# "private key" (compromised OR stolen OR leaked) — X 热门讨论 (2026-09-25 07:59 UTC)
## @yhaiyang (Haipo Yang) · 09-25 06:27 · ♥57 ↻7 💬11 CoinEx is shutting down, but its hot wallet system remains highly advanced and is worth learning from for others in the industry.
We introduced an MPC-based dual-signature scheme for our hot wallets to eliminate single points of failure. Our infrastructure is split into two systems run by completely independent teams: the business system and the wallet system. Each holds one private key, and every withdrawal or transfer must pass substantive risk review by both, in real time. If either system is compromised, assets still cannot be stolen.
The hard part is that the wallet signing process has to be implemented independently, rather than relying on each node's native mechanism, which requires extensive re-engineering. It took us over a year to retrofit the vast majority of the nearly 300 chains supported by CoinEx, one by one. https://x.com/yhaiyang/status/2103370713617014946
## @FabiusDefi (Fabius DeFi) · 09-25 06:58 · ♥33 ↻1 💬22 The biggest CEX hack of 2026 so far 👇
@bitget just confirmed ~$351.6M was drained from part of their hot/warm wallet infrastructure.
A few important points:
- This was not a private key compromise. According to CEO Gracy Chen, the attacker compromised a backend system within the wallet infrastructure, spoofed transaction data, and then triggered Bitget’s own authorization/signing process to move the funds out.
- Deposits + trading on the exchange are still running, while withdrawals are temporarily suspended. There’s currently no confirmed timeline for when they’ll reopen.
- Bitget's User Protection Fund currently holds >$464M, enough to fully cover the ~$351.6M loss.
- $XRP made up the largest portion, with ~102.93M XRP worth ~$157.5M, followed by ~$85.8M in $ETH and stablecoins.
- @BitgetWallet was not affected.
Gracy says DPRK-linked hackers are very likely involved, while the preliminary investigation is leaning more toward a supply-chain compromise through a third-party tool than an insider attack.
But this is still not final, and we’ll need to wait for the full incident report.
The most interesting part to me is that the attacker didn’t even need to steal the private keys.
They may have compromised the wallet backend → spoofed transaction data → then made Bitget’s legitimate authorization/signing pipeline transfer the funds out.
There’s also a similarity here with the Bybit 2025 hack:
Securing private keys alone isn’t enough if the software layer in front of the signer gets compromised.
I personally have funds on Bitget as well, and I still can’t withdraw them rn.
Hopefully, Bitget completes the security review and gets withdrawals back online soon. > 引用 @GracyBitget: [SECURITY NOTICE] Bitget Hot Wallet Incident — September 24, 2026
At 18:31 UTC on September 24, 2026, Bitget's security systems detected unauthorized transfers from some of our hot wallets. Our security team activated emergency response protocols immediately.
What we have confirmed: -Estimated funds affected: approximately $351.6 million -Cold wallets remain fully secure. Bitget operates a three-tier wallet architecture — the breach contained only a portion of the hot wallet and warm wallet layers. -User funds are safe. The full amount of this loss falls within the coverage of Bitget's User Protection Fund, which currently holds over $464 million
Actions we have taken: -Emergency response team activated within minutes of detection -Abnormal transfer addresses identified, flagged, and reported -Withdrawals temporarily suspended as a precautionary measure, pending security review -Law enforcement and on-chain security firms have been formally notified and are engaged
What this means for you: -Your account balances are accurate and your assets are protected -Deposits and trading remain fully operational Withdrawals are temporarily paused and will be restored as soon as the security review is complete -What comes next: We will provide updates on an hourly basis across this channel and all official platforms. A full incident report — including root cause analysis and corrective actions — will be published within 24 hours. We will not speculate on the attack vector until the investigation is complete.
Bitget has navigated multiple market cycles. We will not run from this. Every dollar and every decision will be accounted for, transparently and in full. Updates will be posted here and across all official Bitget channels as they become available.
— Gracy Chen, CEO, Bitget https://x.com/FabiusDefi/status/2103378486132113419