotstolenkeys The Bitget breach has a much more interesting lesson than “$350M was hacked.” Bitget says attackers didn't steal its private keys. Instead, they compromised a critical backend system inside its wallet infrastructure, spoofed transaction data and triggered the exchange's own authorization process to move funds. Around $351.6M was affected across parts of Bitget's hot and warm wallets, while the exchange says its cold wallets remained secure. That's the part I think deserves attention. A crypto exchange can protect its private keys and still have a serious security problem if the systems feeding transactions into the signing process can be compromised. So this isn't simply a story about “keys being stolen.” It's a reminder that exchange security has multiple layers: key protection, transaction validation, backend integrity and authorization controls. Bitget says the attack has been contained and a full technical report is expected. The big question now is: how did the attacker get control of the transaction-generation layer in the first place? #Bitget #CryptoSecurity #CyberSecurity
#bitgetbreachforgedrequestsnotstolenkeys
The Bitget breach has a much more interesting lesson than “$350M was hacked.”

Bitget says attackers didn't steal its private keys.
Instead, they compromised a critical backend system inside its wallet infrastructure, spoofed transaction data and triggered the exchange's own authorization process to move funds.

Around $351.6M was affected across parts of Bitget's hot and warm wallets, while the exchange says its cold wallets remained secure.
That's the part I think deserves attention.

A crypto exchange can protect its private keys and still have a serious security problem if the systems feeding transactions into the signing process can be compromised.

So this isn't simply a story about “keys being stolen.”
It's a reminder that exchange security has multiple layers: key protection, transaction validation, backend integrity and authorization controls.

Bitget says the attack has been contained and a full technical report is expected.

The big question now is: how did the attacker get control of the transaction-generation layer in the first place?

