Bitget lost $351.6 million in early 2026 because attackers successfully compromised the exchange's wallet backend, allowing them to inject spoofed transaction data that the system recognized as legitimate. According to Bitget CEO Gracy Chen, the exploit did not involve the theft of private keys, which are typically the primary target in large-scale exchange hacks. Instead, the attackers manipulated the internal processes that authorize transfers, tricking the platform into sending massive amounts of capital to unauthorized addresses.
The incident, which came to light following a series of massive unauthorized outflows, highlights a shift in cybercrime tactics toward infrastructure manipulation. Chen addressed the community via X (formerly Twitter), clarifying that while the funds are currently missing, the core cryptographic security of the exchange's assets remained intact. The focus of the investigation now lies on how the backend was breached and why internal validation checks failed to catch the fraudulent data injection before the funds were moved.
For the broader crypto market, this hack serves as a stark reminder that even robust key management cannot protect an exchange if its transaction processing layer is vulnerable. In the United States, such high-profile losses often lead to renewed calls from the SEC and CFTC for stricter custodial standards and mandatory third-party audits of exchange backend systems. This event specifically challenges the assumption that 'air-gapped' keys are a panacea for exchange security.
Investors should monitor Bitget’s recovery efforts and any potential compensation plans for affected users. Moving forward, the industry will likely see a push for 'zero-trust' architectures in wallet backends, where transaction data is verified against multiple independent sources before execution. The impact on Bitget’s liquidity and user trust will be a key metric to watch as the exchange attempts to patch the vulnerability and recover the stolen assets.