The Bitget cryptocurrency exchange lost approximately $351.6 million as a result of a cyberattack on its wallet infrastructure, marking one of the largest incidents in the crypto industry in 2026.
According to Bitget CEO Gracie Chen, the attackers managed to compromise a critical backend component of the exchange’s wallet infrastructure, after which they tampered with transaction data and triggered the internal withdrawal authorization process.
However, according to preliminary findings from the company’s investigation, the wallets’ private keys were not compromised.
The attack affected Bitget’s hot and so-called warm wallets. Cold wallets, in which funds are stored offline, remained secure.
After detecting the attack, the exchange halted further unauthorized transfers. Trading and deposits continued to function, but withdrawals were temporarily suspended while security checks were conducted.
Bitget stated that user losses will be covered by its own User Protection Fund, which exceeded $464 million at the time of the incident.
The attack’s uniqueness lies in its mechanism. In major cryptocurrency hacks, attackers often gain access to private keys and then directly sign transactions to withdraw assets.
In the case of Bitget, according to the exchange’s management, the attackers—rather than obtaining the keys—forced the internal system to accept fraudulent transfer data as legitimate transactions.
The incident has once again demonstrated that the security of centralized cryptocurrency platforms depends not only on the protection of private keys and cold storage of assets. Backend infrastructure, transaction authorization systems, and internal control mechanisms also remain potential points of attack.