Bitget CEO Gracy Chen Rules Out Private Key Theft in $351.6M XRP-Led Hack
Bitget CEO Gracy Chen says private keys stayed safe in the $351.6M hack; attackers breached a backend system and used Bitget's own authorization flow.
AI SummaryAI
- Bitget CEO Gracy Chen says private keys were not stolen in the $351.6M hack.
- Attackers compromised a critical backend system to trigger Bitget's own authorization flow.
- Unauthorized transfers were first detected on September 24 at 18:31 UTC.
- Bitget's User Protection Fund holds over $464M, exceeding the estimated loss.
Private Keys Survived the Bitget Breach
Crypto exchange Bitget is investigating an attack that drained an estimated $351.6 million from its wallet infrastructure, and its chief executive now says the exchange's cryptographic keys were never stolen. Unauthorized transfers were first detected on September 24 at 18:31 UTC, per the exchange's official security notice. The affected layer covered portions of the hot and warm wallet stack, while cold storage stayed untouched. In a technical update shared on X, CEO Gracy Chen explained that the attacker compromised a critical backend system connected to Bitget's wallet services, forged transfer data, and then used the platform's own authorization process to push funds out. The central finding: no private key compromise. That distinction matters — the attacker never needed the keys themselves, only the transaction pipeline that decides which transfers get signed. Chen also noted that some IP addresses involved show VPN patterns resembling those previously used by a North Korea-linked group, while stressing that no forensic attribution has yet been made. The breach is contained and new unauthorized outflows blocked, though the initial entry point is still being traced.
Xhttps://x.com/GracyBitget/status/2103359775723626736
Withdrawals Frozen, $464M Fund Readied
The exchange's initial announcement, published hours after detection, set the preliminary damage estimate at roughly $351.6 million and confirmed that deposits and both spot trading and contract trading continue to operate normally while withdrawals stay suspended. User balances are accurate and protected, Bitget stated, and the company flagged the suspicious transfer addresses, alerted law enforcement, and brought in on-chain security firms to help trace and freeze the funds. No timeline for restoring withdrawals was attached to the notice. What the exchange did commit to: a complete incident report — including root-cause analysis and remediation steps — within 24 hours of publication. On solvency, the disclosed numbers point to headroom rather than shortfall. Bitget's User Protection Fund held more than $464 million at publication, larger than the estimated loss. Chen went further, saying the platform also holds over $1 billion of its own assets and maintains 1:1 user reserves, framing the withdrawal pause as a security decision rather than a liquidity one. She indicated withdrawals should resume within hours to days, not weeks, once the vulnerability is fully closed.
Lazarus Trail Points to July AFX Hack
The attack was fast and concentrated. Bitget's team observed roughly 52 significant fund movements in the hours after the breach, but that figure mixes emergency internal transfers and ordinary user withdrawals; about 19 transactions are confirmed to have sent roughly $351 million to attacker wallet addresses. The first anomalous outflow, mostly in Ethereum (ETH), hit at 18:31 UTC, followed about half an hour later by the largest single loss — an XRP hot wallet — with the concentrated draining running until roughly 19:16 UTC. By chain, XRP and Ethereum absorbed the biggest damage, with transfers also touching Arbitrum, Optimism, Base, BNB Smart Chain, and Avalanche. On-chain investigator Specter traced the stolen XRP, after cross-chain movement, back to funds from July's AFX hack, suggesting possible involvement of North Korea's Lazarus Group — though the attribution remains unconfirmed. Bitget Wallet, the self-custodial product, clarified that its on-chain funds are separate from exchange custody and unaffected. Bybit CEO Ben Zhou publicly offered assistance through his LazarusBounty.com tracking platform — a notable reversal from February 2025, when Bitget lent Bybit 40,000 ETH, worth about $106 million then, during Bybit's $1.4 billion breach. Readers tracking the market in real time can follow live spot and futures prices on Binance.
What the On-Chain Record Still Owes Us
Our reading: the security perimeter that failed is not key custody but the authorization pipeline that decides which transfers earn a signature — the same class of weakness behind Bybit's Safe-interface breach, executed here across dozens of assets and chains at once. The verification anchors are concrete: roughly 19 attacker transactions traceable on-chain, the cross-chain XRP trail tied to the AFX hack, and Bitget's pledged post-mortem. For traders weighing counterparty exposure, our best crypto exchanges guide tracks how major platforms handle custody incidents. The root-cause report must answer two questions: how the backend was entered, and how forged transfer data cleared authorization checks.
Related Tags

AI-generated, AI-reviewed, under COINOTAG editorial oversight.


