Bitget chief executive Gracy Chen has given the first detailed account of how a hacker extracted an estimated $351.6 million from the exchange, describing a breach that reached into the core of its wallet infrastructure rather than exploiting a single user-facing weakness.

Speaking on September 24, Chen said the attacker gained control of a critical server underpinning Bitget's wallet systems, then altered transaction records to deceive the exchange's approval mechanism into authorising transfers it should have blocked. "The attacker compromised a critical server in our wallet infrastructure, manipulated the transaction records and induced the approval system to transfer the funds," she said.

The incident affected a range of assets held on the platform, including ether, avalanche, BNB, the USDT and USDT0 stablecoins, USDC and the gold-backed token XAUT, among others. Bitget has not disclosed how the intrusion into the server itself was achieved, saying only that the specific method remains under active investigation.

Losses contained, exchange says

Chen said Bitget has since shut off the pathway used in the attack. "Loss control is confirmed. No further unauthorised transfers are possible," she said, adding that a full technical report would follow once the investigation is complete.

On September 25, Chen confirmed that Bitget had engaged Mandiant and SlowMist, two firms specialising in digital forensics and blockchain security, to conduct an external audit of the breach alongside the exchange's internal teams. She declined to commit to a date for restoring any suspended functions tied to the incident. "We will announce a timeline as soon as one is confirmed — we won't commit to a window we can't guarantee," she said.

User funds insulated, exchange claims

Bitget has sought to draw a firm line between the platform-level breach and customer holdings. The company said the vulnerability did not compromise user private keys, and that individual balances were not touched by the attack.

"User balances remain intact, and Bitget's User Protection Fund will cover the impact caused by this incident at the platform level," Chen said. The exchange has pointed to a reserve fund exceeding $464 million as the backstop for any losses arising from the breach, a sum that comfortably exceeds the estimated size of the theft.

For an exchange operating across European markets under increasing regulatory scrutiny of custody arrangements, the episode is likely to draw attention to how trading platforms secure the infrastructure sitting behind wallet approvals, rather than only the wallets themselves. Bitget has yet to publish the promised technical report detailing how the server was first compromised.