When the news of the attack on Bitget surfaced, the most striking part was not the figure of "approximately $351.6 million involved," but rather the attack path provided by the official statement: the hacker did not directly empty assets by stealing private keys, but rather hacked into a key backend system of the wallet service. By forging transfer information and invoking the authorization signing process, they systematically transferred the platform's funds step by step (according to a single source). On September 25, Bitget CEO Gracy Chen publicly responded for the first time, confirming that this was a security incident targeting systems related to the wallet service, with an involved amount of approximately $351.6 million, but emphasized that this was "involved amount" rather than the final confirmed loss. The stop-loss measures have been completed, the platform does not face further risk of fund loss, and private key leakage can be ruled out (according to a single source). The specific date of the attack, the currencies of the funds used, and their on-chain destinations have not yet been disclosed. The hacker's methods of intrusion are still under technical review, and all key information currently comes from a single public statement, awaiting further evidence. However, beneath the narrative of "the private keys are intact, yet funds were still transferred out," a more pressing question has been thrown back to the entire industry: when the entry point of an attack shifts from private keys to backend systems, just where does a centralized platform claim its "security" boundary lies?
Hacker Breached Backend, Forged Transfer Approval
This time, the intruder was not the "ultimate thief" holding the private keys, but someone who could modify records in the backend. According to Gracy Chen, the attacker hacked into a key backend system of Bitget's wallet service, tampered with transfer information at the source, and utilized this compromised system to invoke the normal authorization signing process, transferring funds from the platform's account "openly." The official statement clearly indicates that private key leakage can be ruled out, suggesting that the signing module itself was not breached; it continued to receive commands and complete signatures, only this time it served the forged transfer transactions.
Tracing back along the attack path, the ability to penetrate the wallet service core and accurately drive the signing process indicates at least a considerable understanding of the internal system architecture and the sequence of signing calls. Such an "insider" intrusion directly breaks through traditional security boundaries. In the past, the industry focused significantly on "holding onto private keys and preventing remote control of off-chain systems," but rarely scrutinized: once a seemingly trusted backend node is compromised, is there still a mechanism to question every command initiated internally? This incident exposes structural blind spots where attacks starting from backend systems may easily be misjudged as "normal operations" under existing defensive thinking.
$351 Million-Level Attack, Stop-Loss Speed Becomes a Focus
This round of attacks launched from the backend system has been described by the official statement as "involving approximately $351.6 million in funds." From the magnitude alone, it has already placed Bitget among the few platform-level major cases in industry history. However, according to a single source's public statement, this figure is still just "an involved amount," not a final approved loss. Gracy Chen indicated that the security team quickly completed preliminary checks and identified the attack source after discovering anomalies. Upon confirming the attack path, they initiated emergency procedures to "complete the stop-loss" and confirmed internally that there is no further risk of fund loss from the platform—under the narrative of "the backend system was exploited, but private keys are ruled out," the speed of stop-loss was naturally spotlighted.
However, from the publicly available information, this emergency's critical variable remains blank: of the involved $351.6 million, what specific currencies are included, which on-chain addresses are they distributed across, and whether any assets have been frozen or reclaimed. Bitget has not provided any breakdown at the on-chain dimension; whether user funds were directly harmed and what compensation or internal absorption plans the platform intends to adopt have also not fallen within this round of disclosures. For an incident of this scale, how "quickly" the stop-loss is executed is not merely about a statement from the official side; rather, it returns to hard metrics such as fund recovery ratio and user loss disposal paths. When and how this information will be complemented with details will determine whether this incident is viewed as a notable crisis management response or an ongoing risk management test that has yet to be resolved.