#Bitget #CryptoSecurity #CyberSecurity
Inside the Bitget Breach: Forged Requests, Not Stolen Keys! 🔐💥 Following the recent $351.6M breach on Bitget, CEO Gracy Chen clarified that private keys were NEVER compromised. Instead, attackers breached a core backend system to generate forged withdrawal requests. 💡 Key Highlights of the Incident: Wallets Affected: Hot & Warm wallets were impacted, but Cold Storage remains 100% safe. User Protection: Bitget's $464M Protection Fund covers 100% of the lost funds. User balances remain accurate and secure. Current Status: Deposits & Trading remain active, while withdrawals are temporarily paused for security checks. This serves as a huge reminder for the industry that backend infrastructure security is just as vital as protecting private keys! What are your thoughts on exchange security after this incident? Let's discuss in the comments below! 👇 #BitgetBreachForgedRequestsNotStolenKeys #CryptoNews #ExchangeSecurity #Web3 #Trading Updates#BitgetBreachForgedRequestsNotStolenKeys
Inside the Bitget Breach: Forged Requests, Not Stolen Keys! 🔐💥
Following the recent $351.6M breach on Bitget, CEO Gracy Chen clarified that private keys were NEVER compromised. Instead, attackers breached a core backend system to generate forged withdrawal requests.
💡 Key Highlights of the Incident:
Wallets Affected: Hot & Warm wallets were impacted, but Cold Storage remains 100% safe.
User Protection: Bitget's $464M Protection Fund covers 100% of the lost funds. User balances remain accurate and secure.
Current Status: Deposits & Trading remain active, while withdrawals are temporarily paused for security checks.
This serves as a huge reminder for the industry that backend infrastructure security is just as vital as protecting private keys!
What are your thoughts on exchange security after this incident? Let's discuss in the comments below! 👇
#BitgetBreachForgedRequestsNotStolenKeys #CryptoNews #ExchangeSecurity #Web3 #Trading Updates#BitgetBreachForgedRequestsNotStolenKeys
·
--
#bitgetbreachforgedrequestsnotstolenkeys Infrastructure Hijack: How Bitget Lost $351.6 Million Without Losing Private Keys $BTC {spot}(BTCUSDT) Bitget suffered a $351.6 million security breach affecting its hot and warm wallet layers, but CEO Gracy Chen confirmed that cryptographic private keys were never compromised. Instead, attackers infiltrated a core backend system within the exchange's wallet infrastructure, allowing them to forge fraudulent withdrawal requests and trick the automated authorization process into signing and executing unauthorized transfers. Because private keys remained intact, cold storage assets were unaffected, preventing a complete platform drain. From a risk perspective, Bitget's $464 million User Protection Fund covers 100% of the stolen capital; however, while trading and deposits remain open, withdrawals have been temporarily frozen pending a full system audit. This incident highlights a growing security shift: modern exchange vulnerabilities are increasingly targeting API workflows and backend authorization pipelines rather than raw private key theft. $BNB {spot}(BNBUSDT)
#bitgetbreachforgedrequestsnotstolenkeys
Infrastructure Hijack: How Bitget Lost $351.6 Million Without Losing Private Keys $BTC
Bitget suffered a $351.6 million security breach affecting its hot and warm wallet layers, but CEO Gracy Chen confirmed that cryptographic private keys were never compromised. Instead, attackers infiltrated a core backend system within the exchange's wallet infrastructure, allowing them to forge fraudulent withdrawal requests and trick the automated authorization process into signing and executing unauthorized transfers. Because private keys remained intact, cold storage assets were unaffected, preventing a complete platform drain. From a risk perspective, Bitget's $464 million User Protection Fund covers 100% of the stolen capital; however, while trading and deposits remain open, withdrawals have been temporarily frozen pending a full system audit. This incident highlights a growing security shift: modern exchange vulnerabilities are increasingly targeting API workflows and backend authorization pipelines rather than raw private key theft. $BNB
#BitgetBreachForgedRequestsNotStolenKeys 🚨 BREAKING: BITGET SECURITY BREACH 🚨 Bitget has confirmed a major security incident involving approximately $351.6M in assets. 🔴 What happened? • Attackers reportedly compromised a backend wallet system • Transfer data was spoofed to trigger the authorization process • Bitget says private keys were NOT stolen • Cold wallets were reportedly unaffected • Withdrawals remain temporarily suspended 💰 Bitget says its User Protection Fund holds $464M+, enough to cover the reported loss. ⚠️ Bitget’s CEO has also raised a preliminary possibility of a North Korea-linked attack, but the attribution is not yet independently confirmed. Crypto security remains one of the biggest risks in the market. Stay alert. 👀 #Bitget #CryptoSecurity #CryptoNews #Bitcoin #Ethereum #BinanceSquare {spot}(BTCUSDT) {spot}(NOTUSDT) {spot}(ZECUSDT)
#BitgetBreachForgedRequestsNotStolenKeys

🚨 BREAKING: BITGET SECURITY BREACH 🚨

Bitget has confirmed a major security incident involving approximately $351.6M in assets.

🔴 What happened?
• Attackers reportedly compromised a backend wallet system
• Transfer data was spoofed to trigger the authorization process
• Bitget says private keys were NOT stolen
• Cold wallets were reportedly unaffected
• Withdrawals remain temporarily suspended

💰 Bitget says its User Protection Fund holds $464M+, enough to cover the reported loss.

⚠️ Bitget’s CEO has also raised a preliminary possibility of a North Korea-linked attack, but the attribution is not yet independently confirmed.

