BTC — ETH — SOL — BNB — XRP — Fear & Greed —
AltcoinGordon
News

Bitget Loses $351.6 Million in Multi-Chain Breach, Funds Swapped and Drained

CEO Gray Chen says spoofed transfers, not stolen private keys, enabled the attack.

Stock photograph illustrating: Bitget Loses $351.6 Million in Multi-Chain Breach, Funds Swapped and Drained
Stock photograph, chosen to illustrate this story. The photographer is credited on the image.

Bitget has confirmed a major security breach resulting in losses of approximately $351.6 million. The exchange said hackers drained funds from wallets spanning multiple blockchain networks. Some reports place the total closer to $350 million, while others cite $352 million, reflecting the difficulty of tallying losses across chains in real time.

According to Bitget, the stolen assets were swapped through various protocols shortly after the breach. This is a common tactic used by attackers to convert illicit funds into harder-to-trace tokens. Moving funds across chains and swapping them quickly also complicates efforts by investigators to freeze or recover assets.

CEO Gray Chen addressed the incident directly, stating that the breach did not involve stolen private keys. Instead, he said the attackers used spoofed transfers to siphon funds from exchange wallets. This distinction matters. Private key theft often points to weaknesses in custody or hardware security. Spoofed transfers suggest a different kind of vulnerability, likely tied to how transaction requests are verified and authorized.

An internal investigation cited by crypto.news points to a backend breach as the likely entry point for attackers. Backend systems typically handle transaction processing, wallet management, and internal authorization checks. A compromise there could allow attackers to insert fraudulent transfer instructions without needing direct access to private keys.

The scale of the loss places this incident among the larger exchange breaches in recent years. Multi-chain attacks of this size raise questions about how exchanges secure the infrastructure connecting different blockchain networks. Cross-chain bridges and internal transfer systems have repeatedly been targeted by hackers because they often present more complex attack surfaces than single-chain wallets.

Bitget has not yet detailed the full scope of user impact or outlined a compensation plan, based on available reporting. Exchanges facing breaches of this magnitude typically face pressure to reassure users quickly, both to maintain trust and to limit withdrawal pressure. How Bitget communicates next steps, including any asset freezes achieved with the help of other platforms, will likely shape user and market reaction in the coming days.

The incident also arrives amid continued scrutiny of exchange security practices industry-wide. Regulators and users alike have grown more attentive to how platforms safeguard hot wallets, backend systems, and transfer authorization processes. A breach of this size on a major exchange is likely to renew those conversations.

Sources disagree on this story

This article was published before the reports below were compared. The reporting above stands; what follows is where the published accounts do not agree.

Coinfomania and crypto.news give conflicting accounts of which cryptocurrency made up the largest share of the $351.6 million taken from Bitget.

What all sources agree on

  • Bitget lost approximately $351.6 million (also described as at least $350 million) in the breach.
  • The exchange's hot and warm wallets were compromised while cold wallets remained secure.
  • Bitget's User Protection Fund, valued at over $464 million, is stated to cover the full loss.
  • Bitget said the breach involved a compromised backend system that spoofed transaction data and triggered the authorization process, rather than a theft of private keys.

Where the reports disagree

1Which asset accounted for the largest share of the stolen funds

The hacker has swiftly converted much of the stolen assets into 67,982 ETH.

Coinfomania

Lookonchain estimates XRP was the largest stolen asset, with 102.93 million tokens worth $157.48 million.

crypto.news

What would settle it: Bitget's or Lookonchain's full on-chain transaction-level accounting of the stolen assets.

What to make of it

Treat the $351.6 million loss figure, the hot/warm-wallet breach, the intact cold wallets, and the $464 million protection fund as established; do not treat claims about which single asset (ETH or XRP) made up the bulk of the stolen funds as settled until Bitget or on-chain trackers publish a reconciled transaction-level breakdown.

Market Impact

A loss of this size on a major exchange could affect user confidence in Bitget specifically, and potentially in centralized exchange security more broadly. Traders often react to breach news by moving assets to other platforms or into self-custody, at least temporarily. This can pressure exchange liquidity and trading volumes in the short term.

The method described, spoofed transfers rather than private key theft, may also prompt other exchanges to review backend transaction authorization systems. If competitors or infrastructure providers implement additional safeguards in response, it could influence how exchange security is evaluated by users and partners going forward.

The full picture of how the breach occurred, and how much of the stolen funds might be recovered, remains under investigation. Bitget's next disclosures will be closely watched by users and the wider industry.

Frequently Asked Questions

How much did Bitget lose in the breach?

Reports place the loss at approximately $351.6 million, with some figures citing $350 million to $352 million depending on the source and timing of the tally.

Were user private keys stolen in the attack?

No. Bitget CEO Gray Chen said the breach occurred through spoofed transfers rather than compromised private keys.

What happened to the stolen funds?

Hackers reportedly drained wallets across multiple blockchain networks and swapped the stolen assets shortly after the breach, a common method used to obscure the trail of stolen crypto.

What caused the breach according to Bitget's investigation?

Bitget's internal probe points to a backend system breach as the likely source, rather than a direct compromise of wallet private keys.

Follow this desk in Google