North Korean Hacker Clues: Leads Appeared but Conclusions Remain Distant
Tracing back along the technical path of the funds being transferred out, the first batch of intelligence provided by Bitget's security team points to "who did it." According to a single source disclosure, Gracy Chen mentioned that some related IPs matched VPN services commonly used by a North Korean hacker group. The tactics used in the invasion of the wallet backend system, such as forging transfer information and invoking authorization signing processes, also show similarities to some past attacks by this organization. This combination of "IP + behavioral characteristics" often serves as a starting point directing suspicion towards a specific hacker group rather than the endpoint in numerous past attack cases in the industry.
However, the official stance is notably cautious—publicly they only state, "do not rule out the possibility of their involvement in this attack," without directly labeling the group as the final attacker. On one hand, North Korean hacker organizations have repeatedly been associated with attacks targeting trading platforms and on-chain funds throughout industry history; on the other hand, this incident remains in the preliminary investigation phase, existing evidence is more of "similar" and "coinciding," rather than "unique fingerprint." In the current context of heightened geopolitical sensitivity, if a hacker connected to a particular country is written into the formal conclusion, public opinion and regulation will challenge whether the evidence chain is robust enough, and hastily making a conclusion itself will become a new source of risk. This is also a practical constraint that Bitget chose to maintain by stating "leads have appeared but attribution remains to be determined."
An Overlooked Weakness: Backend Permissions Are More Deadly Than Private Keys
If in the past the industry's discussion of security instinctively directed the spotlight towards "are the private keys properly safeguarded," the Bitget incident pauses this narrative. The official clearly emphasizes that private key leakage can be ruled out, but the key backend system of the wallet service has been breached, with hackers forging transfer information and invoking existing authorization signing processes to transfer about $351.6 million of related funds from the platform. This means that what is truly compromised is not the string of private keys permanently locked in HSMs or cold storage, but rather the authority itself regarding "who can give commands to the signing module."
Under the mainstream architecture of front-end business systems + wallet services + signing modules, the backend system plays a central role in translating business logic into signing instructions. Once this layer is controlled, attackers could potentially complete the entire signing link legally without even touching the private keys. Gracy Chen also mentioned that the hackers' specific methods of intrusion are still under technical review, which implicitly acknowledges that key mechanisms such as hierarchical backend permissions, operational audits, and whether large transfers have independent verification processes still harbor risks that remain inadequately exposed. For all centralized platforms relying on similar architectures, this systematic vulnerability of "one jump before signing" is becoming a pressing question that must be addressed.
What Users and the Industry Should Look for Next
This incident remains a puzzle where only the outline is visible: when exactly did the attack occur, how long did it last, and were there multiple attempts? Bitget has not provided a complete timeline; how hackers forged transfer information from the key backend system of the wallet service and invoked authorization signing processes to complete outflows remains at the "under technical review" stage as well; the composition of the approximately $351.6 million involved, distribution across which chains, and whether some assets have already been frozen or attempted to be recovered have not been mentioned in public materials. On the other hand, when Gracy Chen spoke publicly, the official line was that "stop-loss has been completed, and there is no further risk of fund loss," but still, no clear compensation or asset recovery plan has been synchronized. This means that whether Bitget will provide a verifiable technical review and a safety rectification roadmap will directly determine the market's final evaluation of its safety capabilities and transparency. A bigger variable lies in the industry: whether this incident prompts the inclusion of critical backend permission management, independent audits of the signing process, and operational access controls as new safety baselines, or if it gets dismissed as an "isolated incident," will determine whether this attack is remembered as an expensive lesson or forces centralized platforms to complete a genuine safety paradigm upgrade before the next attack arrives.
Join our community, let's discuss, and become stronger together!
AiCoin exclusive Hyperliquid benefits: https://app.hyperliquid.xyz/join/AICOIN88
AiCoin exclusive Aster benefits: https://www.asterdex.com/zh-CN/referral/9C50e2
On-chain Telegram community: https://t.me/AiCoinWhaleData
On-chain community: https://www.aicoin.com/link/chat?cid=N6OVMor5g
AiCoin on-chain Twitter: https://x.com/aicoinwhaledata
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。