Crypto security remains one of the biggest risks in the market. Stay alert. 👀

#Bitget #CryptoSecurity #CryptoNews #Bitcoin #Ethereum #BinanceSquare

*$351.6M lost (Bitget official) — on-chain tally $356.86M per Lookonchain — from hot + warm wallets — cold wallets secure — self-custodial Bitget Wallet separate infra not affected* - *Detected Sep 24 18:31 UTC unauthorized transfers — emergency team within minutes — withdrawals suspended precaution, deposits + trading normal* $QI $PHA $ARK - *Method:* *CEO Gracy Chen: "Attacker compromised critical backend system within wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out" — private key compromise ruled out — loss containment confirmed no further transfers possible* - *Chains/assets:* *Ethereum (main concentration), XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, Base — ETH, XRP single-chain loss largest, BNB, AVAX, USDT, USDC, USDT0 on Arbitrum* - *Attribution:* *Prelim North Korea — TraderTraitor/Lazarus cluster — some IPs matched VPN used by DPRK group — Chen: patterns "highly consistent" with DPRK — some hacker wallets already frozen per chains* - *Investigators:* *Mandiant (Google) + SlowMist + law enforcement + Binance/Bybit on-chain — forensic analysis + tracing — full technical report promised within 24h* - *User protection:* *User Protection Fund holds 5,500 BTC ∼$464M covers 100% loss — fund started 2022 $300M, avg $382M Aug 2026 — "User funds safe balances accurate" — Chen to Reuters Sep 25: withdrawal pause "not because of shortfall"* *BREAKING 🚨 Bitget confirms $351.6M hack Sep 24 18:31 UTC hot/warm wallets — cold safe — attacker compromised backend wallet system spoofed transfer data triggered auth — private keys NOT stolen ⚡ Chains: ETH XRP ARB AVAX OP BSC Base — Suspected NK Lazarus TraderTraitor — Mandiant + SlowMist + LE tracing — withdrawals paused trading/deposits open — $464M protection fund 5.5k BTC covers loss — CEO Gracy Chen: contained 🚀*#QNTRises39% #BitgetBreachForgedRequestsNotStolenKeys #BitcoinSpotETFsTurnNetPositiveYTD
*$351.6M lost (Bitget official) — on-chain tally $356.86M per Lookonchain — from hot + warm wallets — cold wallets secure — self-custodial Bitget Wallet separate infra not affected*
- *Detected Sep 24 18:31 UTC unauthorized transfers — emergency team within minutes — withdrawals suspended precaution, deposits + trading normal* $QI $PHA $ARK
- *Method:* *CEO Gracy Chen: "Attacker compromised critical backend system within wallet infrastructure, used it to spoof transaction data, and triggered our authorization process to move funds out" — private key compromise ruled out — loss containment confirmed no further transfers possible*
- *Chains/assets:* *Ethereum (main concentration), XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, Base — ETH, XRP single-chain loss largest, BNB, AVAX, USDT, USDC, USDT0 on Arbitrum*
- *Attribution:* *Prelim North Korea — TraderTraitor/Lazarus cluster — some IPs matched VPN used by DPRK group — Chen: patterns "highly consistent" with DPRK — some hacker wallets already frozen per chains*
- *Investigators:* *Mandiant (Google) + SlowMist + law enforcement + Binance/Bybit on-chain — forensic analysis + tracing — full technical report promised within 24h*
- *User protection:* *User Protection Fund holds 5,500 BTC ∼$464M covers 100% loss — fund started 2022 $300M, avg $382M Aug 2026 — "User funds safe balances accurate" — Chen to Reuters Sep 25: withdrawal pause "not because of shortfall"*
*BREAKING 🚨 Bitget confirms $351.6M hack Sep 24 18:31 UTC hot/warm wallets — cold safe — attacker compromised backend wallet system spoofed transfer data triggered auth — private keys NOT stolen ⚡ Chains: ETH XRP ARB AVAX OP BSC Base — Suspected NK Lazarus TraderTraitor — Mandiant + SlowMist + LE tracing — withdrawals paused trading/deposits open — $464M protection fund 5.5k BTC covers loss — CEO Gracy Chen: contained 🚀*#QNTRises39% #BitgetBreachForgedRequestsNotStolenKeys #BitcoinSpotETFsTurnNetPositiveYTD
Log in to explore more content
Join global crypto users on Binance Square
⚡️ Get latest and useful information about crypto.
💬 Trusted by the world’s largest crypto exchange.
👍 Discover real insights from verified creators.
Email / Phone number