The latest announcement from Bitget confirmed $351.6 million was breached after an attacker compromised their backend system.
On 24 September, Bitget confirmed that an attacker had compromised a critical backend system within its wallet infrastructure and moved approximately $351.6 million out of its hot and warm wallets.
Bitget has said its private keys were not stolen, its cold wallets remain secure, and the loss will be absorbed by its User Protection Fund. Withdrawals were paused, law enforcement and onchain security firms were engaged, and a full technical report is to follow.
What Bitget has confirmed
According to statements from Bitget and its CEO Gracy Chen, the attacker compromised a critical backend system within the wallet infrastructure, used it to spoof transaction data, and triggered the exchange's own authorisation process to move funds out. Private key compromise has been ruled out, with the unauthorised transfers originating from the hot and warm wallet infrastructure, while cold wallets remained unaffected.
Bitget has said loss containment is confirmed, and no further unauthorised transfers are possible. It has also said that early indicators point to a North Korean group, although attribution has not yet been confirmed. What follows is CoinCover's analysis of that disclosure, not a statement of what happened inside Bitget.
This does not appear to have been a storage failure
The instinct after any hot wallet loss is to say the assets should have been in cold storage. That misses the point: hot and cold storage serve different, equally necessary purposes, and an exchange cannot operate without both. In this case, Bitget's cold wallets did exactly what they were designed to do and remained unaffected.
On Bitget's account, what failed was not the keys but the layer that decides what the keys are allowed to sign. Chen's own analogy is that forged withdrawal slips passed through the bank's own teller window: the vault keys never left the building, but paperwork that looked official, went through the same approval process the bank uses every day. And to the system doing the approving, it looked like a normal payout.
This pattern, in our view, is consistent with a structural weakness common to many businesses. When a platform's backend, its signing infrastructure and its recovery arrangements all live inside the same walls, they share the same weaknesses. One compromised system, one misconfigured permission, one person making one mistake under pressure, and the damage is not contained to a single layer.
To be clear, Bitget's recovery arrangements are not what failed here, and we have no reason to think they were part of the problem. The incident was a breach, and breaches are a security question.
But the pattern behind it is the same pattern that decides whether any loss, from theft or from error, ends up being survivable. If one compromised system inside a single perimeter can reach the hot wallets, the same logic applies to everything else held inside that perimeter, including the things a platform would rely on to recover. That is why an incident like this deserves to prompt a broader question: when something does get through, what is standing outside the blast radius?
Digital asset recovery must be independent of what it protects
A platform should never need to be operational, accessible or even still exist for its digital assets to be recovered. The backups, recovery processes, credentials and controls needed to restore access to assets should be held separately from the systems they protect, with sufficient operational and security independence that a failure or compromise of the primary platform cannot take recovery down with it. This is the standard we would like to see the industry adopt as a baseline.
Self-managed backups are, in our experience, the silent manifestation of this risk. Most platforms have them. Far fewer have tested them independently against the scenario they exist for, and fewer still hold them somewhere a breach of the main environment cannot also reach.
Next steps for the industry
For any business holding customer assets, the questions are simple to ask and uncomfortable to answer honestly. Are your backups held outside the environment they back up? Has recovery been tested end to end, recently, and by someone independent? If a single internal system were compromised tomorrow, what could it reach?
Bitget will publish its full report and the industry will learn from it. The broader lesson is already clear. Resilience built entirely in-house has a single point of failure, and that point is the house itself.
Disclaimer
CoinCover provides independent, platform-agnostic protection and recovery infrastructure that works alongside existing custody and security arrangements. The incident in question was not related to that recovery infrastructure, and nothing here is intended to raise doubts about Bitget’s existing recovery setup. Nor should this be read as a claim about what would or would not have prevented this specific incident; Bitget’s investigation will establish that.